graph-studio
Networking Prerequisites
We need to create two subnetworks in the existing VPC network, one for the control plane/master nodes and the other for data plane or worker nodes.
Subnet Creation
Create the subnetwork by running the following command:
gcloud compute networks subnets create SUBNET_NAME \ --network=VPC_NETWORK_NAME \ --region=REGION \ --range=IP_CIDR_RANGE \ --description="Optional description for the subnetwork" \ --enable-private-ip-google-access # Optional: Enables Private Google Access for VMs in this subnet
where:
| Parameter | Description |
|---|---|
SUBNET_NAME |
The name you want to give to your new subnetwork (e.g., my-app-subnet, web-tier-subnet) |
VPC_NETWORK_NAME |
The name of the existing VPC network where you want to create this subnetwork (e.g., my-vpc-network, production-vpc). |
REGION |
The Google Cloud region where this subnetwork will be located (e.g., us-central1, europe-west1). Subnets are regional resources. |
IP_CIDR_RANGE |
The primary IP address range for the subnetwork in CIDR notation (e.g., 10.0.1.0/24, 192.168.10.0/20). This range must be unique within the VPC network. |
--description |
(Optional) A human-readable description for your subnetwork. |
--enable-private-ip-google-access |
(Optional) If specified, instances in this subnetwork can reach Google APIs and services using their internal IP addresses, without needing external IP addresses. This is highly recommended for security and cost efficiency. |
Cloud NAT
If any outbound internet access is needed, you must install Cloud NAT and add the subnets to it.
- Create a Cloud Router (if you don't have one in the region).
A Cloud NAT gateway needs a Cloud Router in the same region and VPC network. If you already have one, you can skip this step.
gcloud compute routers create ROUTER_NAME \ --project=PROJECT_ID \ --network=NETWORK \ --asn=ASN_NUMBER \ --region=REGION
where:
| Parameter | Description |
|---|---|
ROUTER_NAME |
The name of the Cloud Router. |
PROJECT_ID |
The project ID for the project that contains the Cloud Router. |
NETWORK |
The VPC network that contains the instances that you want to reach. |
ASN_NUMBER |
|
| Any private ASN (64512-65534, 4200000000-4294967294) that you are not already using in the on-premises network; Cloud Router requires you to use a private ASN, but your on-premises ASN can be public or private. |
Note: If you are using Cloud Router with Partner Interconnect, you must specify ASN 16550.
|
| REGION | The region where you want to locate the Cloud Router; the Cloud Router advertises all subnets in the region where it's located. |
For further customizations, please refer to the Create Cloud Router section in Create a Cloud Router to Connect a VPC Network to a Peer Network.
- Create the Cloud NAT Gateway and Associate Subnets.
This command creates the Cloud NAT gateway and specifies which subnets will use it for outbound connections.
gcloud compute routers nats create NAT_GATEWAY_NAME \ --router=ROUTER_NAME \ --region=REGION \ --nat-all-subnet-ip-ranges \ --auto-allocate-nat-external-ips \ --project=YOUR_GCP_PROJECT_ID
where:
| Parameter | Description |
|---|---|
NAT_GATEWAY_NAME |
A name for your Cloud NAT gateway (e.g., my-nat-gateway, prod-nat-us-central1). |
ROUTER_NAME |
The name of the Cloud Router you created in Step 1 (or an existing one). |
REGION |
The same region as your Cloud Router and subnets. |
--nat-all-subnet-ip-ranges |
This is the simplest way to tell Cloud NAT to provide NAT for all primary and secondary IP ranges of all subnets in the specified VPC network and region. This is generally recommended unless you have specific subnets you want to exclude. |
--auto-allocate-nat-external-ips |
|
| This tells Cloud NAT to automatically allocate and manage external IP addresses for NAT. This is the easiest and most common configuration. |
Alternatively, you can specify static external IP addresses you've reserved: --nat-external-ip-pool=IP_ADDRESS_NAME1,IP_ADDRESS_NAME2,...
|
| YOUR_GCP_PROJECT_ID | Your Google Cloud Project ID |
Creating BaseDomain
Please refer to the section Create Private Zone in Create, Modify, and Delete Zones.
Reference Google Cloud commands to create the zone and add a network to it are as follows.
To create a private DNS zone in Google Cloud, you use the GCloud DNS managed-zones create command with the --visibility=private flag and specify the VPC networks that can query it.
gcloud dns managed-zones create ZONE_NAME \ --dns-name=DNS_SUFFIX \ --description="Optional description for your private DNS zone" \ --visibility=private \ --networks=VPC_NETWORK_LIST \ --project=YOUR_GCP_PROJECT_ID
where:
| Parameter | Description |
|---|---|
ZONE_NAME |
A unique name for your private DNS zone (e.g., my-internal-zone, dev-app-dns). This is an internal name within Cloud DNS, not the domain name itself. |
DNS_SUFFIX |
The DNS name suffix for your private zone (e.g., internal.example.com). All records in this zone will share this suffix. Crucially, it must end with a period (.). |
--description |
(Optional) A brief, human-readable description for your zone. |
--visibility=private |
This is the key flag that designates the zone as a private DNS zone. |
--networks=VPC_NETWORK_LIST |
A comma-separated list of the VPC network names (or full resource URLs) to which this private zone must be visible. Only the specified networks can query records in this zone. |
- Example for a single network:
--networks=my-vpc-network - Example for multiple networks:
--networks=my-vpc-network,another-vpc-network - To get a network's full URL:
gcloud compute networks describe VPC_NETWORK_NAME --format="get(selfLink)"
|
| --project=YOUR_GCP_PROJECT_ID | Your Google Cloud Project ID. |
Source: https://docs.sw.siemens.com/documentation/external/PL20260212925461721/en-US/graph_studio/openshift-network-prereq.htm · retrieved 2026-08-23