7 min read

    07 - Hands-on Lab - Setting Up Your First GCP Project & Cloud Shell

    gcpcloudlabcloudshell

    Welcome to Day 07 of Learn GCP in 30 Days! Today is your Week 1 Capstone Hands-on Lab.

    🎯

    Today's Goal Congratulations on completing Week 1! Today, you will put all of Week 1's concepts into practice: creating your first GCP Project, launching Cloud Shell terminal, running foundational gcloud CLI commands, and inspecting your IAM security permissions live.


    Lab Architecture: What We Are Building Today

    In this lab, you will complete 4 hands-on tasks:

    mermaid

    Step-by-Step Lab Instructions


    Task 1: Create Your First GCP Project

    1. Open your browser and log into console.cloud.google.com.
    2. Click the Project Selector dropdown in the top bar (next to the Google Cloud logo).
    3. Click New Project in the top-right of the pop-up window.
    4. Fill in the project details:
      • Project Name: gcp-lab-day07
      • Organization / Location: Leave as default (No Organization if using a personal account).
    5. Click Create and wait 10 seconds.
    6. Locate Your Created Project in the UI:
      • Click the Project Selector dropdown in the top bar again.
      • Look under the No Organization tab/filter (since personal accounts have no organization node, your project lives here).
      • You will see your newly created gcp-lab-day07 project listed!
    📌

    Important Note: Don't Select It Manually Yet! You can see and select your project from this UI dropdown, but do not select it manually right now! In Task 3, we are going to learn how to select and switch to this project using gcloud CLI commands.

    Action Required: Copy your unique Project ID (e.g. gcp-lab-day07-482910) and save it in your notes.


    Task 2: Launch & Authorize Cloud Shell

    1. Look at the top-right control bar of your GCP Web Console.
    2. Click the Activate Cloud Shell (>_) icon.
    3. A terminal window will open at the bottom of your screen. Click Continue if prompted.
    4. When Cloud Shell finishes loading, run your first test command:
      bash
      gcloud auth list
      
    5. A pop-up dialog will ask: "Authorize Cloud Shell to make GCP API calls?" Click Authorize.

    Output should show your active Google account email:

    text
    Credentialed Accounts
    ACTIVE  ACCOUNT
    *       alex@gmail.com
    

    Task 3: Run Foundational gcloud CLI Commands

    Now let's configure your terminal to point directly to your newly created project.

    Step 3.1: Set Your Active Project

    Replace YOUR_PROJECT_ID with your actual Project ID from Task 1:

    bash
    gcloud config set project YOUR_PROJECT_ID
    

    Output:

    text
    Updated property [core/project].
    

    Step 3.2: Verify Active Configuration

    Run the following command to check your active CLI settings:

    bash
    gcloud config list
    

    Output:

    text
    [core]
    account = alex@gmail.com
    disable_usage_reporting = True
    project = gcp-lab-day07-482910
    

    Step 3.3: List All Projects in Your Account

    To see all GCP projects associated with your account, type:

    bash
    gcloud projects list
    

    Output:

    text
    PROJECT_ID             NAME           PROJECT_NUMBER
    gcp-lab-day07-482910   gcp-lab-day07  918273645012
    

    Task 4: Project Access (Owner vs Member) & Inspect IAM

    Before inspecting IAM policy commands, let's understand how team members join projects created by others.

    Understanding Project Sharing (Owner vs. Member POV)

    In a real-world software team, one person creates the project (Owner), and other developers join it.

    • Owner's Perspective (How to Add a Team Member):

      1. Open the left navigation menu ☰ →\rightarrow Go to IAM & Admin →\rightarrow Click IAM.
      2. Click the Grant Access (or Add) button at the top of the page.
      3. Under New Principals, enter the team member's Google email (e.g. teammate@gmail.com).
      4. Under Select a Role, assign them a role (e.g. Viewer or Compute Admin).
      5. Click Save.
    • Member's Perspective (How a Joined Member Accesses the Project):

      1. The team member receives an email invitation.
      2. When they log into console.cloud.google.com, they click the Project Selector dropdown.
      3. They select the No Organization (or Company Name) tab, and the shared project appears in their list!
    💡

    Whose Billing Account Pays for Shared Projects & What Your Friend Sees

    • Who Pays?: Billing is tied to the Project, not to individual team members! When your friend builds inside your shared project, your linked Billing Account / $300 credit pays for all resources. Your friend is never charged.
    • What your friend sees when opening IAM / Billing: When your friend opens the project and clicks on IAM & Admin or Billing, GCP displays "Link Billing Account".
    • Why this happens: A Billing Account (your credit card profile) is a separate security asset from a Project. Because you granted your friend access to the Project (e.g. Viewer or Editor) but NOT access to your private Billing Account, GCP hides your payment profile for security. To your friend's account, GCP prompts them to "Link Billing Account" if they wish to attach a billing profile of their own.

    Inspecting Your Project's IAM Policy via CLI

    Now, let's use gcloud to view the active IAM security policy attached to your project:

    bash
    gcloud projects get-iam-policy YOUR_PROJECT_ID
    

    Output will display the IAM roles assigned to your account (e.g. roles/owner):

    yaml
    bindings:
    - members:
      - user:alex@gmail.com
      role: roles/owner
    etag: BwX1yZ2a3b4=
    version: 1
    

    Signal vs. Noise: Key Concepts & Noise Filter

    🧠

    Good to Know (Key Concepts)

    • gcloud auth list: Displays the active authenticated user account.
    • gcloud config set project YOUR_PROJECT_ID: Sets the target project for all subsequent CLI commands.
    • gcloud config list: Displays active CLI configuration.
    • gcloud projects list: Lists all projects associated with your account.
    • Project Sharing: Owners grant access under IAM & Admin; members see shared projects inside their Project Selector.
    ℹ️

    Noise Filter (Don't Memorize)

    • Do NOT try to memorize gcloud flag syntax parameters—type gcloud help or append --help to any command (e.g. gcloud compute instances create --help) to view full manual documentation directly in terminal!

    Common Doubts & Interview Traps

    Q1: What should I do if gcloud config set project returns "ERROR: Project [xyz] not found"?

    • Answer: Check whether you accidentally typed the Project Name instead of the Project ID! gcloud requires the globally unique Project ID (e.g., gcp-lab-day07-482910).

    Q2: Does opening Cloud Shell or running these gcloud commands cost money?

    • Answer: No! Cloud Shell, gcloud CLI commands, and project creation are 100% free. You only incur costs when launching paid infrastructure resources (like VMs or Cloud SQL databases).

    Daily Practice Drill & Self-Check

    Test your understanding of today's lab:

    text
    // Try answering these:
    1. Which command should you run to verify which Google account is currently logged into gcloud CLI?
    2. How does a team member access a GCP project created and shared by another developer?
    
    💡 Click for Solutions
    1. Run gcloud auth list!
    2. They log into console.cloud.google.com, click the Project Selector dropdown, and select the shared project from the list under the No Organization (or company) tab!

    🎉 Congratulations! You have completed Day 07 and Week 1!

    You have mastered cloud fundamentals, Web Console UI navigation, interaction methods, Resource Hierarchy, Billing safety, IAM security, and successfully completed your first hands-on lab using Cloud Shell CLI.

    Tomorrow on Day 08, we kick off Week 2: Core Compute & Networking with VPC Networking, Subnets and IP Ranges!


    ← 06 - IAM & Access Management - Users, Roles, Service Accounts | Next Topic → 08 - VPC Networking, Subnets and IP Ranges