GoogleCloudPlatform / GoogleCloudPlatform/pubsec-declarative-toolkit

FinOps: Options for IDS (associated LBs), Armor and internal/zonal network Egress pricing

Open
#371 1 comment 0 reactions 1 assignee Claimed by @fmichaelobrien View on GitHub
Networking
Dominant language
Shell
Stars
36
Forks
26
PR merge metrics
No merged PRs in 30d

Description

Pricing scenarios for LZ options with/without the following services around L4 to L7 packet inspection
- Cloud IDS
- Cloud Armor (use Traffic Generator example app)
- Cloud Firewall (use Traffic Generator example app)
- PII (as part of VPC-SC)
- Premium Networking (32 Gbps - outbound, VM to public IP 7Gbps) = VM Tier_1 - requires minimum vCPUs of
- 48 vCPU = 50Gbps/25Gbps (outbound/publicIP), CC = 295/mo, per VM Tier_1 361/mo
- 64 vCPU - same as above but CC/393/mo and Tier_1 361/mo
- 96 vCPU = 100Gbps/25Gbps (outbound/publicIP), CC = 590/mo, per VM Tier_1 722/mo
- higher to 224 vCPUs no change in 100Gpbs
Confidential Computing (requires N2D AMD EPYC CPU platform and Ubuntu 20.04 LTS Pro FIPS server min OS - a premium image at flat 0.000127 GB/hr $0.034/hr for 18-48 vCPUs - does not participate in spot/preemptible pricing - for N2d-standard-48 / 192Gb the premium image usage fee is = .034/hr/48vCPU + 0.000127 GB/hr (for 192Gb = .025/hr) = total of .058/hr = 42/mo for confidential computing in general PAYG not 3 year reserved = 0.269/hr) - not required for PBMM - may be for PBHH TBD -

- PBMM via SI-7 https://github.com/GoogleCloudPlatform/pbmm-on-gcp-onboarding/blob/main/docs/google-cloud-security-controls.md#6780si-7software-firmware-and-information-integrity requires only that Shielded VMs (no additional cost) are enabled https://github.com/GoogleCloudPlatform/pbmm-on-gcp-onboarding/blob/main/docs/google-cloud-security-controls.md#compute---shielded-vms for example even though the GKE cluster running the infrastructure has the following organization policy set to false https://github.com/GoogleCloudPlatform/pubsec-declarative-toolkit/issues/132 - we set it to true for all workloads involving IaaS GCE and PaaS GKE constraints/compute.requireShieldedVm = true
- N2-32 VMs (Active-Passive and Active-Active NGFWs) - https://cloud.google.com/compute/docs/machine-resource#recommendations_for_machine_types
- Assured workloads

In terms of
- flat cost
- project percentage cost
- egress cost
- free tier limits
- Network tier costs
- capacity limits (5Gb IDS limit per endpoint)
- quota capacity (ie: 25 peer limit)
-

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.