Soru

Zorluk: OrtaSelecting and Designing Storage and Database Resources

A regional media streaming company is architecting a storage backend for user profile management and subscription entitlements. The workload requires strict ANSI SQL compliance, full ACID transactional guarantees, automated regional high availability across multiple zones, and encryption at rest using Customer-Managed Encryption Keys (CMEK) via Cloud KMS. The total database footprint is estimated at 2 TB, and all application traffic originates within a single GCP region. Which GCP database service should the cloud architect recommend to fulfill these requirements while minimizing cost and operational complexity?

  1. Cloud SQL for PostgreSQL configured with High Availability (regional failover) and Customer-Managed Encryption Keys (CMEK).Cevap
  2. B
    Cloud Spanner provisioned with a regional instance configuration and Customer-Managed Encryption Keys (CMEK).
  3. C
    Cloud SQL for PostgreSQL configured with High Availability and Customer-Supplied Encryption Keys (CSEK).
  4. D
    Cloud Storage Dual-Region bucket storing relational data files encrypted with CMEK, integrated with BigQuery for querying.

Cevap

Cloud SQL for PostgreSQL configured with High Availability (regional failover) and Customer-Managed Encryption Keys (CMEK).
The correct recommendation is Cloud SQL for PostgreSQL configured with High Availability (HA) and Customer-Managed Encryption Keys (CMEK). Cloud SQL supports databases up to 64 TB, delivers full ANSI SQL compliance and ACID transactional semantics, provides regional cross-zone failover for high availability, and seamlessly integrates with Cloud KMS for CMEK governance at an optimal price point for single-region applications.

Adım Adım Çözüm

1
Analyze the workload storage requirements
Identified requirements for relational ANSI SQL, strict row-level ACID transactions, single-region deployment, 2 TB scale, high availability, and CMEK key management.
Establishing accurate data access patterns and scaling bounds determines the target GCP database class (OLTP vs OLAP vs NoSQL).
2
Compare candidate GCP database options against workload characteristics
Cloud SQL for PostgreSQL easily supports 2 TB relational OLTP workloads with multi-zone HA failover and Cloud KMS CMEK encryption in a single region. Cloud Spanner is over-provisioned and costly for non-global multi-region scale.
Choosing the appropriate managed database avoids over-engineering and controls infrastructure expenditure.
3
Validate security key management options
Cloud SQL integrates directly with Cloud KMS for Customer-Managed Encryption Keys (CMEK). Customer-Supplied Encryption Keys (CSEK) are not supported on Cloud SQL.
Ensuring regulatory security compliance requires choosing supported GCP encryption mechanisms.

Anahtar Kavram

Selecting Cloud SQL over Cloud Spanner for regional relational workloads
Tahmini Süre:1m 30s
Bu soruyu puanla