Skip to content

GCP.NetworkConnectivity reference

Source: src/GCP/NetworkConnectivity/AutomatedDnsRecord.ts

A DNS record managed by Network Connectivity Service Connectivity Automation.

Identity fields (automatedDnsRecordId, location, serviceClass, creationMode, recordType, hostname, dnsSuffix, originalConfig, consumerNetwork) replace the record. The API has no patch method.

AutomatedDnsRecord: Creating an AutomatedDnsRecord

Section titled “AutomatedDnsRecord: Creating an AutomatedDnsRecord”
const network = yield* GCP.Compute.Network("AppVpc", {
autoCreateSubnetworks: false,
});
const record = yield* GCP.NetworkConnectivity.AutomatedDnsRecord("Redis", {
serviceClass: "gcp-memorystore-redis",
creationMode: "CONSUMER_API",
recordType: "A",
hostname: "redis",
dnsSuffix: "psc.internal.",
originalConfig: { ttl: "30s", rrdatas: ["10.0.0.1"] },
consumerNetwork: network.selfLink ?? network.networkName,
labels: { env: "prod" },
});

Source: src/GCP/NetworkConnectivity/Hub.ts

A Network Connectivity Center hub — the global attachment point for VPC, VPN, and interconnect spokes.

Hubs live at locations/global. Changing hubId replaces the hub. Description, labels, exportPsc, policyMode, and presetTopology update in place. A hub can only be deleted when it has no spokes.

Generated name

const hub = yield* GCP.NetworkConnectivity.Hub("Mesh", {});

Named hub with labels

const hub = yield* GCP.NetworkConnectivity.Hub("Mesh", {
hubId: "app-mesh",
description: "prod mesh",
labels: { env: "prod" },
});
const hub = yield* GCP.NetworkConnectivity.Hub("Star", {
policyMode: "PRESET",
presetTopology: "STAR",
});
const hub = yield* GCP.NetworkConnectivity.Hub("Mesh", {
exportPsc: true,
});
const hub = yield* GCP.NetworkConnectivity.Hub("Mesh", {
hubId: "app-mesh",
description: "prod mesh v2",
exportPsc: true,
labels: { env: "prod", role: "ncc" },
});

Source: src/GCP/NetworkConnectivity/InternalRange.ts

A Network Connectivity internal range — an IPAM reservation inside a VPC, with usage and peering behavior.

Ranges live at locations/global. internalRangeId, location, network, usage, peering, immutable, and migration are immutable. Description, labels, CIDR, prefix length, overlaps, target CIDRs, exclude CIDRs, and allocation options update in place.

Generated name on a custom VPC

const network = yield* GCP.Compute.Network("Vpc", {
autoCreateSubnetworks: false,
});
const range = yield* GCP.NetworkConnectivity.InternalRange("Reserved", {
network: network.selfLink ?? network.networkName,
usage: "FOR_VPC",
peering: "FOR_SELF",
ipCidrRange: "10.0.0.0/24",
});

Explicit id, labels, and description

const range = yield* GCP.NetworkConnectivity.InternalRange("Reserved", {
internalRangeId: "app-reserved",
network: "projects/{project}/global/networks/app-vpc",
usage: "FOR_VPC",
peering: "FOR_SELF",
ipCidrRange: "10.0.0.0/24",
description: "app subnet space",
labels: { env: "prod" },
});
const range = yield* GCP.NetworkConnectivity.InternalRange("Reserved", {
network: network.networkName,
usage: "FOR_VPC",
peering: "FOR_SELF",
prefixLength: 24,
targetCidrRange: ["192.168.0.0/16"],
allocationOptions: { allocationStrategy: "FIRST_SMALLEST_FITTING" },
});
const range = yield* GCP.NetworkConnectivity.InternalRange("OnPrem", {
network: network.networkName,
usage: "EXTERNAL_TO_VPC",
peering: "FOR_SELF",
ipCidrRange: "172.16.0.0/24",
labels: { role: "on-prem" },
});
const range = yield* GCP.NetworkConnectivity.InternalRange("Reserved", {
internalRangeId: "app-reserved",
network: "app-vpc",
usage: "FOR_VPC",
peering: "FOR_SELF",
ipCidrRange: "10.0.0.0/24",
description: "app subnet space v2",
labels: { env: "prod", role: "ipam" },
});

Source: src/GCP/NetworkConnectivity/MulticloudDataTransferConfig.ts

A Data Transfer Essentials MulticloudDataTransferConfig — the billing/metering configuration for services whose traffic is billed through DTE.

Changing multicloudDataTransferConfigId or location replaces the config. Description, labels, and services update in place.

