Blueprints
Reference architectures every submitted design is held against — 13 published by the architecture office, 1 derived from designs that were already reviewed. 12 are for Google Cloud; 2 say what good looks like on an estate the group did not choose.
v2.3Public web application and API on Cloud Run behind one external HTTPS load balancer with Cloud Armor, customer identity from Identity Platform, administration behind Identity-Aware Proxy, and Cloud SQL and Cloud Storage held privately inside a VPC Service Controls perimeter.
v2.0Google Cloud workloads reach SAP S/4HANA in Mannheim only by publishing to a Pub/Sub buffer that one dispatcher drains through a single internal load balancer and two Cloud Interconnect attachments with mutual TLS, so an outage at either end delays work instead of losing it.
v1.7Partner and internal consumers call Cloud Run services only through Apigee with mutual TLS and OAuth 2.0, while Cloud SQL and Memorystore stay on private IPs inside the API VPC.
v1.2Registered senders drop files over Private Service Connect into a landing bucket, Cloud Scheduler runs a Cloud Run job that verifies each file against its manifest before loading Cloud SQL and BigQuery, rejected files go to a quarantine bucket and a Pub/Sub dead-letter topic, and a late or malformed file pages the Integration Platform rota.
v1.1Product documentation, datasheets and signed firmware are served from a Cloud Storage origin through Cloud CDN behind one external HTTPS load balancer with Cloud Armor, restricted artefacts are reached only through a fifteen-minute signed URL issued by a Cloud Run service, and a Cloud Build pipeline publishes immutable content-hashed objects and invalidates just the paths it changed.
v1.2A private Autopilot cluster published through one external HTTPS load balancer with Cloud Armor, admitting only images the Northwind pipeline signed, with pods federated to their own service accounts and Cloud SQL held on private IP inside a VPC Service Controls perimeter.
v1.4On-premises producers publish to Pub/Sub over Cloud Interconnect, Dataflow validates and enriches the stream into BigQuery and a Cloud Storage archive inside a VPC Service Controls perimeter, and Looker consumers reach the warehouse only through Identity-Aware Proxy.
v1.0Identity Platform holds the customer directory with authenticator or passkey enrolment, a Cloud Run service issues and validates tokens behind one external HTTPS load balancer with per-endpoint Cloud Armor rate limits, Firestore holds profiles inside a VPC Service Controls perimeter, and a nightly job carries out deletion, dormancy and token expiry.
v1.2An employee-facing agent on Cloud Run behind Identity-Aware Proxy that plans with Vertex AI function calling but acts only through a tool broker, which is the sole holder of credentials, checks each call against the requester's entitlements, refuses any write without a second person's approval and appends every attempt to a BigQuery action log.
v1.1Analysts reach Vertex AI Workbench notebooks through Identity-Aware Proxy and query BigQuery and Cloud Storage held inside a VPC Service Controls perimeter with customer-managed keys.
v1.0Employee-facing assistant on Cloud Run behind Identity-Aware Proxy that answers from enterprise documents through Vertex AI Vector Search with per-user entitlement filtering, screens every prompt and response with Model Armor, and keeps the model, index and conversation store inside a VPC Service Controls perimeter.
v1.0Supplier invoices and warranty claims land in a perimeter-held bucket under customer-managed keys, are extracted by Document AI with the payment-detail fields disabled, and reach the on-premises ERP only after a named reviewer has confirmed every field.
v1.4The shape a web application takes when a named Microsoft dependency puts it on Azure: Application Gateway with the WAF in Prevention mode as the only public address, a zone-redundant App Service with public access disabled and route-all virtual network integration, Entra ID and a user-assigned managed identity instead of connection strings, and Azure SQL Database, Key Vault and Storage reached over Private Link with diagnostic settings shipped to the central workspace.
v1.1What an inherited three-tier AWS workload must be brought to while it waits for its migration date: Route 53, CloudFront and an Application Load Balancer behind AWS WAF with ACM certificates, EC2 and RDS in private subnets with no public addresses, and the group controls laid over the top — an organisation trail to the log archive account, IAM Identity Center federated to Entra ID with no local users, no public S3, and backups held under a separate account's key.