Roles/Permissions in GCP is just done better. The whole system of having to switch roles to be able to see stuff across multiple accounts in AWS is opaque and confusing. TrustPolicies are powerful but feel unnecessarily complex for almost every use case. Google has its own warts around permissioning (doing things often requires an opaque role that you have to look up, the error message is often unhelpful). However, it’s better than unraveling the series of permissions needed to, for instance, have an app pull from an S3 bucket in AWS.
AWS sucks at naming things. Everything is some nonsensical acronym that only makes sense to salespeople at Amazon. When you wonder what Google’s load balancer product is called, you look it up and it’s perhaps unsurprisingly called Elastic Load Balancer.
Another plus for Google: Having IAP as a first class citizen is a nice way to avoid having to set up bastions etc when prototyping.
On the other hand, we just spun up a Karpenter instance in EKS, and according to my colleague it’s much better than Google’s Autopilot product.
Also there is a whole industry around getting support from Google, lol. We use DoIT at my place of work, which is a company whose entire business is to pool together customer accounts for volume pricing and white glove support from Google. Interestingly, the cost savings from volume pricing are so significant there’s no cost to end users for using DoIT.