Review subnet Private Google Access settings

Check Private Google Access and Google API connectivity for VMs without external IP addresses.

Description

Private Google Access is a subnet setting that lets VMs without external IP addresses reach supported Google APIs and services. API calls can fail when a workload needs this feature but it is disabled and no other access path is available.

It does not grant API IAM permissions or block all external traffic. An omitted task value does not alone establish an existing subnet's effective state; check its applied settings and network configuration.

Potential impact

  • Workloads without external IP addresses can lose access to required Google APIs.
  • Connectivity troubleshooting can lead to unnecessary external IP addresses or broad network paths.

Remediation

  • Set private_ip_google_access: yes when needed. If another approved access method is in use, check that path and its requirements too.
  • Review DNS, routes, firewalls and API permissions, then test from a VM without an external IP. Manage general internet-access restrictions separately.

Examples

These subnet task excerpts require the actual network result object, project and service-account JSON file. DNS, routing and firewall configuration are not included.

Before

yaml
- name: 서브넷 생성
  google.cloud.gcp_compute_subnetwork:
    name: ansiblenet
    region: us-west1
    network: "{{ network }}"
    ip_cidr_range: 172.16.0.0/16
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present

After

yaml
- name: 서브넷 생성
  google.cloud.gcp_compute_subnetwork:
    name: ansiblenet
    region: us-west1
    network: "{{ network }}"
    ip_cidr_range: 172.16.0.0/16
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    private_ip_google_access: yes
    state: present

Explanation:

  • Before: The task does not specify Private Google Access. Check the existing subnet's actual state.
  • After: The feature is explicitly enabled. Network paths and Google API authentication and permissions are still required.

References