Network Tag (GCP)
A freeform string label attached to a Compute Engine VM at creation time, used to target firewall rules to specific VMs. Network tags are simple but can be forgotten or misspelled at scale, which is why Service Account-based targeting is often preferred for anything security-critical in a growing fleet.
Frequently Asked Questions
How do GCP Network Tags actually get used to target firewall rules?
A firewall rule can specify target tags instead of (or alongside) a target service account or 'all instances in the network' — only VMs carrying a matching tag string have that rule applied to them. Because tags are just freeform text set at VM creation (or added later), a firewall rule referencing `tag:web-server` applies automatically to any VM tagged that way, without needing to reference specific instance names or IP ranges.
Why do many GCP teams move away from Network Tags for security-critical firewall rules?
Tags are just strings anyone with VM-edit permission can add, remove, or typo — there's no IAM control over who can attach a given tag to a VM, so a mistyped or missing tag can silently expose or block a workload. Service Account-based firewall targeting is generally preferred at scale because assigning a service account to a VM is a more controlled, auditable action, tied to IAM rather than a freeform label anyone can edit.