Google Cloud SWP Enterprise Diagnostic Console

Cloud Run Direct VPC: Purpose 1 (SWP SaaS Egress) & Purpose 2 (Private Google Access VIP)

SWP Logs Explorer
Live GCP Configuration Parameters:
Subnet PGA: swp-tenant-subnet: true
Cloud DNS: googleapis-private-zone
Restricted VIP: Restricted VIP (199.36.153.4/30)
Proxy PSC: 10.10.0.10:8080
Cloud NAT: 104.197.76.172
NO_PROXY: *.googleapis.com, 199.36.153.*
ENTERPRISE ARCHITECTURE FLOW: END-TO-END CONNECTIVITY (GSLB INGRESS ➞ CLOUD SERVICE MESH ➞ SECURE WEB PROXY)
Dashed Horizontal Flow: Active Routing
● 1. Internet Client
User / API Consumer
HTTPS / TLS 1.3
DNS A-Record
● 2. GSLB Anycast VIP
136.81.54.239 (Global)
SSL: Google-Managed
ACTIVE CERT
URL Map Dispatch
● 3. Ingress Gateway
swp-ingress-url-map
Serverless NEGs (us-central1)
PATH ROUTING
NEG Ingress
● 4. Cloud Run Mesh
swp-poc-mesh Fabric
orders • catalog • auth
CSM SIDECARS
Direct VPC
● 5. Tenant VPC Subnet
swp-tenant-subnet (10.10.0.0/24)
Tag: swp-poc-tag
EGRESS FIREWALL
PSC: 10.10.0.10:8080
● 6. Secure Web Proxy
swp-gateway (Central VPC)
Policy: swp-policy (CEL)
ENTERPRISE SWP
Egress NAT
● 7. Cloud NAT Egress
IP: 104.197.76.172
Target: Allowed SaaS / APIs
FIXED PUBLIC IP
Level 1: Ingress — Global Server Load Balancer (GSLB) & Google-Managed SSL
Anycast IP: 136.81.54.239 Google-Managed SSL
Ingress Component Configuration & Routing Target Protocol / Port Status & Verification
DNS A-Record Instruction
Client Ingress FQDN
test.zed.wtf ➞ 136.81.54.239
Point your DNS provider A record to this Anycast IP
DNS / Anycast Ready for Delegation
Google-Managed SSL Certificate
Cloud Load Balancing Managed Cert
swp-ingress-managed-cert
Domain: test.zed.wtf (Google CA, no private certs)
TLS 1.2 / 1.3 ACTIVE
Port 80 Forwarding Rule
Automatic HTTP ➞ HTTPS 301
swp-ingress-http-rule (IP: 136.81.54.239:80)
Enforces MOVED_PERMANENTLY_DEFAULT to https://test.zed.wtf/
HTTP : 80 ACTIVE (301)
Port 443 Forwarding Rule & URL Map
Target HTTPS Proxy + Serverless NEGs
swp-ingress-https-rule ➞ swp-ingress-url-map
Default ➞ swp-probe-service | /mesh/* ➞ microservices
HTTPS : 443 ACTIVE (GSLB)
Level 2: Gateway — Ingress URL Map & API Dispatcher
URL Map: swp-ingress-url-map 4 Path Rules
Request Host & Path Dispatch Target Backend Service Destination Cloud Run Service Protocol / Port & Serverless NEG
/ (Default Path) swp-backend-default swp-probe-service (Web Console) HTTPS / NEG: swp-neg-default
/mesh/orders* swp-backend-orders swp-mesh-orders (Orders API) HTTPS / NEG: swp-neg-orders
/mesh/catalog* swp-backend-catalog swp-mesh-catalog (Catalog API) HTTPS / NEG: swp-neg-catalog
/mesh/auth* swp-backend-auth swp-mesh-auth (Auth API) HTTPS / NEG: swp-neg-auth
Level 3: Service Mesh — Cloud Run Service Mesh (CSM Fabric) & Microservices
Mesh: swp-poc-mesh
Microservice Name Domain Function & Role Mesh Endpoint Mesh Probe Mesh Telemetry & Fabric Status
swp-mesh-orders
Mesh Sidecar Attached
Orders & Checkout Processing
Direct VPC Egress (swp-tenant-network)
/orders
Ready
swp-mesh-catalog
Mesh Sidecar Attached
Product Catalog & Inventory Engine
Direct VPC Egress (swp-tenant-network)
/catalog
Ready
swp-mesh-auth
Mesh Sidecar Attached
Identity, OAuth & Access Tokens
Direct VPC Egress (swp-tenant-network)
/auth
Ready
Egress Path A: Private Connections
Restricted VIP (199.36.153.4/30)
Mode B: Top 10 Web Application Private Google APIs (Direct Internal VIP bypasses SWP via NO_PROXY)
# Cloud Service Architecture Role Action Verification
1
Cloud Storage (GCS)
https://storage.googleapis.com/generate_204
Blob & Media Storage
Uploads, static files, report exports, and media CDN assets
Ready
2
Secret Manager API
https://secretmanager.googleapis.com/
Secrets & Credentials
DB passwords, API keys, OAuth secrets, and TLS certificates
Ready
3
