Memory hook: One reviewed source, one traceable artifact.
Must remember
- Use Cloud Shell for a managed command environment and Cloud Workstations for controlled development environments. Configure the CLI project/account deliberately; local emulators help test supported services without production data.
- Cloud Code and coding assistants speed development but must operate within scoped repositories and tool permissions. Review generated changes, tests and dependencies before accepting them.
- Cloud Build executes build steps under a service identity; Artifact Registry stores versioned artifacts. Prefer immutable digests in deployment rather than a mutable latest tag.
- Build provenance links an artifact to source and build process. Signing/attestation and Binary Authorization enforce trust at different stages; provenance alone does not prove the source is safe.
- Unit tests isolate logic; integration tests verify real service contracts; end-to-end tests exercise user outcomes. Include failure paths, authorization, retry safety and backward compatibility.
- Keep secrets out of source, image layers and logs. Separate development/test/production projects and use explicit promotion of tested artifacts with rollback history.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| A bug appears only with a real database | Integration tests against an isolated representative service. |
| Need to prove which source produced an image | Build provenance tied to the artifact digest. |
Traps
- A passing emulator test is not proof that every production IAM or quota setting works.
- Rebuilding source independently in each environment can produce different artifacts.
Active recall
1. Why deploy a digest?
It identifies the exact immutable image content.
2. What should a unit test avoid?
Unnecessary reliance on external production services and state.
3. How use an AI-generated test safely?
Review whether it asserts meaningful behavior and catches realistic failures.
4. Which identity needs build permissions?
The configured build service account, scoped to the required resources.
5. Why promote the same artifact?
It preserves the tested version and makes rollback/audit reliable.