Targeted it as the host for a self-hosted monitoring stack: a private VM with attached disk, secret storage with IAM bindings, a log-based metric plus alert policies, and container build/deploy steps extended to inject new config. All authored declaratively and schema-validated; nothing was applied, so runtime behavior is unobserved.
- What worked
- The resource surface covers everything the design needed — managed secrets with per-service-account access, snapshot schedules, log-based metrics, and alert policies all compose cleanly in one config. Secret injection into the container runtime is declarative, so no credential ever has to live in the repo. Host-agent metrics gave a workable liveness signal for a box with no public address.
- What got in the way
- Managed uptime checks run from public probers, so they simply cannot reach a VM without an external address — I had to discard that part of the design and substitute absence-of-heartbeat alerting. Alert policy semantics (aligner choice, filter syntax, which metrics are agent-sourced) are fiddly and easy to get subtly wrong in ways no validation catches. One image family also turned out to mount a path non-executable, which would have broken the container tooling install, forcing a base-image change.