MulticloudDataTransferConfig: Creating a Config

Section titled “MulticloudDataTransferConfig: Creating a Config”

Generated name

const config = yield* GCP.NetworkConnectivity.MulticloudDataTransferConfig(
"Dte",
{ description: "dte metering", labels: { env: "prod" } },
);

Named config with a service

const config = yield* GCP.NetworkConnectivity.MulticloudDataTransferConfig(
"Dte",
{
multicloudDataTransferConfigId: "app-dte",
location: "us-central1",
services: { "google-cloud-storage": {} },
},
);

MulticloudDataTransferConfig: Updating a Config

Section titled “MulticloudDataTransferConfig: Updating a Config”
const config = yield* GCP.NetworkConnectivity.MulticloudDataTransferConfig(
"Dte",
{
multicloudDataTransferConfigId: "app-dte",
location: "us-central1",
description: "dte metering v2",
labels: { env: "prod", role: "dte" },
},
);

Source: src/GCP/NetworkConnectivity/MulticloudDataTransferConfigsDestination.ts

A Data Transfer Essentials Destination — an IP prefix plus ASN/CSP endpoints billed through a MulticloudDataTransferConfig.

Changing parent, destinationId, or ipPrefix replaces the destination. Description, labels, and endpoints update in place.

MulticloudDataTransferConfigsDestination: Creating a Destination

Section titled “MulticloudDataTransferConfigsDestination: Creating a Destination”
const config = yield* GCP.NetworkConnectivity.MulticloudDataTransferConfig(
"Dte",
{},
);
const destination =
yield* GCP.NetworkConnectivity.MulticloudDataTransferConfigsDestination(
"OnPrem",
{
parent: config.name,
ipPrefix: "203.0.113.0/24",
endpoints: [{ asn: "64512", csp: "aws" }],
labels: { env: "prod" },
},
);

MulticloudDataTransferConfigsDestination: Updating a Destination

Section titled “MulticloudDataTransferConfigsDestination: Updating a Destination”
const destination =
yield* GCP.NetworkConnectivity.MulticloudDataTransferConfigsDestination(
"OnPrem",
{
parent: config.name,
ipPrefix: "203.0.113.0/24",
endpoints: [
{ asn: "64512", csp: "aws" },
{ asn: "64513", csp: "azure" },
],
description: "on-prem v2",
labels: { env: "prod", role: "dte" },
},
);

Source: src/GCP/NetworkConnectivity/PolicyBasedRoute.ts

A VPC policy-based route.

Policy-based routes match L4 traffic by source, destination, and protocol — not just destination IP — and always take precedence over other route types. They live at locations/global. The API has create, get, list, and delete only, so every user-facing field is immutable and changing it replaces the resource.

PolicyBasedRoute: Creating a Policy-Based Route

Section titled “PolicyBasedRoute: Creating a Policy-Based Route”

Skip other policy-based routes

const network = yield* GCP.Compute.Network("Vpc", {
autoCreateSubnetworks: false,
});
const route = yield* GCP.NetworkConnectivity.PolicyBasedRoute("Skip", {
network: network.networkName,
filter: { protocolVersion: "IPV4" },
nextHopOtherRoutes: "DEFAULT_ROUTING",
});

Named route with VM tags and an ILB next hop

const route = yield* GCP.NetworkConnectivity.PolicyBasedRoute("Inspect", {
policyBasedRouteId: "app-inspect",
network: network.networkName,
filter: {
protocolVersion: "IPV4",
ipProtocol: "TCP",
srcRange: "10.0.0.0/8",
destRange: "0.0.0.0/0",
},
nextHopIlbIp: "10.10.10.20",
virtualMachine: { tags: ["client"] },
priority: 500,
description: "send tagged VMs to the inspection ILB",
labels: { env: "prod" },
});

PolicyBasedRoute: Interconnect attachments

Section titled “PolicyBasedRoute: Interconnect attachments”
const route = yield* GCP.NetworkConnectivity.PolicyBasedRoute("Vlan", {
network: network.networkName,
filter: { protocolVersion: "IPV4" },
nextHopOtherRoutes: "DEFAULT_ROUTING",
interconnectAttachment: { region: "all" },
});

Source: src/GCP/NetworkConnectivity/RegionalEndpoint.ts

A Private Service Connect regional endpoint for a Google API.

Identity fields (regionalEndpointId, location, targetGoogleApi, accessType, network, subnetwork, address) replace the endpoint. The API has no patch method.