Cloud Firestore / Datastore
https://firestore.googleapis.com/
NoSQL App Database
User profiles, session state, real-time sync, and document storage
Ready
4
Cloud SQL Admin API
https://sqladmin.googleapis.com/
Relational Database
Managed Cloud SQL (Postgres/MySQL) connectivity, instance metadata, and IAM DB auth
Ready
5
Cloud Logging API
https://logging.googleapis.com/
Observability & Logs
Structured application logs, HTTP access logs, and audit trails
Ready
6
Cloud Monitoring API (APM)
https://monitoring.googleapis.com/
Telemetry & APM
Performance metrics, uptime checks, health alerts, and latency graphs
Ready
7
Cloud Pub/Sub API
https://pubsub.googleapis.com/
Async Messaging Broker
Decoupled event streaming, webhook ingestion, and worker queues
Ready
8
Cloud Tasks API
https://cloudtasks.googleapis.com/
Background Worker Jobs
Asynchronous task queues, rate-limited execution, and delayed jobs
Ready
9
Cloud KMS (Key Management)
https://cloudkms.googleapis.com/
Data Encryption
Cryptographic envelope encryption for sensitive PII and keys
Ready
10
Cloud Run Admin API
https://run.googleapis.com/
Container Orchestration
Serverless revision lifecycles, traffic-splitting, and autoscaling
Ready
Egress Path B: Secure Web Proxy (SWP)
Cloud NAT: 104.197.76.172
Purpose 1: Secure Web Proxy (SWP) Egress Verification via PSC (10.10.0.10:8080)
Target Destination Policy Rule Test Actions Execution Status
ALLOW https://ibm.com/
SWP Match → 200 OK
Ready
ALLOW https://google.com/
SWP Match → 200 OK
Ready
DENY https://yahoo.com/
SWP Policy → 403 Denied
Ready
DENY https://hp.com/
SWP Policy → 403 Denied
Ready
NAT IP https://checkip.amazonaws.com/
Egress NAT (104.197.76.172)
Ready
Technical Architecture & Policy Comparison Matrix & Egress Traffic Path Architecture (Click to expand)
Egress Mode Architecture: SWP vs. Private Google Access (PGA) DUAL-PIPELINE EGRESS
Purpose 1: External SaaS Egress (SWP) via Cloud NAT 104.197.76.172
Cloud Run ➞ Direct VPC ➞ PSC (10.10.0.10:8080) ➞ Central SWP ➞ Cloud NAT ➞ Public Target
HTTP_PROXY tunnel enforced by allow-swp-proxy firewall (Pri 1000). Gateway evaluates CEL host allowlist & SA identity. Direct internet egress blocked by deny-all-egress.
Purpose 2: Internal Google Cloud APIs (PGA) 100% Internal SDN Transit
Cloud Run ➞ Cloud DNS (*.googleapis.com) ➞ Restricted VIP (199.36.153.4/30) ➞ Internal Google Backbone
Bypasses SWP via NO_PROXY. Allowed by firewall allow-private-google-apis (Pri 1100). Packets stay within Google's private network; zero public endpoint or NAT traversal.
Dimension Purpose 1: Secure Web Proxy (SWP) Purpose 2: Private Google Access (PGA VIP)
Destination Scope External SaaS, public partner APIs, internet destinations Google Cloud APIs (Cloud Storage, Secret Manager, Firestore, etc.)
DNS Resolution Standard public DNS or resolved dynamically via SWP proxy Cloud DNS Private Zone (*.googleapis.com ➞ restricted.googleapis.com)
Destination IP External public internet IP (source NATed by Cloud NAT) Restricted VIP pool: 199.36.153.4/30 (199.36.153.4 - 199.36.153.7)
Application Client Handling Explicit HTTP CONNECT tunnel via HTTP_PROXY / HTTPS_PROXY Direct socket connection via NO_PROXY bypass list
VPC Firewall Permission allow-swp-proxy (Priority 1000, TCP:8080 to 10.10.0.10) allow-private-google-apis (Priority 1100, TCP:443 to 199.36.153.4/30)
Direct Internet Bypass Blocked by Tenant VPC rule deny-all-egress-ipv4 (Pri 2000) Blocked by Tenant VPC rule deny-all-egress-ipv4 (Pri 2000)
Data Path Transit Direct VPC ➞ PSC Endpoint ➞ Central SWP ➞ Cloud NAT ➞ Internet Direct VPC ➞ Subnet PGA ➞ VPC Route ➞ Google SDN Backbone Core
AUDIT LOG & DIAGNOSTIC STREAM
[READY] Console initialized. Ready to test Purpose 1 (SWP), Purpose 2 (Private Google Access), GSLB Ingress, or Mesh Microservices.