The Google Distributed Cloud (GDC) air-gapped solutions guides bridge the gap between out-of-the-box product capabilities and production-ready enterprise architectures. These guides equip platform administrators and application operators with conceptual frameworks, reference architectures, and practical implementation steps to run critical workloads in GDC air-gapped environments.
The solutions guides adhere to strict requirements for performance, security, and data sovereignty.
Document types
Solutions are documented across three complementary document types:
- Reference architectures: Architectural blueprints that outline design principles, system topology, component interactions, and security controls for deploying a solution.
- Reference implementations: Step-by-step guides for installing, configuring, and verifying the infrastructure, dependencies, and software deployment on GDC clusters.
- User guides: Day-2 operational guides covering practical administration, service configuration, monitoring, scaling, and ongoing maintenance.
Available solutions
The following sections list the available solution guides for GDC air-gapped, organized by technical domain matching the Google Cloud Architecture Center.
AI and machine learning
- AI Gateway
- Reference architecture: Centralized routing, protocol mediation, and traffic management for large language models (LLMs).
- Envoy
- Reference implementation: Deploy Envoy Gateway and Envoy Agent Router on a standard cluster.
- Body-based routing: Configure request payload inspection and content-based model routing.
- Open-weight LLMs
- Reference architecture: Architecture for deploying and serving open-weight large language models.
- Reference implementation: Deploy vLLM and serve open-weight models on standard clusters with GPUs.
- User guide: Configure Open WebUI and connect to served open-weight models.
Databases
- Self-managed MySQL databases
- Reference architecture: Design patterns for enterprise MySQL database topologies.
- Reference implementation: Deploy MySQL with replication and persistent volume management.
- Self-managed Oracle databases
- Reference architecture: Architectural blueprints for migrating Oracle databases to virtual machines.
- Deploy self-managed Oracle databases: Deploy single-instance Oracle databases on compute virtual machines.
- Deploy highly-available self-managed Oracle databases: Configure Oracle Data Guard for disaster recovery and high availability.
- Self-managed PostgreSQL databases
- Reference architecture: Architecture for scalable PostgreSQL database clusters.
- Reference implementation: Deploy and configure PostgreSQL with automated backups and replication.
Networking
- Self-managed Layer 7 load balancing
- Reference architecture: Architecture for application ingress routing and TLS termination.
- HAProxy reference implementation: Deploy and tune HAProxy for high-throughput Layer 7 traffic routing.
- NGINX reference implementation: Deploy and configure NGINX reverse proxy services.
Security and IAM
- Keyfactor EJBCA
- Reference architecture: Public key infrastructure (PKI) and certificate authority architecture.
- Reference implementation: Deploy Keyfactor EJBCA for enterprise certificate lifecycle management.