FinOps Scale-to-Zero Architecture on Google Cloud Platform
Building modern cloud infrastructure requires balancing high availability, enterprise security, and ruthless cost discipline. At Austin Software Services, we established a strict architectural mandate: our entire platform and blog tier must maintain a hard ceiling of under $30/month while scaling seamlessly to production workloads.
Here is the exact engineering breakdown of how we achieved true scale-to-zero on Google Cloud Platform using Terraform.
1. The Cost Trap: Cloud NAT vs. Direct VPC Egress
One of the most insidious costs in cloud networking is the managed NAT Gateway. In traditional GCP architectures, private Cloud Run services routing to VPC subnets require a Serverless VPC Access Connector combined with Cloud NAT.
- Cloud NAT baseline fee: $0.044/hour + $0.045/GB egress = ~$32.00/month even at 0 traffic!
- Serverless VPC Access Connector: Minimum 2
e2-microinstances = ~$15.00/month.
The Solution: Direct VPC Egress with PRIVATE_RANGES_ONLY
With the release of Cloud Run v2, Google introduced Direct VPC Egress, allowing containers to attach directly to VPC subnets without a connector:
vpc_access {
network_interfaces {
network = "projects/austinss-web-dev/global/networks/austinss-vpc-dev"
subnetwork = "projects/austinss-web-dev/regions/us-central1/subnetworks/austinss-subnet-dev"
}
egress = "PRIVATE_RANGES_ONLY"
}
By setting egress = "PRIVATE_RANGES_ONLY", internal traffic to private IP addresses routes securely through your VPC, while all public internet egress (outbound API calls, webhooks) routes directly via Google Front End (GFE) for $0.00/month base cost.
2. Serverless Compute: Scale-to-Zero Autoscaling
Cloud Run v2 allows setting min_instances = 0 in non-production environments:
scaling {
min_instance_count = 0
max_instance_count = 3
}
When idle, container instances terminate completely. The service incurs $0.00 compute charges during off-hours. With Google's free tier offering 2 million free requests and 360,000 vCPU-seconds monthly, standard development testing is virtually free.
3. Database & Storage Tier
- Cloud Firestore Native: Single-region
us-central1offers 50,000 daily read operations and 20,000 daily writes permanently free. - Cloud Storage (Media): 5 GB-months of Regional Standard Storage in
us-central1is included in GCP Free Tier. Lifecycle rules automatically purge incomplete multipart uploads after 7 days and delete superseded object versions after 30 days.
lifecycle_rule {
action {
type = "Delete"
}
condition {
days_since_noncurrent_time = 30
num_newer_versions = 2
}
}
Summary
By eliminating managed NAT gateways, adopting Direct VPC Egress, and enforcing min_instance_count = 0 with GCP free-tier storage boundaries, you can build enterprise-ready architectures that sleep for free and scale on demand.