पाठ 21 / 25
Private Connectivity and DNS
Reach managed services and other networks privately.
Keeping traffic off the internet
Several features keep traffic private. Private Google Access lets VMs without external IPs call Google APIs. Private Service Connect creates an endpoint with an internal IP in your VPC for Google APIs or for a producer's service, so you can reach, for example, a managed database or a partner's service by private address. Private services access (VPC peering to a Google-managed network) is how services such as Cloud SQL and Memorystore get private IPs. VPC Network Peering connects two VPCs, but it is not transitive. Cloud VPN (HA VPN) and Cloud Interconnect connect on-premises networks. Cloud DNS hosts public and private zones visible only to chosen VPCs, which you need for private endpoints to resolve correctly. Serverless services such as Cloud Run reach VPC resources through Direct VPC egress or Serverless VPC Access connectors.
Cloud Run reaching a private Cloud SQL IP
Direct VPC egress puts the service's outbound traffic into a subnet.
gcloud compute addresses create google-managed-services --global --purpose=VPC_PEERING \
--prefix-length=16 --network=shop-vpc
gcloud services vpc-peerings connect --service=servicenetworking.googleapis.com \
--ranges=google-managed-services --network=shop-vpc
gcloud sql instances patch shop-pg --network=shop-vpc --no-assign-ip
gcloud run services update orders-api --region=asia-south1 \
--network=shop-vpc --subnet=web-asia-south1 --vpc-egress=private-ranges-onlyPlan IP ranges for the whole company
Peering, VPN and private services access all fail if ranges overlap. Reserve address blocks for each environment and for Google-managed services early.
त्वरित जाँच: VPC A peers with B, and B peers with C. Can A reach C through B?
- Yes, peering is transitive
- Only for Cloud Run
- No, VPC peering is not transitive
- Only if all are auto-mode networks
Answer
No, VPC peering is not transitive — VPC Network Peering is non-transitive; A needs its own peering or another connectivity design.