Live GCP Configuration Parameters:
Subnet PGA: swp-tenant-subnet: true
Cloud DNS: googleapis-private-zone
Restricted VIP: Restricted VIP (199.36.153.4/30)
Proxy PSC: 10.10.0.10:8080
Cloud NAT: 104.197.76.172
NO_PROXY: *.googleapis.com, 199.36.153.*
ENTERPRISE ARCHITECTURE FLOW: END-TO-END CONNECTIVITY (GSLB INGRESS ➞ CLOUD SERVICE MESH ➞ SECURE WEB PROXY)
Dashed Horizontal Flow: Active Routing
● 1. Internet Client
User / API Consumer
HTTPS / TLS 1.3
DNS A-Record
● 2. GSLB Anycast VIP
136.81.54.239 (Global)
SSL: Google-Managed
ACTIVE CERT
URL Map Dispatch
● 3. Ingress Gateway
swp-ingress-url-map
Serverless NEGs (us-central1)
PATH ROUTING
NEG Ingress
● 4. Cloud Run Mesh
swp-poc-mesh Fabric
orders • catalog • auth
CSM SIDECARS
Direct VPC
● 5. Tenant VPC Subnet
swp-tenant-subnet (10.10.0.0/24)
Tag: swp-poc-tag
EGRESS FIREWALL
PSC: 10.10.0.10:8080
● 6. Secure Web Proxy
swp-gateway (Central VPC)
Policy: swp-policy (CEL)
ENTERPRISE SWP
Egress NAT
● 7. Cloud NAT Egress
IP: 104.197.76.172
Target: Allowed SaaS / APIs
FIXED PUBLIC IP
Level 1: Ingress — Global Server Load Balancer (GSLB) & Google-Managed SSL
Anycast IP: 136.81.54.239
Google-Managed SSL
| Ingress Component | Configuration & Routing Target | Protocol / Port | Status & Verification |
|---|---|---|---|
|
DNS A-Record Instruction Client Ingress FQDN |
test.zed.wtf ➞ 136.81.54.239Point your DNS provider A record to this Anycast IP |
DNS / Anycast | Ready for Delegation |
|
Google-Managed SSL Certificate Cloud Load Balancing Managed Cert |
swp-ingress-managed-certDomain: test.zed.wtf (Google CA, no private certs)
|
TLS 1.2 / 1.3 | ACTIVE |
|
Port 80 Forwarding Rule Automatic HTTP ➞ HTTPS 301 |
swp-ingress-http-rule (IP: 136.81.54.239:80)Enforces MOVED_PERMANENTLY_DEFAULT to https://test.zed.wtf/ |
HTTP : 80 | ACTIVE (301) |
|
Port 443 Forwarding Rule & URL Map Target HTTPS Proxy + Serverless NEGs |
swp-ingress-https-rule ➞ swp-ingress-url-mapDefault ➞ swp-probe-service | /mesh/* ➞ microservices |
HTTPS : 443 | ACTIVE (GSLB) |
GSLB Ingress Probe Telemetry:
PASS
Diagnostics JSON
Level 2: Gateway — Ingress URL Map & API Dispatcher
URL Map: swp-ingress-url-map
4 Path Rules
| Request Host & Path | Dispatch Target Backend Service | Destination Cloud Run Service | Protocol / Port & Serverless NEG |
|---|---|---|---|
/ (Default Path) |
swp-backend-default |
swp-probe-service (Web Console) | HTTPS / NEG: swp-neg-default |
/mesh/orders* |
swp-backend-orders |
swp-mesh-orders (Orders API) | HTTPS / NEG: swp-neg-orders |
/mesh/catalog* |
swp-backend-catalog |
swp-mesh-catalog (Catalog API) | HTTPS / NEG: swp-neg-catalog |
/mesh/auth* |
swp-backend-auth |
swp-mesh-auth (Auth API) | HTTPS / NEG: swp-neg-auth |
Level 3: Service Mesh — Cloud Run Service Mesh (CSM Fabric) & Microservices
Mesh: swp-poc-mesh
| Microservice Name | Domain Function & Role | Mesh Endpoint | Mesh Probe | Mesh Telemetry & Fabric Status |
|---|---|---|---|---|
|
swp-mesh-orders Mesh Sidecar Attached |
Orders & Checkout Processing Direct VPC Egress (swp-tenant-network) |
/orders |
Ready
|
|
|
swp-mesh-catalog Mesh Sidecar Attached |
Product Catalog & Inventory Engine Direct VPC Egress (swp-tenant-network) |
/catalog |
Ready
|
|
|
swp-mesh-auth Mesh Sidecar Attached |
Identity, OAuth & Access Tokens Direct VPC Egress (swp-tenant-network) |
/auth |
Ready
|
Active Mesh Response Payload:
PASS
Microservice Response JSON
Egress Path A: Private Connections
Restricted VIP (199.36.153.4/30)
Mode B: Top 10 Web Application Private Google APIs (Direct Internal VIP bypasses SWP via
NO_PROXY)
| # | Cloud Service | Architecture Role | Action | Verification |
|---|---|---|---|---|
| 1 |
Cloud Storage (GCS)
https://storage.googleapis.com/generate_204
|
Blob & Media Storage
Uploads, static files, report exports, and media CDN assets
|
Ready
|
|
| 2 |
Secret Manager API
https://secretmanager.googleapis.com/
|
Secrets & Credentials
DB passwords, API keys, OAuth secrets, and TLS certificates
|
Ready
|
|
| 3 |
Cloud Firestore / Datastore
