Skip to main content

Cloud NAT

Cloud NAT (network address translation) gives resources without an external IP address outbound access to the internet. On the GCP Enterprise Baseline no VM has an external IP, so each VPC network sends its internet-bound traffic through its own Cloud Router and Cloud NAT in each region.

What it does​

Cloud NAT is a software-defined service, not a gateway VM: it runs on a Cloud Router in one region and translates the private addresses of a network's subnets to NAT IP addresses for outbound connections. It is regional and zone-redundant. It reserves ports per VM for connections; with dynamic port allocation a VM gets more ports as it opens more connections. NAT IPs are allocated automatically by Google or chosen from reserved addresses. Cloud NAT can log translations and errors to Cloud Logging. It carries only outbound connections and their replies; it never accepts inbound ones.

How BuiltForProd uses it​

The vpc module creates one Cloud Router and one Cloud NAT per network per region: cr-acme-usw1-<domain> and nat-acme-usw1-<domain> for the hub, prod and nonprod VPC networks, all in acme-core-network, so egress stays in one project. The switches live in network.hcl of the region:

GCP/acme-gcp-platform-baseline/environments/core/network/us-west1/network.hcl (lines 15-17)
enable_cloud_nat = true # @optional: one Cloud NAT per VPC per region (~$32/month each + $0.045/GB)
nat_min_ports_per_vm = 64 # @optional: raise for connection-heavy workloads
nat_log_filter = "ERRORS_ONLY" # @optional: ALL logs every connection (Logging cost)
SettingValue
enable_cloud_natOn: about $32 per month per NAT plus $0.045 per GB (code comment)
Source rangesEvery subnet and every range of the network, GKE pod ranges included
NAT IP allocationAutomatic (AUTO_ONLY); reserved addresses replace it when partners allow-list egress IPs
Portsnat_min_ports_per_vm = 64, dynamic port allocation on
Loggingnat_log_filter = "ERRORS_ONLY"; ALL logs every connection, at Logging cost

Why every network has its own. Each isolation-domain VPC keeps its own egress, so prod and nonprod share no NAT and no default route. Each network keeps Google's default internet route, which carries the NAT egress.

What may leave. The network firewall policy of each VPC allows egress on TCP 80 and 443 and UDP 53 and 123, logs and denies private destinations outside the domain and the hub, and ends with a logged deny of every other egress, so nothing leaves through the NAT on another port (Cloud NGFW firewall policies). Google APIs do not need the NAT: Private Google Access on every workload subnet reaches them directly.

What uses it. The Web App Blueprint's private GKE nodes and pods, the Data and ETL Blueprint's trigger service through direct VPC egress on the stage's data subnet and its Spark batches, and the optional bastions and runners all leave through the NAT of their network. The organization policy compute.vmExternalIpAccess denies external IPs to every VM, so there is no other way out. Cloud NAT and Cloud Router logs reach the central log bucket through the organization sink.

Terms you will see​

TermMeaning
Cloud RouterThe regional control-plane resource Cloud NAT runs on.
NAT IPThe public address outbound connections leave from.
Dynamic port allocationMore NAT ports for a VM as it opens more connections.
ERRORS_ONLYThe NAT log filter that records only dropped translations.
Private Google AccessReaching Google APIs from private addresses, without the NAT.

Where to read more​