HA VPN (Site-to-Site)
99.99% SLA HA VPN gateway pair with BGP-dynamic routing - GCP-to-on-prem or GCP-to-AWS/Azure.
Verification
Live-testedReally deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-08-03 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o gcp-ha-vpn-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/gcp-ha-vpn/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle gcp-ha-vpn-1.0.0.sigstore.json \
gcp-ha-vpn-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "089bf88b49c3bec4143d0ce1657cdcbac2e56622e32503c531e868715ba2408f gcp-ha-vpn-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "ha_vpn" {
source = "www.iac-bazaar.com/iac-bazaar/gcp-ha-vpn/gcp"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/gcp-ha-vpn?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Terraform module 1.0.0, live-tested on IaC Bazaar: [HA VPN (Site-to-Site)](https://www.iac-bazaar.com/catalog/gcp-ha-vpn?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```hcl
module "ha_vpn" {
source = "www.iac-bazaar.com/iac-bazaar/gcp-ha-vpn/gcp"
version = "1.0.0"
}
```Preview:
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
gcp-ha-vpn
A 99.99%-SLA HA VPN gateway pair with BGP-dynamic routing — connect a
GCP VPC to on-prem, AWS or Azure (peer_type = "external"), or to a
second GCP VPC (peer_type = "gcp"). One module call builds the HA VPN gateway
(two interfaces, two Google-assigned external IPs), a Cloud Router for BGP, the
peer gateway, the redundant tunnels, the Cloud Router interfaces and the BGP
sessions — with the BGP wiring (the buyer's main pain point) made explicit and
validated. Works with Terraform and OpenTofu (>= 1.6), Google provider
>= 7.0, < 8.0.
Design & secure defaults
- HA topology by construction. The HA VPN gateway always exposes two
interfaces; the
tunnelsmap is intended to carry two tunnels (one per interface) so a single tunnel or interface failure does not drop the connection — the requirement for the 99.99% SLA. - BGP-dynamic routing. A Cloud Router runs BGP on the Google side. The
local ASN is validated to be a private RFC6996 ASN. Per-session
advertised_route_priority(MED) lets you make one tunnel active and one standby. - No BFD, by API design — GCP rejects BFD on VPN tunnel interfaces
(
BFD cannot be enabled on VPN Tunnel interfaces), so this module exposes no BFD knob; failover relies on BGP keepalives across the HA gateway pair. - IKEv2 only by default (
ike_version = 2). - Secrets stay out of the topology. Pre-shared keys live in a separate
tunnel_shared_secretsmap markedsensitive; the non-sensitivetunnelsmap drivesfor_each, and secrets are looked up by key (Terraform cannot iterate a sensitive collection). Nothing is hardcoded. - Cross-field invariants enforced with
precondition: an external peer requires apeer_external_gateway_interfaceon every tunnel; a GCP peer requirespeer_gcp_gateway.
This module describes the Google side plus the peer-gateway object. On the remote side (on-prem / AWS / Azure, or the second GCP module) you configure the mirror-image tunnels, ASNs and link-local /30s.
Requirements
| Requirement | Version |
|---|---|
| Terraform / OpenTofu | >= 1.6 |
hashicorp/google | >= 7.0, < 8.0 |
License
Commercial — LicenseRef-IaCBazaar-Commercial. See the IaC Bazaar terms.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
- Inputs
- Outputs
Related modules
gcp-network-connectivity-center
A hub with no spokes connects nothing; a VPC spoke advertises every subnet to every other spoke unless told otherwise, which is how a sandbox learns the production database range; and site-to-site data transfer routes branches through Google at its rates. Spokes come with the hub, each VPC spoke narrows its exports or says why not, and branch transit is off unless accepted.
gcp-private-service-connect
ACCEPT_AUTOMATIC admits any project on Google Cloud that knows the attachment URI, which is not a secret and appears in logs. Manual by default with a per-consumer connection limit; an empty accept list is refused too. PROXY protocol is on so backends see the consumer rather than the NAT range, removed consumers are disconnected, and the NAT subnet is created with the attachment.
gcp-cloud-nat
A regional Cloud Router and Cloud NAT gateway giving private, external-IP-less instances outbound internet access, with auto-allocated NAT IPs, all-subnet coverage, and logging on by default.
gcp-vpc
Production VPC with subnets, secondary ranges, firewall rules, Cloud Router and Cloud NAT - the network base every GCP workload sits on.
gcp-interconnect
An interconnect is a private path, not a private conversation: traffic crosses the colocation facility and the partner in clear unless the attachment carries HA VPN. One attachment is no SLA, and a partner attachment is created disabled until somebody flips it. A redundant pair across two edge availability domains, IPsec by default with clear text accepted by name, and enabled unless told.
gcp-shared-vpc
Attaching a service project is the visible half: its instances land in a shared subnet only when the creating principal holds networkUser on that subnet, and for GKE, Cloud Run or Dataflow that principal is the service agent, not a person. Takes the per-subnet grants with the attachments, refuses a project attached with none, and adds the host-level grant GKE needs.