Full Report
Developers and IT operations pros of all stripes come to Google Cloud to build modern, cloud-first and cloud-native applications. Here’s the latest from Google Cloud on everything app dev, containers, Kubernetes, DevOps, serverless and open source, all in one place. Week of Apr 11 - Apr 15, 2022Listen to a ProdcastGoogle’s SRE team has launched a “Prodcast” focusing on concepts from its SRE book. Available from wherever you get your podcasts. Run Apache Spark on a modern container baseDataproc, our managed version of Apache Spark, is now generally available on Google Kubernetes Engine (GKE), allowing you to create a Dataproc cluster and submit Spark jobs on a self-managed GKE cluster. Read all about it. Loads of new runtimes in App Engine and Cloud FunctionsJava, Ruby, Python and PHP developers, rejoice! You can now update or develop new App Engine apps and Cloud Functions using Java 17, Ruby 3, Python 3.10 and PHP 8.1.BeReal shows you how modern app development is doneSocial media company BeReal discusses how it uses Google Cloud services including Firebase, Cloud Functions and GKE to build its app. Build fast without breaking thingsIn this three-part series, learn about the Supply-chain Levels for Software Artifacts (SLSA) framework designed to improve the integrity of your software packages and infrastructure. Start with, How to SLSA Part 1 - The Basics, then move on to part 2 and part 3. Related Article Picture this: How the U.S. Forest Service uses Google Cloud tools to analyze a changing planet For over a decade, the U.S. Forest Service has been using Google Earth Engine and other Google Cloud tools to study our changing planet. Read Article Week of Apr 4 - Apr 8, 2022How to migrate a container from a VM to Cloud RunWith Cloud Run, you can migrate a legacy VM to a container and save money – even if you don’t know Kubernetes. This video shows you how. Receive Error Reporting notifications through Slack and WebhooksError Reporting can analyze, aggregate, and notify DevOps teams about crashes that happened in their cloud services, right to their preferred channels. Learn more in this blog. Cloud-native architecture is in the cards at NCREarlier this year, NCR Authentic Cards talked about how it built a transaction processing platform on Google Cloud. NCR and its consulting partner Opus Systems are back for part two of the migration story, taking a detailed look at all the components that went into the cloud-based architecture. How to easily share a service with Cloud Run Have you ever written a script that you wanted to make available to others? Cloud Run makes it easy to deploy a processing service quickly and easily. In this blog post, Developer Advocate Laurent Picard creates an image processing service that generates coloring pages, then makes it available to others — all in under 200 lines of Python and JavaScript. Follow along in this tutorial. Related Article Introducing Topaz — the first subsea cable to connect Canada and Asia The Topaz subsea cable is the first fiber cable to connect Canada and Asia, and will provide better resiliency and lower latency for Goog... Read Article Week of Mar 28 - Apr 1, 2022Another cool thing you can do with Cloud FunctionsGot data you want to ingest from Cloud Storage to BigQuery? Cloud Functions can help with that. This tutorial shows you how. Add custom severity levels to Cloud Monitoring alert policiesNot all alerts are created equal. In this blog post, learn how to add static and dynamic severity levels to a Cloud Monitoring alert policy, with enhanced notification channels including email, webhooks, Cloud Pub/Sub and PagerDuty. Learn how to use CPU allocation controls in Cloud RunLast fall, we added “always-on CPU” capabilities to Cloud Run, making it a better fit for running background- and other asynchronous-processing tasks. In this post, Developer Advocate Wesley Chun uses a weather alerting app to demonstrate how to use the feature, and along the way, reduces the app’s average user response latency by over 80%. Related Article Go 1.18 and Google Cloud: Go now with Google Cloud Go 1.18 release and Google Cloud working better together. Read Article Week of Mar 21 - Mar 25, 2022Get Going with latest Go 1.18 releaseWith the release of version 1.18, the Go programming language now includes support for generic code using parameterized types, integrated fuzz testing, and a new Go workspace mode that makes it simple to work with multiple modules. Learn more here. Week of Mar 14 - Mar 18, 2022Create EventArc triggers with TerraformIn addition to the Google Cloud Console or gcloud, you can also use a Terraform resource to create an Eventarc trigger. Mete Atamel shows you how. Scaling to new markets with Cloud RunFrench publisher Les Echos Le Parisien Annonces switched from dedicated on-prem infrastructure to Cloud Run to supplement its main news site with regional variations. Les Echos shares its website architecture here. The serverless way to celebrate Pi DayIn honor of Pi Day, Google Cloud Developer Advocate Emma Haruka Iwao shows you how to use the new Cloud Functions (2nd gen) to calculate π — serverlessly. Week of Mar 07 - Mar 11, 2022Rhode Island moves to Google Cloud-based job boardWhen the pandemic hit, the State of Rhode Island moved its workforce development operations entirely online on a foundation of Google Workspace and Google Cloud resources, including Firestore, Cloud Functions, and Kubernetes, among others. Check out how they did it. Containerized microservices at Lowe’sLowe’s already told us how they use SRE. They’re at it again, describing how they built an e-commerce website using a containerized microservices architecture and Kubernetes, with Istio for service mesh and Cloud Operations for good measure.Cruise AVs hit the road with Google Cloud servicesAutonomous Vehicle (AV) startup Cruise detailed how it’s using data analytics and machine learning on a foundation of Google Kubernetes Engine (GKE) and other services to develop and test its self-driving cars. Read the guest post. L’Oréal’s data analytics gets a makeover with serverlessWe’re hurtling toward a programmable cloud — a world where developers use cloud-native serverless tools like Cloud Functions to quickly prototype and build powerful, data-driven business insights. L’Oréal is a great example. Better telemetry for your Anthos clustersAnthos Service Mesh Dashboard is now available (public preview) on the Anthos clusters on Bare Metal and Anthos clusters on VMware. Now, you can get out-of-the-box telemetry dashboards to see a services-first view of your application on the Cloud Console.Instrument your Java appsWith the new version of the Google Cloud Logging Java library, you can wire your application logs with more information — without adding a single line of code.Visualize metrics from Cloud SpannerBuilding an app on top of Cloud Spanner but can’t assess how well it’s operating? The new OpenTelemetery receiver for Cloud Spanner provides an easy way for you to process and visualize metrics from Cloud Spanner System tables, and export these to the APM tool of your choice. Read more here. Week of Feb 28 - Mar 4, 2022Introducing Cloud SDKThe rebranded Cloud SDK is a collection of all the libraries and tools (including Google Cloud CLI) you need to interact with Google Cloud products and services. Learn more here. Cloud CLI, meet TerraformGoogle Cloud CLI’s new Declarative Export for Terraform allows you to export the current state of your Google Cloud infrastructure into a descriptive file compatible with Terraform (HCL) or Google’s KRM declarative tooling, and is now available in preview. Knative graduates to incubating project Congratulations to Knative, which has been accepted by the Cloud Native Computing Foundation, or CNCF, as an incubating project, enabling the next phase of serverless architecture. We manage Prometheus so you don’t have toGoogle Cloud Managed Service for Prometheus is now generally available! Get all the benefits of open source-compatible monitoring with the ease of use of Google-scale managed services. Learn more here.