https://firestore.googleapis.com/
|
NoSQL App Database
User profiles, session state, real-time sync, and document storage
|
Ready
|
|
| 4 |
Cloud SQL Admin API
https://sqladmin.googleapis.com/
|
Relational Database
Managed Cloud SQL (Postgres/MySQL) connectivity, instance metadata, and IAM DB auth
|
Ready
|
|
| 5 |
Cloud Logging API
https://logging.googleapis.com/
|
Observability & Logs
Structured application logs, HTTP access logs, and audit trails
|
Ready
|
|
| 6 |
Cloud Monitoring API (APM)
https://monitoring.googleapis.com/
|
Telemetry & APM
Performance metrics, uptime checks, health alerts, and latency graphs
|
Ready
|
|
| 7 |
Cloud Pub/Sub API
https://pubsub.googleapis.com/
|
Async Messaging Broker
Decoupled event streaming, webhook ingestion, and worker queues
|
Ready
|
|
| 8 |
Cloud Tasks API
https://cloudtasks.googleapis.com/
|
Background Worker Jobs
Asynchronous task queues, rate-limited execution, and delayed jobs
|
Ready
|
|
| 9 |
Cloud KMS (Key Management)
https://cloudkms.googleapis.com/
|
Data Encryption
Cryptographic envelope encryption for sensitive PII and keys
|
Ready
|
|
| 10 |
Cloud Run Admin API
https://run.googleapis.com/
|
Container Orchestration
Serverless revision lifecycles, traffic-splitting, and autoscaling
|
Ready
|
Egress Path B: Secure Web Proxy (SWP)
Cloud NAT: 104.197.76.172
Purpose 1: Secure Web Proxy (SWP) Egress Verification via PSC (10.10.0.10:8080)
| Target Destination | Policy Rule | Test Actions | Execution Status |
|---|---|---|---|
|
ALLOW
https://ibm.com/
|
SWP Match → 200 OK |
|
Ready
|
|
ALLOW
https://google.com/
|
SWP Match → 200 OK |
|
Ready
|
|
DENY
https://yahoo.com/
|
SWP Policy → 403 Denied |
|
Ready
|
|
DENY
https://hp.com/
|
SWP Policy → 403 Denied |
|
Ready
|
|
NAT IP
https://checkip.amazonaws.com/
|
Egress NAT (104.197.76.172) |
|
Ready
|
Technical Architecture & Policy Comparison Matrix & Egress Traffic Path Architecture (Click to expand)
Egress Mode Architecture: SWP vs. Private Google Access (PGA)
DUAL-PIPELINE EGRESS
Purpose 1: External SaaS Egress (SWP)
via Cloud NAT 104.197.76.172
Cloud Run ➞ Direct VPC ➞ PSC (10.10.0.10:8080) ➞ Central SWP ➞ Cloud NAT ➞ Public Target
HTTP_PROXY tunnel enforced by
allow-swp-proxy firewall (Pri 1000). Gateway evaluates CEL host allowlist & SA identity. Direct internet egress blocked by deny-all-egress.
Purpose 2: Internal Google Cloud APIs (PGA)
100% Internal SDN Transit
Cloud Run ➞ Cloud DNS (*.googleapis.com) ➞ Restricted VIP (199.36.153.4/30) ➞ Internal Google Backbone
Bypasses SWP via
NO_PROXY. Allowed by firewall allow-private-google-apis (Pri 1100). Packets stay within Google's private network; zero public endpoint or NAT traversal.
| Dimension | Purpose 1: Secure Web Proxy (SWP) | Purpose 2: Private Google Access (PGA VIP) |
|---|---|---|
| Destination Scope | External SaaS, public partner APIs, internet destinations | Google Cloud APIs (Cloud Storage, Secret Manager, Firestore, etc.) |
| DNS Resolution | Standard public DNS or resolved dynamically via SWP proxy | Cloud DNS Private Zone (*.googleapis.com ➞ restricted.googleapis.com) |
| Destination IP | External public internet IP (source NATed by Cloud NAT) | Restricted VIP pool: 199.36.153.4/30 (199.36.153.4 - 199.36.153.7) |
| Application Client Handling | Explicit HTTP CONNECT tunnel via HTTP_PROXY / HTTPS_PROXY |
Direct socket connection via NO_PROXY bypass list |
| VPC Firewall Permission | allow-swp-proxy (Priority 1000, TCP:8080 to 10.10.0.10) |
allow-private-google-apis (Priority 1100, TCP:443 to 199.36.153.4/30) |
| Direct Internet Bypass | Blocked by Tenant VPC rule deny-all-egress-ipv4 (Pri 2000) |
Blocked by Tenant VPC rule deny-all-egress-ipv4 (Pri 2000) |
| Data Path Transit | Direct VPC ➞ PSC Endpoint ➞ Central SWP ➞ Cloud NAT ➞ Internet | Direct VPC ➞ Subnet PGA ➞ VPC Route ➞ Google SDN Backbone Core |
[READY] Console initialized. Ready to test Purpose 1 (SWP), Purpose 2 (Private Google Access), GSLB Ingress, or Mesh Microservices.