Q: Your production GKE clusters and Cloud SQL databases have public endpoints completely disabled for security compliance. Standard Cloud Build cannot reach internal RFC 1918 IP addresses to deploy applications or run schema migrations. How do you design and deploy Cloud Build Private Pools inside your VPC?
Runbook for replacing default public Cloud Build workers with Private Worker Pools peering into private VPC networks, enabling secure access to private GKE clusters, Cloud SQL, and internal artifact registries.
Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Establish Service Networking Private Connection for Cloud Build
Allocate a dedicated CIDR block in your VPC for private Google service producer peering:
- IP Range Reservation: Allocated private range:
gcloud compute addresses create cloud-build-pool-range --global --purpose=VPC_PEERING --prefix-length=24 --network=prod-vpc. - Peering Connection: Created peering with Google Services:
gcloud services vpc-peerings connect --service=servicenetworking.googleapis.com --ranges=cloud-build-pool-range --network=prod-vpc.
Provision Cloud Build Private Worker Pool
Deploy dedicated, single-tenant build workers with customizable machine specifications:
- Create Worker Pool: Executed
gcloud builds worker-pools create private-pool-us --region=us-central1 --peered-network=projects/PROJ_ID/global/networks/prod-vpc --worker-machine-type=e2-standard-4 --worker-disk-size=100GB --no-public-egress. - No Public Egress: Set
--no-public-egressto prevent build jobs from accessing the public internet directly, routing outbound traffic strictly through corporate Cloud NAT and firewalls.
Configure Internal VPC Firewall Rules & Private GKE Master Access
Grant private worker CIDR blocks access to internal cluster control planes and internal databases:
- GKE Authorized Networks: Added Cloud Build CIDR (e.g.,
10.250.0.0/24) to GKE private cluster master authorized networks. - VPC Firewall Rule: Created ingress firewall rule on target GKE and Cloud SQL instances permitting TCP ports 443, 5432 from the Cloud Build private subnet.
Execute Cloud Build Workflows on Private Worker Pool
Update cloudbuild.yaml definitions to run steps inside the private worker pool:
- YAML Pool Specification: Added
options: { pool: { name: 'projects/PROJ_ID/locations/us-central1/workerPools/private-pool-us' } }. - Validation Build: Executed build verifying seamless execution of
kubectl applyagainst private GKE control plane andflyway migrateagainst private Cloud SQL.
- Allocate a dedicated RFC 1918 CIDR block and configure VPC Service Networking peering.
- Create a Cloud Build Private Worker Pool with --no-public-egress for strict data loss prevention.
- Authorize the private worker pool CIDR in GKE master authorized networks and firewall rules.
- Specify the pool resource path in cloudbuild.yaml to execute fully isolated enterprise builds.