Q: How do you design a multi-tier Shared VPC architecture in GCP for an enterprise with 20 product squads? How do you grant squads network access without letting them alter firewall rules or routing tables?
Architectural playbook for deploying a centralized Google Cloud Shared VPC across Host and Service Projects, ensuring security isolation, subnetwork IAM delegation, and centralized egress filtering.
Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Designate Host Project & Subnet IP Carving
Establish a dedicated Network Host Project with non-overlapping RFC 1918 CIDR allocations:
- Host Project: Designated
network-core-prodas the Shared VPC Host Project. - Subnet Segregation: Created private subnets across regions:
subnet-prod-us-central1 (10.100.0.0/20)with secondary alias ranges for GKE Pods and Services. - Cloud Router & NAT: Deployed regional Cloud Routers with Cloud NAT for private internet egress.
Attach Service Projects & Delegate Subnet Permissions
Attach application projects to the host project and grant granular IAM roles:
- Attach Projects: Attached
billing-app-prodandauth-app-prodas Service Projects. - Subnet User Role: Granted
roles/compute.networkUserstrictly at the individual subnetwork level, not project level. - Targeted Access: Service projects can deploy VMs/GKE onto their designated subnet, but cannot view or attach to other squads' subnets.
Grant Permissions for GKE Service Agents
Allow GKE in service projects to manage firewall rules and load balancers:
- GKE Service Agent: Granted
roles/container.hostServiceAgentUserto the Service Project GKE Service Agent on the Host Project. - Google APIs Service Agent: Granted
roles/compute.networkUserto the Google APIs service agent in the host project.
Enforce Hierarchical Firewall Policies & Cloud DNS Peering
Centralize security governance and private service resolution:
- Hierarchical Firewall Policies: Enforced mandatory organization-level rules (e.g. block SSH 0.0.0.0/0, mandate IAP bastion).
- Cloud DNS Private Zones: Hosted all private domains in the Host Project and established DNS Peering with on-premises datacenters.
- Created a centralized Host Project managing shared regional subnets with secondary GKE IP ranges.
- Attached product service projects and granted compute.networkUser strictly at the individual subnetwork level.
- Provisioned GKE hostServiceAgentUser permissions so container clusters could deploy Cloud Load Balancers.
- Enforced organizational hierarchical firewall policies to guarantee zero public ingress without IAP.