VPC networks
A VPC (Virtual Private Cloud) network is a private network for Google Cloud resources. The GCP Enterprise Baseline builds three of them in acme-core-network, a hub and one per isolation domain, and gives every stage the same set of subnets from one address plan.
What it does
A VPC network is global: one network spans every region. Its subnets are regional, each with a primary range and optional secondary ranges, which GKE uses for pod and service addresses. A subnet can have a purpose: a proxy-only subnet (REGIONAL_MANAGED_PROXY) holds the proxies of regional Envoy-based load balancers, a Private Service Connect subnet holds published service endpoints. Private Google Access lets resources without an external IP call Google APIs, and VPC flow logs sample the network flows of a subnet into Cloud Logging. With global routing a Cloud Router learns and advertises routes for every region of the network.
How BuiltForProd uses it
Three VPCs. The network stack (environments/core/network/us-west1) instantiates one unit definition, vpc-domain, three times: vpc-acme-hub, vpc-acme-prod and vpc-acme-nonprod, all in acme-core-network, the Shared VPC host. Each network has global routing, no auto-created subnets, and evaluates its VPC firewall rules before its network firewall policy. A stage belongs to exactly one domain (isolation_domains in network.hcl): prod holds prod, nonprod holds sandbox, dev and staging, and hub is reserved.
One address plan. network_map.yaml is the only place a CIDR is written. Inside 10.0.0.0/8 each region has a /12, the stage projects a /13, the core projects a /14, and each stage a /16:
"region 0":
gcp_region: us-west1
region_slug: usw1
cidr: 10.0.0.0/12
plat:
cidr: 10.0.0.0/13
prod:
domain: prod
primary_cidr: 10.0.0.0/16
subnets:
nodes: { cidr: 10.0.0.0/20, secondary_ranges: { pods: 10.0.128.0/17, services: 10.0.16.0/20 } }
data: { cidr: 10.0.32.0/22 }
proxy: { cidr: 10.0.36.0/23, purpose: REGIONAL_MANAGED_PROXY }
psc: { cidr: 10.0.38.0/24, purpose: PRIVATE_SERVICE_CONNECT }
psa_range: 10.0.40.0/22
gke_master_range: 172.20.0.0/28
| Subnet key | Purpose | In prod |
|---|---|---|
nodes | GKE nodes, with pods and services secondary ranges | sn-acme-usw1-prd-nodes, /20 (/17 pods, /20 services) |
data | Data services and endpoints, such as Private Service Connect addresses | sn-acme-usw1-prd-data, /22 |
proxy | Proxy-only subnet for internal Application Load Balancers, one per VPC and region | sn-acme-usw1-prd-proxy, /23 |
psc | Private Service Connect | sn-acme-usw1-prd-psc, /24 |
Each stage also reserves a /22 for Private Service Access and a /28 for its GKE control plane, outside the organization range. Google Cloud allows one active proxy-only subnet per VPC and region, so each domain lists it on one stage and every stage of the domain uses it: prod on prod, nonprod on staging (sn-acme-usw1-stg-proxy), while dev and sandbox keep their /23 free. The hub has a shared subnet (bastions and shared services) and its own proxy subnet, and the auto-runner block gives the optional self-hosted runners their own subnet with pod and service ranges. A second region, us-east1, is reserved in the map: nothing is created there until its region folders exist.
The ipam unit reads the map, checks it against the region folders and network.hcl, and republishes it as typed outputs for the VPC, firewall, DNS and stage units; the guard scripts check-network-maps.py and check-no-hardcoded-cidrs.py keep CIDRs out of every other file.
Subnet settings. Every workload subnet has Private Google Access and flow logs at a one-minute interval with all metadata; flow_logs_sampling = 1.0 in network.hcl logs every flow (0.5 halves the Logging cost). Proxy-only and Private Service Connect subnets carry no VMs and no flow logs. Egress to the internet goes through each network's own Cloud NAT.
Terms you will see
| Term | Meaning |
|---|---|
| Isolation domain | A VPC and the stages in it: prod, nonprod; the hub is reserved. |
network_map.yaml | The address plan, the only file with CIDRs. |
| Secondary range | An extra range on a subnet, here pods and services for GKE. |
| Proxy-only subnet | The one proxy subnet per VPC and region that regional managed load balancers draw addresses from. |
| Flow logs | Sampled records of every connection on a subnet. |
Where to read more
- GCP Enterprise Baseline overview and its architecture overview.
- VPC Network Peering for how the hub connects the domains.
- Hub-and-spoke networking for the topology.