An engineer coming from AWS creates a VPC in GCP expecting it to be scoped to a single region, then spends an afternoon confused about why subnets are defined per-region inside what is actually a global resource. This pillar covers the networking primitives that determine whether a Google Cloud environment is secure and performant, or quietly misconfigured - VPC design, firewall rules, and the load balancing and connectivity options that link everything together.
What This Pillar Covers
- Designing custom-mode VPCs and subnets, understanding GCP's global-by-default VPC model
- Configuring firewall rules using network tags and Service Accounts rather than subnet attachment
- Centralizing network management across teams with Shared VPC
- Choosing the right Cloud Load Balancer type for a given traffic pattern
- Choosing between Cloud VPN and VPC Network Peering for connecting networks
- Giving private instances outbound internet access with Cloud NAT
Who This Is For
Cloud administrators, network engineers, and DevOps engineers responsible for designing secure network architectures, routing application traffic correctly, and connecting GCP environments to on-premises infrastructure or other VPCs.
Why This Matters in Production
GCP's VPC being global by default, with firewall rules applied through tags rather than subnet boundaries, is the single most common source of genuine confusion for engineers migrating from another cloud. A firewall rule created without realizing it needs a matching network tag on the VM can silently fail to apply any protection at all, with no error surfaced to flag the mismatch.
Prerequisites
- Completion of GCP Fundamentals and Resource Governance, or equivalent familiarity with Projects and IAM
- Understanding of core networking concepts - IP addressing, CIDR notation, and TCP/IP
- Basic familiarity with firewall concepts is helpful for the firewall rules topic