Book Image

Google Cloud Certified Professional Cloud Developer Exam Guide

By : Sebastian Moreno
Book Image

Google Cloud Certified Professional Cloud Developer Exam Guide

By: Sebastian Moreno

Overview of this book

Google Cloud Platform is one of the three major cloud providers in the industry, exhibiting great leadership in application modernization and data management. This book provides a comprehensive introduction for those who are new to cloud development and shows you how to use the tools to create cloud-native applications by integrating the technologies used by Google. The book starts by taking you through the basic programming concepts and security fundamentals necessary for developing in Google Cloud. You'll then discover best practices for developing and deploying applications in the cloud using different components offered by Google Cloud Platform such as Cloud Functions, Google App Engine, Cloud Run, and other GCP technologies. As you advance, you'll learn the basics of cloud storage and choosing the best options for storing different kinds of data as well as understand what site reliability engineers do. In the last part, you'll work on a sample case study of Hip Local, a community application designed to facilitate communication between people nearby, created by the Google Cloud team. By the end of this guide, you'll have learned how to design, develop, and deploy an end-to-end application on the Google Cloud Platform.
Table of Contents (21 chapters)
1
Section 1: Welcome to the Google Cloud Developers' Guide
4
Section 2: Developing and Modernizing Applications on Google Cloud Platform
9
Section 3: Storage Foundations
14
Section 4: SRE for Developers
17
Section 5: Analyzing a Sample Case Study

Reducing the attack surface with POLP

Often, we find ourselves in a situation where, to speed up the development of our application, we grant permissions without understanding what we are really doing, just to make the code work. The problem with this strategy is that by assigning more permissions than the application needs to perform its functions, we increase its attack surface. This increases the possibility of vulnerabilities arising in our application, with the risk that these will be exploited by malicious actors. This is why POLP exists, and we will look at this in detail next.

POLP

The idea behind POLP is that each application must have the minimum permissions it needs in order to operate, so as to prevent an application from performing actions for which it was not created.

In order to comply with this principle, it is necessary to identify in the application design phase the dependencies of the services to be consumed and the actions that they will perform on these...