Professional Cloud Security EngineerConfiguring network securityMedium
A development team is deploying a new microservice in a Google Kubernetes Engine (GKE) cluster that needs to consume a managed service (e.g., Cloud SQL, Cloud Memorystore) in a different Google Cloud project within the same organization. For security and compliance, all communication between the microservice and the managed service must remain entirely private, without traversing the public internet. Which Google Cloud networking feature should be implemented to achieve this?
- AVPC Network Peering
- BShared VPC
- CPrivate Service Connect
- DPrivate Google Access
Show answer & explanationAnswer & explanation
Correct answer: C. Private Service Connect
Private Service Connect allows consumers to access managed services privately across different VPC networks and projects, without using VPC Network Peering or traversing the internet. This is specifically designed for secure, private consumption of services.
Why the other options are wrong
- A. VPC Network Peering connects entire VPCs, which might not be granular enough for consuming specific managed services privately across projects and could expose more than intended.
- B. Shared VPC allows multiple projects to use a common host VPC network, but it's for shared infrastructure, not private service consumption between independent projects.
- D. Private Google Access allows instances with internal IPs to reach Google APIs and services over Google's internal network, but it's for Google APIs, not managed services deployed in a separate project.
Private Service Connect (PSC)
Private Service Connect (PSC) allows consumers to privately access Google-managed services and services deployed by other VPCs, using internal IP addresses and without traversing the internet.
- Enables private access to services across VPCs/projects.
- Uses internal IP addresses, no public internet.
- Supports both consumer and producer side configurations.
Memory trick: PSC: Private, Secure, Connected; services to services.