RegionalEndpoint: Creating a RegionalEndpoint

Section titled “RegionalEndpoint: Creating a RegionalEndpoint”
const network = yield* GCP.Compute.Network("AppVpc", {
autoCreateSubnetworks: false,
});
const subnet = yield* GCP.Compute.Subnetwork("AppSubnet", {
network: network.selfLink ?? network.networkName,
ipCidrRange: "10.20.0.0/24",
privateIpGoogleAccess: true,
});
const endpoint = yield* GCP.NetworkConnectivity.RegionalEndpoint("Storage", {
targetGoogleApi: "storage.us-central1.p.rep.googleapis.com",
accessType: "REGIONAL",
network: network.selfLink ?? network.networkName,
subnetwork: subnet.selfLink ?? subnet.subnetworkName,
labels: { env: "prod" },
});

Source: src/GCP/NetworkConnectivity/ServiceConnectionMap.ts

A PSC Service Connection Map that pairs producer service attachments with consumer networks for Cross-Cloud / producer-consumer connectivity.

Changing serviceConnectionMapId or location replaces the map. Description, labels, token, and PSC configs update in place.

ServiceConnectionMap: Creating a ServiceConnectionMap

Section titled “ServiceConnectionMap: Creating a ServiceConnectionMap”
const map = yield* GCP.NetworkConnectivity.ServiceConnectionMap("Sql", {
serviceClass: "gcp-cloud-sql",
description: "sql psc map",
labels: { env: "prod" },
});

ServiceConnectionMap: Updating a ServiceConnectionMap

Section titled “ServiceConnectionMap: Updating a ServiceConnectionMap”
const map = yield* GCP.NetworkConnectivity.ServiceConnectionMap("Sql", {
serviceClass: "gcp-cloud-sql",
description: "sql psc map v2",
labels: { env: "prod", role: "psc" },
});

Source: src/GCP/NetworkConnectivity/ServiceConnectionPolicy.ts

A PSC Service Connection Policy that allows a consumer VPC to connect to a producer service class (Cloud SQL, Memorystore, …).

Changing serviceConnectionPolicyId, location, or network replaces the policy. Description, labels, serviceClass, and pscConfig update in place.

ServiceConnectionPolicy: Creating a ServiceConnectionPolicy

Section titled “ServiceConnectionPolicy: Creating a ServiceConnectionPolicy”
const network = yield* GCP.Compute.Network("AppVpc", {
autoCreateSubnetworks: false,
});
const subnet = yield* GCP.Compute.Subnetwork("PscSubnet", {
network: network.selfLink ?? network.networkName,
ipCidrRange: "10.20.0.0/24",
});
const policy = yield* GCP.NetworkConnectivity.ServiceConnectionPolicy(
"Redis",
{
serviceClass: "gcp-memorystore-redis",
network: network.selfLink ?? network.networkName,
pscConfig: {
subnetworks: [subnet.selfLink ?? subnet.subnetworkName],
},
labels: { env: "prod" },
},
);

ServiceConnectionPolicy: Updating a ServiceConnectionPolicy

Section titled “ServiceConnectionPolicy: Updating a ServiceConnectionPolicy”
const policy = yield* GCP.NetworkConnectivity.ServiceConnectionPolicy(
"Redis",
{
serviceClass: "gcp-memorystore-redis",
network: network.selfLink ?? network.networkName,
description: "redis psc v2",
pscConfig: {
subnetworks: [subnet.selfLink ?? subnet.subnetworkName],
limit: "4",
},
labels: { env: "prod", role: "psc" },
},
);

Source: src/GCP/NetworkConnectivity/ServiceConnectionToken.ts

A PSC Service Connection Token that authenticates a consumer to create connections in a producer Service Connection Map.

Changing serviceConnectionTokenId, location, or network replaces the token. The API has no patch method.

ServiceConnectionToken: Creating a ServiceConnectionToken

Section titled “ServiceConnectionToken: Creating a ServiceConnectionToken”
const network = yield* GCP.Compute.Network("AppVpc", {
autoCreateSubnetworks: false,
});
const token = yield* GCP.NetworkConnectivity.ServiceConnectionToken(
"Consumer",
{
network: network.selfLink ?? network.networkName,
description: "psc token",
labels: { env: "prod" },
},
);

Source: src/GCP/NetworkConnectivity/Spoke.ts

A Network Connectivity Center spoke — one VPC, VPN tunnel set, VLAN attachment set, router-appliance set, producer VPC, or gateway attached to a hub.

Set exactly one of linkedVpcNetwork, linkedVpnTunnels, linkedInterconnectAttachments, linkedRouterApplianceInstances, linkedProducerVpcNetwork, or gateway. VPC spokes live at location: "global"; hybrid spokes are regional.

Changing spokeId, location, hub, group, or the linked resource identity replaces the spoke. Description, labels, and include/exclude CIDR ranges update in place.

