GCP.NetworkConnectivity reference
AutomatedDnsRecord
Section titled “AutomatedDnsRecord”Source:
src/GCP/NetworkConnectivity/AutomatedDnsRecord.ts
A DNS record managed by Network Connectivity Service Connectivity Automation.
Identity fields (automatedDnsRecordId, location, serviceClass,
creationMode, recordType, hostname, dnsSuffix,
originalConfig, consumerNetwork) replace the record. The API has
no patch method.
AutomatedDnsRecord: Creating an AutomatedDnsRecord
Section titled “AutomatedDnsRecord: Creating an AutomatedDnsRecord”const network = yield* GCP.Compute.Network("AppVpc", { autoCreateSubnetworks: false,});const record = yield* GCP.NetworkConnectivity.AutomatedDnsRecord("Redis", { serviceClass: "gcp-memorystore-redis", creationMode: "CONSUMER_API", recordType: "A", hostname: "redis", dnsSuffix: "psc.internal.", originalConfig: { ttl: "30s", rrdatas: ["10.0.0.1"] }, consumerNetwork: network.selfLink ?? network.networkName, labels: { env: "prod" },});Source:
src/GCP/NetworkConnectivity/Hub.ts
A Network Connectivity Center hub — the global attachment point for VPC, VPN, and interconnect spokes.
Hubs live at locations/global. Changing hubId replaces the hub.
Description, labels, exportPsc, policyMode, and presetTopology
update in place. A hub can only be deleted when it has no spokes.
Hub: Creating a Hub
Section titled “Hub: Creating a Hub”Generated name
const hub = yield* GCP.NetworkConnectivity.Hub("Mesh", {});Named hub with labels
const hub = yield* GCP.NetworkConnectivity.Hub("Mesh", { hubId: "app-mesh", description: "prod mesh", labels: { env: "prod" },});Hub: Preset topology
Section titled “Hub: Preset topology”const hub = yield* GCP.NetworkConnectivity.Hub("Star", { policyMode: "PRESET", presetTopology: "STAR",});Hub: Private Service Connect
Section titled “Hub: Private Service Connect”const hub = yield* GCP.NetworkConnectivity.Hub("Mesh", { exportPsc: true,});Hub: Updating a Hub
Section titled “Hub: Updating a Hub”const hub = yield* GCP.NetworkConnectivity.Hub("Mesh", { hubId: "app-mesh", description: "prod mesh v2", exportPsc: true, labels: { env: "prod", role: "ncc" },});InternalRange
Section titled “InternalRange”Source:
src/GCP/NetworkConnectivity/InternalRange.ts
A Network Connectivity internal range — an IPAM reservation inside a VPC, with usage and peering behavior.
Ranges live at locations/global. internalRangeId, location,
network, usage, peering, immutable, and migration are
immutable. Description, labels, CIDR, prefix length, overlaps, target
CIDRs, exclude CIDRs, and allocation options update in place.
InternalRange: Creating an Internal Range
Section titled “InternalRange: Creating an Internal Range”Generated name on a custom VPC
const network = yield* GCP.Compute.Network("Vpc", { autoCreateSubnetworks: false,});const range = yield* GCP.NetworkConnectivity.InternalRange("Reserved", { network: network.selfLink ?? network.networkName, usage: "FOR_VPC", peering: "FOR_SELF", ipCidrRange: "10.0.0.0/24",});Explicit id, labels, and description
const range = yield* GCP.NetworkConnectivity.InternalRange("Reserved", { internalRangeId: "app-reserved", network: "projects/{project}/global/networks/app-vpc", usage: "FOR_VPC", peering: "FOR_SELF", ipCidrRange: "10.0.0.0/24", description: "app subnet space", labels: { env: "prod" },});InternalRange: Auto-allocation
Section titled “InternalRange: Auto-allocation”const range = yield* GCP.NetworkConnectivity.InternalRange("Reserved", { network: network.networkName, usage: "FOR_VPC", peering: "FOR_SELF", prefixLength: 24, targetCidrRange: ["192.168.0.0/16"], allocationOptions: { allocationStrategy: "FIRST_SMALLEST_FITTING" },});InternalRange: External reservation
Section titled “InternalRange: External reservation”const range = yield* GCP.NetworkConnectivity.InternalRange("OnPrem", { network: network.networkName, usage: "EXTERNAL_TO_VPC", peering: "FOR_SELF", ipCidrRange: "172.16.0.0/24", labels: { role: "on-prem" },});InternalRange: Updating an Internal Range
Section titled “InternalRange: Updating an Internal Range”const range = yield* GCP.NetworkConnectivity.InternalRange("Reserved", { internalRangeId: "app-reserved", network: "app-vpc", usage: "FOR_VPC", peering: "FOR_SELF", ipCidrRange: "10.0.0.0/24", description: "app subnet space v2", labels: { env: "prod", role: "ipam" },});MulticloudDataTransferConfig
Section titled “MulticloudDataTransferConfig”Source:
src/GCP/NetworkConnectivity/MulticloudDataTransferConfig.ts
A Data Transfer Essentials MulticloudDataTransferConfig — the
billing/metering configuration for services whose traffic is billed
through DTE.
