VPC Network Peering
VPC Network Peering connects two VPC networks so their resources reach each other over private addresses. The GCP Enterprise Baseline peers the hub with each isolation-domain VPC and never the domains with each other, so prod and nonprod have no route between them.
What it does
A peering is two halves, one created in each network, and becomes active when both exist. Peered networks exchange their subnet routes, and optionally custom routes, in both directions. Peering is not transitive: if A peers with B and B with C, A still cannot reach C through B. Traffic stays on Google's network with the same latency as within one VPC, and firewall rules on each side still decide what is allowed.
How BuiltForProd uses it
The peering unit in acme-core-network (environments/core/network/us-west1) creates four peerings:
| Peering | From | To |
|---|---|---|
peer-acme-hub-to-prod | vpc-acme-hub | vpc-acme-prod |
peer-acme-prod-to-hub | vpc-acme-prod | vpc-acme-hub |
peer-acme-hub-to-nonprod | vpc-acme-hub | vpc-acme-nonprod |
peer-acme-nonprod-to-hub | vpc-acme-nonprod | vpc-acme-hub |
Only subnet routes are exchanged; custom routes are neither exported nor imported. Because peering is not transitive, a prod address is unreachable from nonprod even though both peer with the hub: the isolation is structural, not a rule that could be edited away. The network firewall policy of each VPC adds an explicit, logged deny for any other private source or destination, so an attempt shows up in the logs (Cloud NGFW firewall policies).
The organization policy compute.restrictVpcPeering allows peering only with networks of acme-core-network, so no stage project can peer its way around the design. Google Cloud runs one peering operation per network at a time, so the unit applies its peerings one after another and the reverse halves wait for the forward ones.
Stages and domains. isolation_domains in network.hcl decides which VPC a stage's subnets live in: prod = ["prod"] and nonprod = ["sandbox", "dev", "staging"]; the name hub is reserved. A stage belongs to exactly one domain. Moving a stage to another domain moves its subnets to another VPC, which rebuilds everything attached to them.
Each domain network reaches Google-managed services through its own Private Service Access connection, a separate peering with Google's producer network.
Terms you will see
| Term | Meaning |
|---|---|
| Peering | A private connection between two VPCs, one half in each. |
| Subnet route | The route to a subnet's range, exchanged across the peering. |
| Non-transitive | Peering reaches only the directly peered network. |
| Isolation domain | prod or nonprod, each its own VPC peered only with the hub. |
Where to read more
- GCP Enterprise Baseline overview and its architecture overview.
- VPC networks for the three networks and their subnets.
- Hub-and-spoke networking for isolation domains.