Cloud NAT
Cloud NAT (network address translation) gives resources without an external IP address outbound access to the internet. On the GCP Enterprise Baseline no VM has an external IP, so each VPC network sends its internet-bound traffic through its own Cloud Router and Cloud NAT in each region.
What it does
Cloud NAT is a software-defined service, not a gateway VM: it runs on a Cloud Router in one region and translates the private addresses of a network's subnets to NAT IP addresses for outbound connections. It is regional and zone-redundant. It reserves ports per VM for connections; with dynamic port allocation a VM gets more ports as it opens more connections. NAT IPs are allocated automatically by Google or chosen from reserved addresses. Cloud NAT can log translations and errors to Cloud Logging. It carries only outbound connections and their replies; it never accepts inbound ones.
How BuiltForProd uses it
The vpc module creates one Cloud Router and one Cloud NAT per network per region: cr-acme-usw1-<domain> and nat-acme-usw1-<domain> for the hub, prod and nonprod VPC networks, all in acme-core-network, so egress stays in one project. The switches live in network.hcl of the region:
enable_cloud_nat = true # @optional: one Cloud NAT per VPC per region (~$32/month each + $0.045/GB)
nat_min_ports_per_vm = 64 # @optional: raise for connection-heavy workloads
nat_log_filter = "ERRORS_ONLY" # @optional: ALL logs every connection (Logging cost)
| Setting | Value |
|---|---|
enable_cloud_nat | On: about $32 per month per NAT plus $0.045 per GB (code comment) |
| Source ranges | Every subnet and every range of the network, GKE pod ranges included |
| NAT IP allocation | Automatic (AUTO_ONLY); reserved addresses replace it when partners allow-list egress IPs |
| Ports | nat_min_ports_per_vm = 64, dynamic port allocation on |
| Logging | nat_log_filter = "ERRORS_ONLY"; ALL logs every connection, at Logging cost |
Why every network has its own. Each isolation-domain VPC keeps its own egress, so prod and nonprod share no NAT and no default route. Each network keeps Google's default internet route, which carries the NAT egress.
What may leave. The network firewall policy of each VPC allows egress on TCP 80 and 443 and UDP 53 and 123, logs and denies private destinations outside the domain and the hub, and ends with a logged deny of every other egress, so nothing leaves through the NAT on another port (Cloud NGFW firewall policies). Google APIs do not need the NAT: Private Google Access on every workload subnet reaches them directly.
What uses it. The Web App Blueprint's private GKE nodes and pods, the Data and ETL Blueprint's trigger service through direct VPC egress on the stage's data subnet and its Spark batches, and the optional bastions and runners all leave through the NAT of their network. The organization policy compute.vmExternalIpAccess denies external IPs to every VM, so there is no other way out. Cloud NAT and Cloud Router logs reach the central log bucket through the organization sink.
Terms you will see
| Term | Meaning |
|---|---|
| Cloud Router | The regional control-plane resource Cloud NAT runs on. |
| NAT IP | The public address outbound connections leave from. |
| Dynamic port allocation | More NAT ports for a VM as it opens more connections. |
ERRORS_ONLY | The NAT log filter that records only dropped translations. |
| Private Google Access | Reaching Google APIs from private addresses, without the NAT. |
Where to read more
- GCP Enterprise Baseline overview for the network switches and their prices.
- VPC networks for the networks each NAT serves.
- Hub-and-spoke networking for central egress.