Skip to main content

VPC networks

A VPC (Virtual Private Cloud) network is a private network for Google Cloud resources. The GCP Enterprise Baseline builds three of them in acme-core-network, a hub and one per isolation domain, and gives every stage the same set of subnets from one address plan.

What it does​

A VPC network is global: one network spans every region. Its subnets are regional, each with a primary range and optional secondary ranges, which GKE uses for pod and service addresses. A subnet can have a purpose: a proxy-only subnet (REGIONAL_MANAGED_PROXY) holds the proxies of regional Envoy-based load balancers, a Private Service Connect subnet holds published service endpoints. Private Google Access lets resources without an external IP call Google APIs, and VPC flow logs sample the network flows of a subnet into Cloud Logging. With global routing a Cloud Router learns and advertises routes for every region of the network.

How BuiltForProd uses it​

Three VPCs. The network stack (environments/core/network/us-west1) instantiates one unit definition, vpc-domain, three times: vpc-acme-hub, vpc-acme-prod and vpc-acme-nonprod, all in acme-core-network, the Shared VPC host. Each network has global routing, no auto-created subnets, and evaluates its VPC firewall rules before its network firewall policy. A stage belongs to exactly one domain (isolation_domains in network.hcl): prod holds prod, nonprod holds sandbox, dev and staging, and hub is reserved.

One address plan. network_map.yaml is the only place a CIDR is written. Inside 10.0.0.0/8 each region has a /12, the stage projects a /13, the core projects a /14, and each stage a /16:

GCP/acme-gcp-platform-baseline/network_map.yaml (lines 26-41)
"region 0":
gcp_region: us-west1
region_slug: usw1
cidr: 10.0.0.0/12
plat:
cidr: 10.0.0.0/13
prod:
domain: prod
primary_cidr: 10.0.0.0/16
subnets:
nodes: { cidr: 10.0.0.0/20, secondary_ranges: { pods: 10.0.128.0/17, services: 10.0.16.0/20 } }
data: { cidr: 10.0.32.0/22 }
proxy: { cidr: 10.0.36.0/23, purpose: REGIONAL_MANAGED_PROXY }
psc: { cidr: 10.0.38.0/24, purpose: PRIVATE_SERVICE_CONNECT }
psa_range: 10.0.40.0/22
gke_master_range: 172.20.0.0/28
Subnet keyPurposeIn prod
nodesGKE nodes, with pods and services secondary rangessn-acme-usw1-prd-nodes, /20 (/17 pods, /20 services)
dataData services and endpoints, such as Private Service Connect addressessn-acme-usw1-prd-data, /22
proxyProxy-only subnet for internal Application Load Balancers, one per VPC and regionsn-acme-usw1-prd-proxy, /23
pscPrivate Service Connectsn-acme-usw1-prd-psc, /24

Each stage also reserves a /22 for Private Service Access and a /28 for its GKE control plane, outside the organization range. Google Cloud allows one active proxy-only subnet per VPC and region, so each domain lists it on one stage and every stage of the domain uses it: prod on prod, nonprod on staging (sn-acme-usw1-stg-proxy), while dev and sandbox keep their /23 free. The hub has a shared subnet (bastions and shared services) and its own proxy subnet, and the auto-runner block gives the optional self-hosted runners their own subnet with pod and service ranges. A second region, us-east1, is reserved in the map: nothing is created there until its region folders exist.

The ipam unit reads the map, checks it against the region folders and network.hcl, and republishes it as typed outputs for the VPC, firewall, DNS and stage units; the guard scripts check-network-maps.py and check-no-hardcoded-cidrs.py keep CIDRs out of every other file.

Subnet settings. Every workload subnet has Private Google Access and flow logs at a one-minute interval with all metadata; flow_logs_sampling = 1.0 in network.hcl logs every flow (0.5 halves the Logging cost). Proxy-only and Private Service Connect subnets carry no VMs and no flow logs. Egress to the internet goes through each network's own Cloud NAT.

Terms you will see​

TermMeaning
Isolation domainA VPC and the stages in it: prod, nonprod; the hub is reserved.
network_map.yamlThe address plan, the only file with CIDRs.
Secondary rangeAn extra range on a subnet, here pods and services for GKE.
Proxy-only subnetThe one proxy subnet per VPC and region that regional managed load balancers draw addresses from.
Flow logsSampled records of every connection on a subnet.

Where to read more​