Private Service Access
Google Cloud offers three ways for private addresses to reach Google's own services without the internet. The GCP Enterprise Baseline prepares all three in every VPC network: Private Google Access on every workload subnet, a Private Service Access range per stage, and a Private Service Connect subnet per stage.
What it does
- Private Google Access lets a resource without an external IP call Google APIs, such as Cloud Storage or Secret Manager, over Google's network. It is a setting of each subnet.
- Private Service Access connects a VPC to a Google-managed service producer network through VPC peering. The VPC reserves internal ranges, allocates them to the
servicenetworking.googleapis.comconnection, and managed services that use this model take their addresses from those ranges. - Private Service Connect (PSC) puts a service behind an endpoint, a forwarding rule with an internal address in the consumer's own subnet, without peering. A Private Service Connect subnet holds addresses for published services.
How BuiltForProd uses it
Private Google Access is on for every workload subnet of the three VPC networks, so nodes, Cloud Run direct VPC egress and Dataproc batches reach Google APIs without Cloud NAT. The sts.googleapis.com, iamcredentials.googleapis.com and other APIs the platform calls are enabled per project by the project baseline.
Private Service Access. network_map.yaml reserves a psa_range for each stage and for the hub, a /22 such as 10.0.40.0/22 for prod. The vpc module creates one global address of purpose VPC_PEERING per range, named for example psa-acme-prod-usw1-prd, and peers all of a network's ranges with Google's producer network through one servicenetworking.googleapis.com connection per VPC. The connection is abandoned rather than deleted on removal, because the producer side may still hold instances. These ranges serve the Google-managed services that still use peering; the ranges never overlap the stage subnets because the map checks containment.
Private Service Connect. Each stage has a psc subnet (a /24 such as 10.0.38.0/24 for prod) of purpose PRIVATE_SERVICE_CONNECT. The Web App Blueprint reaches Memorystore for Valkey through consumer endpoints it creates itself in the stage's data subnet, and publishes the primary endpoint's address as redis--host in Secret Manager. Because an endpoint names the Shared VPC network, the stage deployer holds the custom role sharedVpcNetworkUse (compute.networks.use) on the host, while its address still needs compute.networkUser on the stage's own subnet. The blueprint registers user-created endpoints rather than a service connection policy, because a policy is unique per network, region and service class and so cannot belong to one stage of a shared domain VPC.
Terms you will see
| Term | Meaning |
|---|---|
| Private Google Access | Calling Google APIs from private addresses, set per subnet. |
| Producer network | The Google-managed network that peered managed services live in. |
psa_range | The reserved range per stage in network_map.yaml. |
| Endpoint | A Private Service Connect forwarding rule with an internal address. |
| Service connection policy | An automatic endpoint policy, unique per network, region and service class. |
Where to read more
- GCP Enterprise Baseline overview and the GCP Web App Blueprint overview.
- Shared VPC for the grants an endpoint needs.
- Hub-and-spoke networking for the network design.