Google CloudLive-testedattested

GCP VPC Network Foundation

Production VPC with subnets, secondary ranges, firewall rules, Cloud Router and Cloud NAT - the network base every GCP workload sits on.

terraformGoogle Cloudgcp

Compare Virtual Private Cloud (VPC) across clouds →

Part of: GCP Production Landing Zone, GCP Kubernetes Platform

gcp-vpcvizier v1.2.0

Verification

Live-tested

Really deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-06-30 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o gcp-vpc-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/gcp-vpc/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle gcp-vpc-1.0.0.sigstore.json \
  gcp-vpc-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "15bfa5784d0ed0c3587749edaa4b1cc04bf318773b76f8f8601ce834ff19513f  gcp-vpc-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "vpc" {
  source  = "www.iac-bazaar.com/iac-bazaar/gcp-vpc/gcp"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/gcp-vpc/badge)](https://www.iac-bazaar.com/catalog/gcp-vpc?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Terraform module 1.0.0, live-tested on IaC Bazaar: [GCP VPC Network Foundation](https://www.iac-bazaar.com/catalog/gcp-vpc?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```hcl
module "vpc" {
  source  = "www.iac-bazaar.com/iac-bazaar/gcp-vpc/gcp"
  version = "1.0.0"
}
```

Preview:IaC Bazaar: live-tested

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

gcp-vpc

Production VPC with subnets, secondary ranges, firewall rules, Cloud Router and Cloud NAT — the network base every GCP workload sits on. Works with Terraform and OpenTofu (>= 1.6), Google provider >= 7.0, < 8.0.

Secure defaults:

  • Custom-mode network (no auto subnets), Private Google Access on per subnet
  • VPC flow logs on by default (5-min aggregation, 50% sampling, all metadata)
  • No public SSH: baseline rule allows SSH only from Google's IAP range (35.235.240.0/20); pair with gcloud compute ssh --tunnel-through-iap
  • Allow-internal baseline covers secondary ranges, so GKE pod-to-pod works
  • Cloud NAT (auto-allocated IPs, error logging) per region — private instances get egress without external IPs
  • Firewall rule logging on by default; every rule must be explicitly allow XOR deny

Requirements

  • Terraform or OpenTofu >= 1.6
  • hashicorp/google >= 7.0, < 8.0

Notes for integrators:

  • subnet_secondary_ranges is shaped to feed straight into GKE (cluster_secondary_range_name / services_secondary_range_name).
  • Cloud NAT here uses AUTO_ONLY IP allocation and NATs all subnet ranges in the region; bring static NAT IPs in a wrapper if you need allowlisting.
  • If you set delete_default_routes_on_create = true, nothing in the VPC can reach the internet (even via NAT) until you add a default route back.

License

Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage
  • Inputs
  • Outputs

Related modules

Static validatedLive test pending

gcp-network-connectivity-center

A hub with no spokes connects nothing; a VPC spoke advertises every subnet to every other spoke unless told otherwise, which is how a sandbox learns the production database range; and site-to-site data transfer routes branches through Google at its rates. Spokes come with the hub, each VPC spoke narrows its exports or says why not, and branch transit is off unless accepted.

View module
Static validatedLive test pending

gcp-private-service-connect

ACCEPT_AUTOMATIC admits any project on Google Cloud that knows the attachment URI, which is not a secret and appears in logs. Manual by default with a per-consumer connection limit; an empty accept list is refused too. PROXY protocol is on so backends see the consumer rather than the NAT range, removed consumers are disconnected, and the NAT subnet is created with the attachment.

View module
Live-tested

gcp-cloud-nat

A regional Cloud Router and Cloud NAT gateway giving private, external-IP-less instances outbound internet access, with auto-allocated NAT IPs, all-subnet coverage, and logging on by default.

View module
Live-tested

gcp-ha-vpn

99.99% SLA HA VPN gateway pair with BGP-dynamic routing - GCP-to-on-prem or GCP-to-AWS/Azure.

View module
Static validatedLive test pending

gcp-interconnect

An interconnect is a private path, not a private conversation: traffic crosses the colocation facility and the partner in clear unless the attachment carries HA VPN. One attachment is no SLA, and a partner attachment is created disabled until somebody flips it. A redundant pair across two edge availability domains, IPsec by default with clear text accepted by name, and enabled unless told.

View module
Static validatedLive test pending

gcp-shared-vpc

Attaching a service project is the visible half: its instances land in a shared subnet only when the creating principal holds networkUser on that subnet, and for GKE, Cloud Run or Dataflow that principal is the service agent, not a person. Takes the per-subnet grants with the attachments, refuses a project attached with none, and adds the host-level grant GKE needs.

View module