Analysis Summary
# Industry News: Google Cloud Accelerates Cloud-Native Adoption and Supply Chain Security
## Summary
Google Cloud has announced a significant expansion of its cloud-native ecosystem, focusing on the General Availability (GA) of Apache Spark on Google Kubernetes Engine (GKE) and the introduction of advanced serverless runtimes. A major strategic highlight is the promotion of the SLSA framework to address escalating software supply chain security concerns.
## Key Details
- **Date:** February 28 – April 15, 2022 (Summary of multi-week updates)
- **Companies Involved:** Google Cloud, CNCF, Apache Software Foundation, NCR, Cruise, L’Oréal.
- **Category:** Product Launch / Ecosystem Expansion / Security Framework
## The Story
During the spring of 2022, Google Cloud executed a broad strategy to bridge the gap between big data, serverless computing, and enterprise DevOps. The centerpiece was the GA of Dataproc on GKE, allowing organizations to unify Spark-based data processing with containerized application management.
Simultaneously, Google addressed developer friction by launching new runtimes for App Engine and Cloud Functions (Java 17, Python 3.10, etc.) and simplifying the migration path from VMs to serverless via Cloud Run. Structurally, the graduation of Knative to a CNCF incubating project and the GA of Managed Service for Prometheus signal Google’s commitment to open-standards-based cloud infrastructure, positioning Google Cloud as the most "open" alternative to AWS and Azure.
## Business Impact
### For the Companies Involved
- **Google Cloud:** Solidifies its position as the preferred platform for high-end Kubernetes and data engineering workloads.
- **NCR & BeReal:** Demonstrate the ability to scale rapidly using Google’s managed services, reducing time-to-market for complex transaction and social media platforms.
### For Competitors
- **AWS & Microsoft Azure:** Face increased pressure as Google simplifies the transition from legacy VMs to serverless, lowering the barrier to entry for GCP.
- **Databricks:** Faces direct competition from the general availability of managed Spark on GKE.
### For Customers
- **Enterprises:** Gain better cost control through "always-on CPU" for Cloud Run and reduced operational overhead via Managed Prometheus.
- **Developers:** Benefit from modern language support and easier infrastructure-as-code integration with new Terraform export tools.
### For the Market
- **Standardization:** The industry is moving toward "Open Operations," where managed services are expected to be compatible with open-source standards like Prometheus and OpenTelemetry.
## Technical Implications
The release of **Declarative Export for Terraform** within the Google Cloud CLI is a significant technical shift, allowing teams to reverse-engineer existing manual cloud setups into reproducible code. Additionally, the **SLSA (Supply-chain Levels for Software Artifacts)** framework provides a technical roadmap for achieving verifiable build integrity, moving beyond simple vulnerability scanning.
## Strategic Analysis
- **Market Positioning:** Google is doubling down on "The Programmable Cloud," focusing on developers and SREs (Site Reliability Engineers) rather than just IT procurement.
- **Competitive Advantage:** Deep integration between GKE and data tools (Dataproc/Spark) creates a "sticky" ecosystem for data-heavy enterprises.
- **Challenges:** Despite technical superiority in Kubernetes, Google must still overcome the market share dominance of AWS in the general enterprise sector.
## Industry Reactions
- **Analyst Opinions:** Generally positive regarding the Knative graduation, viewing it as a sign of maturity for serverless standards.
- **Market Response:** Substantial interest from the public sector and traditional finance (e.g., State of Rhode Island, NCR) indicates Google is successfully moving beyond its "startup-only" reputation.
## Future Outlook
- **Predictive Trend:** Expect a massive shift toward "Serverless Spark" and container-based data science as silos between data engineers and DevOps teams continue to dissolve.
- **Watch For:** Increased adoption of the SLSA framework as a requirement for government and regulated industry contracts.
## For Security Professionals
The most critical takeaway is the focus on **SLSA (Supply-chain Levels for Software Artifacts)**. As software supply chain attacks (like Log4j or SolarWinds) become more frequent, practitioners should evaluate Google’s SLSA framework to secure their build pipelines. Furthermore, the GA of **Managed Service for Prometheus** allows security teams to monitor Kubernetes clusters for anomalies using industry-standard tools without the burden of managing the underlying monitoring infrastructure.