Skip to main content

Frequently Asked Questions

How do GCP Network Tags actually get used to target firewall rules?

A firewall rule can specify target tags instead of (or alongside) a target service account or 'all instances in the network' — only VMs carrying a matching tag string have that rule applied to them. Because tags are just freeform text set at VM creation (or added later), a firewall rule referencing `tag:web-server` applies automatically to any VM tagged that way, without needing to reference specific instance names or IP ranges.

Why do many GCP teams move away from Network Tags for security-critical firewall rules?

Tags are just strings anyone with VM-edit permission can add, remove, or typo — there's no IAM control over who can attach a given tag to a VM, so a mistyped or missing tag can silently expose or block a workload. Service Account-based firewall targeting is generally preferred at scale because assigning a service account to a VM is a more controlled, auditable action, tied to IAM rather than a freeform label anyone can edit.