Part 7 · 2 chapters · ~15 min
AWS and GCP Side by Side
One wallet API built on both clouds tier by tier, with a service map that includes Azure for reference; then the five differences that actually change designs: network scope, organisation and identity, load balancer scope, serverless containers and analytics, and what exists in Africa.
20
The same design, service by service
one product, two clouds
- Edge and web: a CDN in front of a private bucket, with a WAF.
- Compute and load balancing: Fargate behind a regional ALB, or Cloud Run behind a global ALB.
- Data: managed Postgres with HA plus managed Redis, reachable privately only.
- Storage and events: signed URLs, a queue with dead-lettering, and a stream into analytics.
- Identity: roles or service accounts per service, a secret store and KMS.
- Observability: each provider's stack, or OpenTelemetry to a vendor.
| need | AWS | GCP | Azure (for reference) |
|---|---|---|---|
| VMs | EC2 | Compute Engine | Virtual Machines |
| managed Kubernetes | EKS | GKE (Autopilot) | AKS |
| serverless containers | Fargate, App Runner | Cloud Run | Container Apps |
| functions | Lambda | Cloud Functions | Functions |
| object storage | S3 | Cloud Storage | Blob Storage |
| managed Postgres | RDS, Aurora | Cloud SQL, AlloyDB | Database for PostgreSQL |
| key-value / document | DynamoDB | Firestore, Bigtable | Cosmos DB |
| cache | ElastiCache, MemoryDB | Memorystore | Cache for Redis |
| queue | SQS | Cloud Tasks, Pub/Sub | Service Bus, Queue Storage |
| stream | Kinesis, MSK | Pub/Sub, Managed Kafka | Event Hubs |
| warehouse | Redshift, Athena | BigQuery | Synapse, Fabric |
| CDN | CloudFront | Cloud CDN, Media CDN | Front Door |
| DNS | Route 53 | Cloud DNS | Azure DNS |
| secrets / keys | Secrets Manager / KMS | Secret Manager / Cloud KMS | Key Vault |
| IaC (native) | CloudFormation, CDK | Infrastructure Manager (Terraform) | Bicep, ARM |
| observability | CloudWatch, X-Ray | Cloud Logging, Monitoring, Trace | Monitor, App Insights |
deeper
The older Deploying The Core Bank module builds one specific system, a core bank, on both clouds and prices it. This chapter is the general map; that module is the worked example.
ONE DESIGN, TWO CLOUDS
a wallet API with uploads, events and a ledger, built on AWS and on GCP, tier by tier
swipe the figure sideways, or tap expand for full screen
1/6
edge, web
Edge and web: AWS CloudFront in front of an S3 bucket (origin access control) for the static app, with AWS WAF; GCP Cloud CDN behind the global external Application Load Balancer with a GCS backend bucket, with Cloud Armor. Both terminate TLS at the edge with managed certificates.
21
Where the clouds really differ
five differences that change designs
- Network scope: AWS VPCs are regional; GCP VPC networks are global.
- Organisation: AWS uses accounts as the boundary; GCP uses a project hierarchy with inherited IAM.
- Load balancing: GCP's front end is global anycast; AWS ALBs are regional.
- Serverless containers: Cloud Run is the GCP default. AWS splits the same job across three services.
- Analytics: BigQuery and Spanner are GCP's distinctive services.
- In Africa: both clouds have South African regions and West African edge locations. Check service availability before choosing a region.
multi-cloud
Running one product actively on two clouds doubles the platform work and keeps you to the services both share. It is rarely worth it for availability, since a second region on one cloud is cheaper and simpler. It is sometimes worth it for regulation, negotiation leverage, or a service only one cloud has. Portability through containers, Terraform, OpenTelemetry and Postgres is cheap insurance. Active multi-cloud is an expensive policy.
WHERE THE CLOUDS REALLY DIFFER
the five differences that change designs, not just service names
swipe the figure sideways, or tap expand for full screen
1/6
network scope
Network scope: an AWS VPC lives in one region, with subnets per zone; going multi-region means a VPC per region and connecting them. A GCP VPC network is global, with subnets per region; instances in europe-west1 and africa-south1 share one private network out of the box. Multi-region private networking is simpler on GCP.