Connecting resources.
WHAT A VIRTUAL PRIVATE CLOUD IS
An isolated network for your resources, spanning regions.
WHAT SUBNETS ARE
Regional address ranges within it.
WHAT FIREWALL RULES DO
Control traffic to and from instances, by rule.
WHAT TO CONFIGURE
Deny by default, permitting only what is required.
WHAT TO NEVER EXPOSE
Management access to the internet.
WHY
It is scanned continuously.
WHAT TO USE INSTEAD
Identity-aware access, or a bastion arrangement.
WHAT PRIVATE ACCESS PROVIDES
Reaching platform services without traversing the public internet.
WHAT LOAD BALANCING PROVIDES
Distributing traffic, with health checks, at global or regional scope.
WHAT CLOUD ARMOUR PROVIDES
Protection against volumetric attacks and application-layer rules.
WHAT TO PLAN EARLY
Address ranges that do not overlap with your other networks.
WHY
Overlapping ranges prevent connectivity, and renumbering afterwards is painful.
WHAT TO CONSIDER ABOUT REGIONS
Latency to your users, which is the largest factor in perceived speed.
WHAT TO MONITOR
Egress, which is billed and frequently surprises.