VPC spoke on a generated name

const network = yield* GCP.Compute.Network("AppVpc", {
autoCreateSubnetworks: false,
});
const hub = yield* GCP.NetworkConnectivity.Hub("Mesh", {});
const spoke = yield* GCP.NetworkConnectivity.Spoke("AppVpcSpoke", {
hub: hub.name,
linkedVpcNetwork: { uri: network.selfLink! },
});

Named VPC spoke with labels and export filters

const spoke = yield* GCP.NetworkConnectivity.Spoke("AppVpcSpoke", {
spokeId: "app-vpc",
location: "global",
hub: hub.name,
description: "app vpc",
labels: { env: "prod" },
linkedVpcNetwork: {
uri: network.selfLink!,
includeExportRanges: ["10.0.0.0/8"],
},
});
const spoke = yield* GCP.NetworkConnectivity.Spoke("AppVpcSpoke", {
spokeId: "app-vpc",
location: "global",
hub: hub.name,
description: "app vpc v2",
labels: { env: "prod", role: "spoke" },
linkedVpcNetwork: {
uri: network.selfLink!,
includeExportRanges: ["10.0.0.0/8", "192.168.0.0/16"],
},
});

Source: src/GCP/NetworkConnectivity/SpokesGatewayAdvertisedRoute.ts

A route a Network Connectivity Center gateway spoke advertises to a hub (or other recipient).

Changing parent, gatewayAdvertisedRouteId, ipRange, labels, or description replaces the route (GCP does not allow updating labels or the description). priority and recipient update in place.

SpokesGatewayAdvertisedRoute: Creating a GatewayAdvertisedRoute

Section titled “SpokesGatewayAdvertisedRoute: Creating a GatewayAdvertisedRoute”
const hub = yield* GCP.NetworkConnectivity.Hub("Mesh", {});
const spoke = yield* GCP.NetworkConnectivity.Spoke("Gw", {
location: "us-central1",
hub: hub.name,
gateway: {
capacity: "CAPACITY_1_GBPS",
ipRangeReservations: [{ ipRange: "10.200.0.0/23" }],
},
});
const route = yield* GCP.NetworkConnectivity.SpokesGatewayAdvertisedRoute(
"OnPrem",
{
parent: spoke.name,
ipRange: "192.168.0.0/16",
recipient: "ADVERTISE_TO_HUB",
labels: { env: "prod" },
},
);

SpokesGatewayAdvertisedRoute: Updating a GatewayAdvertisedRoute

Section titled “SpokesGatewayAdvertisedRoute: Updating a GatewayAdvertisedRoute”
const route = yield* GCP.NetworkConnectivity.SpokesGatewayAdvertisedRoute(
"OnPrem",
{
parent: spoke.name,
ipRange: "192.168.0.0/16",
priority: 200,
recipient: "ADVERTISE_TO_HUB",
description: "on-prem v2",
labels: { env: "prod" },
},
);

Source: src/GCP/NetworkConnectivity/Transport.ts

A Network Connectivity Partner Cross-Cloud Interconnect transport.

Transports attach a VPC (or NCC hub, on the beta API) to a remote cloud-service-provider profile such as AWS or Azure. transportId, location, network, remoteProfile, providedActivationKey, and remoteAccountId are immutable. Description, labels, bandwidth, stack type, and advertised routes update in place. Creating a transport without an activation key typically leaves it in PENDING_KEY until the remote provider accepts the generated key.

Generated name with an AWS profile

const network = yield* GCP.Compute.Network("Vpc", {
autoCreateSubnetworks: false,
});
const transport = yield* GCP.NetworkConnectivity.Transport("Aws", {
location: "us-east4",
network: network.selfLink ?? network.networkName,
remoteProfile: "aws-us-east-1",
bandwidth: "BPS_1G",
remoteAccountId: "123456789012",
advertisedRoutes: ["10.0.0.0/8"],
});

Named transport with labels

const transport = yield* GCP.NetworkConnectivity.Transport("Aws", {
transportId: "app-aws",
location: "us-east4",
network: "projects/{project}/global/networks/app-vpc",
remoteProfile: "aws-us-east-1",
bandwidth: "BPS_1G",
remoteAccountId: "123456789012",
description: "prod aws interconnect",
labels: { env: "prod" },
});
const transport = yield* GCP.NetworkConnectivity.Transport("Azure", {
location: "us-east4",
network: network.networkName,
providedActivationKey: "ABC1234",
});
const transport = yield* GCP.NetworkConnectivity.Transport("Aws", {
transportId: "app-aws",
location: "us-east4",
network: "app-vpc",
remoteProfile: "aws-us-east-1",
bandwidth: "BPS_2G",
remoteAccountId: "123456789012",
advertisedRoutes: ["10.0.0.0/8", "192.168.0.0/16"],
description: "prod aws interconnect v2",
labels: { env: "prod", role: "cci" },
});