Changing multicloudDataTransferConfigId or location replaces the
config. Description, labels, and services update in place.
MulticloudDataTransferConfig: Creating a Config
Section titled “MulticloudDataTransferConfig: Creating a Config”Generated name
const config = yield* GCP.NetworkConnectivity.MulticloudDataTransferConfig( "Dte", { description: "dte metering", labels: { env: "prod" } },);Named config with a service
const config = yield* GCP.NetworkConnectivity.MulticloudDataTransferConfig( "Dte", { multicloudDataTransferConfigId: "app-dte", location: "us-central1", services: { "google-cloud-storage": {} }, },);MulticloudDataTransferConfig: Updating a Config
Section titled “MulticloudDataTransferConfig: Updating a Config”const config = yield* GCP.NetworkConnectivity.MulticloudDataTransferConfig( "Dte", { multicloudDataTransferConfigId: "app-dte", location: "us-central1", description: "dte metering v2", labels: { env: "prod", role: "dte" }, },);MulticloudDataTransferConfigsDestination
Section titled “MulticloudDataTransferConfigsDestination”Source:
src/GCP/NetworkConnectivity/MulticloudDataTransferConfigsDestination.ts
A Data Transfer Essentials Destination — an IP prefix plus ASN/CSP
endpoints billed through a MulticloudDataTransferConfig.
Changing parent, destinationId, or ipPrefix replaces the
destination. Description, labels, and endpoints update in place.
MulticloudDataTransferConfigsDestination: Creating a Destination
Section titled “MulticloudDataTransferConfigsDestination: Creating a Destination”const config = yield* GCP.NetworkConnectivity.MulticloudDataTransferConfig( "Dte", {},);const destination = yield* GCP.NetworkConnectivity.MulticloudDataTransferConfigsDestination( "OnPrem", { parent: config.name, ipPrefix: "203.0.113.0/24", endpoints: [{ asn: "64512", csp: "aws" }], labels: { env: "prod" }, }, );MulticloudDataTransferConfigsDestination: Updating a Destination
Section titled “MulticloudDataTransferConfigsDestination: Updating a Destination”const destination = yield* GCP.NetworkConnectivity.MulticloudDataTransferConfigsDestination( "OnPrem", { parent: config.name, ipPrefix: "203.0.113.0/24", endpoints: [ { asn: "64512", csp: "aws" }, { asn: "64513", csp: "azure" }, ], description: "on-prem v2", labels: { env: "prod", role: "dte" }, }, );PolicyBasedRoute
Section titled “PolicyBasedRoute”Source:
src/GCP/NetworkConnectivity/PolicyBasedRoute.ts
A VPC policy-based route.
Policy-based routes match L4 traffic by source, destination, and
protocol — not just destination IP — and always take precedence over
other route types. They live at locations/global. The API has create,
get, list, and delete only, so every user-facing field is immutable and
changing it replaces the resource.
