Skip to main content

Frequently Asked Questions

Why would a VM need Cloud NAT if it already has a private IP?

A GCP VM without an external IP can't reach the internet at all by default — no outbound package installs, no API calls to third parties, nothing. Cloud NAT gives that VM outbound internet access (for OS updates, pulling dependencies, calling external APIs) while keeping it unreachable from the outside. This is the standard pattern for backend VMs, GKE nodes, and Cloud SQL proxies that should never be directly internet-facing but still need to phone out.

What's a common Cloud NAT gotcha in production?

Port exhaustion. Cloud NAT allocates a fixed number of source ports per VM by default, and a VM making many concurrent outbound connections (e.g., high-throughput API calls or a poorly pooled database driver) can exhaust them, causing silent connection failures. The fix is tuning minPortsPerVm upward or switching to dynamic port allocation. Also remember it requires a Cloud Router in the same region and network — forgetting that is the most common setup failure.