Google Cloud

Load Balancing — Global and Regional

Use the global load balancer and its single anycast IP, and know which balancer suits which protocol.

GCP's load balancing is its most distinctive service, because the external HTTP(S) balancer is global with one IP address.

One switchboard number answered at whichever exchange is nearest and still staffed — callers never learn a different number when one exchange goes dark.

Key Concepts

1
    Global external HTTP(S)   layer 7, one anycast IP worldwide,
                              CDN and Armor attach here
    Regional external         layer 7 or 4, within one region
    Internal HTTP(S)          layer 7, private, between tiers
    Internal passthrough TCP/UDP  layer 4, private
    Network (passthrough)     layer 4, preserves the client IP
2
One IP for the world is the thing to say. Users anywhere resolve to the same address, and Google's backbone carries them to the nearest healthy backend. No DNS routing, no per-region addresses, no TTL-bound failover.
3
The components, which the interview often walks through.
    forwarding rule  the IP and port
    target proxy     terminates TLS, applies the URL map
    URL map          path and host routing rules
    backend service  health check, balancing mode, backends
    backend          an instance group or a serverless NEG
4
Backends can be anything, which is unusual: managed instance groups, GKE services, Cloud Run, Cloud Functions, App Engine, a bucket, or an endpoint outside GCP entirely.
5
Balancing mode decides what "full" means.
    RATE          requests per second per instance
    UTILIZATION   CPU
    CONNECTION    concurrent connections (layer 4)
6
Health checks must mean something. One returning 200 unconditionally keeps broken instances in rotation; one that queries a shared database turns a single database blip into a total outage. Check what that instance needs to serve its own traffic.
7
Cloud CDN and Cloud Armor attach to the backend service, so caching and WAF are configuration on the balancer rather than separate products in front of it.
8
Traffic splitting is built in for canary releases — send 5% to a new backend service and increase it — without touching DNS.
9
The client IP needs care. The global balancer puts it in X-Forwarded-For; only the passthrough Network Load Balancer preserves the real source address on the socket.
X-Forwarded-For
10
What the interviewer is probing.1. "What is distinctive about the global external load balancer?" Probing: the single IP. Stalls: "It balances globally." Moves up: one anycast IP worldwide, so users everywhere resolve the same address and the backbone carries them to the nearest healthy backend — no DNS routing, no TTL-bound failover.
11
2. "Walk through the components." Probing: the structure. Stalls: "It is one thing." *Moves up:* forwarding rule, target proxy, URL map, backend service, backends — with health checks and balancing mode on the backend service.
12
3. "What can be a backend?" Probing: the breadth. Stalls: "Instance groups." Moves up: managed instance groups, GKE services, Cloud Run and Functions via serverless NEGs, buckets, and endpoints outside GCP.
13
4. "Which balancer preserves the client IP on the socket?" Probing: the layer difference. Stalls: "All of them." Moves up: only the passthrough Network Load Balancer; behind the global HTTP balancer it is in X-Forwarded-For.