PolicyBasedRoute: Creating a Policy-Based Route
Section titled “PolicyBasedRoute: Creating a Policy-Based Route”Skip other policy-based routes
const network = yield* GCP.Compute.Network("Vpc", { autoCreateSubnetworks: false,});const route = yield* GCP.NetworkConnectivity.PolicyBasedRoute("Skip", { network: network.networkName, filter: { protocolVersion: "IPV4" }, nextHopOtherRoutes: "DEFAULT_ROUTING",});Named route with VM tags and an ILB next hop
const route = yield* GCP.NetworkConnectivity.PolicyBasedRoute("Inspect", { policyBasedRouteId: "app-inspect", network: network.networkName, filter: { protocolVersion: "IPV4", ipProtocol: "TCP", srcRange: "10.0.0.0/8", destRange: "0.0.0.0/0", }, nextHopIlbIp: "10.10.10.20", virtualMachine: { tags: ["client"] }, priority: 500, description: "send tagged VMs to the inspection ILB", labels: { env: "prod" },});PolicyBasedRoute: Interconnect attachments
Section titled “PolicyBasedRoute: Interconnect attachments”const route = yield* GCP.NetworkConnectivity.PolicyBasedRoute("Vlan", { network: network.networkName, filter: { protocolVersion: "IPV4" }, nextHopOtherRoutes: "DEFAULT_ROUTING", interconnectAttachment: { region: "all" },});RegionalEndpoint
Section titled “RegionalEndpoint”Source:
src/GCP/NetworkConnectivity/RegionalEndpoint.ts
A Private Service Connect regional endpoint for a Google API.
Identity fields (regionalEndpointId, location, targetGoogleApi,
accessType, network, subnetwork, address) replace the
endpoint. The API has no patch method.
RegionalEndpoint: Creating a RegionalEndpoint
Section titled “RegionalEndpoint: Creating a RegionalEndpoint”const network = yield* GCP.Compute.Network("AppVpc", { autoCreateSubnetworks: false,});const subnet = yield* GCP.Compute.Subnetwork("AppSubnet", { network: network.selfLink ?? network.networkName, ipCidrRange: "10.20.0.0/24", privateIpGoogleAccess: true,});const endpoint = yield* GCP.NetworkConnectivity.RegionalEndpoint("Storage", { targetGoogleApi: "storage.us-central1.p.rep.googleapis.com", accessType: "REGIONAL", network: network.selfLink ?? network.networkName, subnetwork: subnet.selfLink ?? subnet.subnetworkName, labels: { env: "prod" },});ServiceConnectionMap
Section titled “ServiceConnectionMap”Source:
src/GCP/NetworkConnectivity/ServiceConnectionMap.ts
A PSC Service Connection Map that pairs producer service attachments with consumer networks for Cross-Cloud / producer-consumer connectivity.
Changing serviceConnectionMapId or location replaces the map.
Description, labels, token, and PSC configs update in place.
ServiceConnectionMap: Creating a ServiceConnectionMap
Section titled “ServiceConnectionMap: Creating a ServiceConnectionMap”const map = yield* GCP.NetworkConnectivity.ServiceConnectionMap("Sql", { serviceClass: "gcp-cloud-sql", description: "sql psc map", labels: { env: "prod" },});ServiceConnectionMap: Updating a ServiceConnectionMap
Section titled “ServiceConnectionMap: Updating a ServiceConnectionMap”const map = yield* GCP.NetworkConnectivity.ServiceConnectionMap("Sql", { serviceClass: "gcp-cloud-sql", description: "sql psc map v2", labels: { env: "prod", role: "psc" },});ServiceConnectionPolicy
Section titled “ServiceConnectionPolicy”Source:
src/GCP/NetworkConnectivity/ServiceConnectionPolicy.ts
A PSC Service Connection Policy that allows a consumer VPC to connect to a producer service class (Cloud SQL, Memorystore, …).
Changing serviceConnectionPolicyId, location, or network
replaces the policy. Description, labels, serviceClass, and
pscConfig update in place.
ServiceConnectionPolicy: Creating a ServiceConnectionPolicy
Section titled “ServiceConnectionPolicy: Creating a ServiceConnectionPolicy”const network = yield* GCP.Compute.Network("AppVpc", { autoCreateSubnetworks: false,});const subnet = yield* GCP.Compute.Subnetwork("PscSubnet", { network: network.selfLink ?? network.networkName, ipCidrRange: "10.20.0.0/24",});const policy = yield* GCP.NetworkConnectivity.ServiceConnectionPolicy( "Redis", { serviceClass: "gcp-memorystore-redis", network: network.selfLink ?? network.networkName, pscConfig: { subnetworks: [subnet.selfLink ?? subnet.subnetworkName], }, labels: { env: "prod" }, },);ServiceConnectionPolicy: Updating a ServiceConnectionPolicy
Section titled “ServiceConnectionPolicy: Updating a ServiceConnectionPolicy”const policy = yield* GCP.NetworkConnectivity.ServiceConnectionPolicy( "Redis", { serviceClass: "gcp-memorystore-redis", network: network.selfLink ?? network.networkName, description: "redis psc v2", pscConfig: { subnetworks: [subnet.selfLink ?? subnet.subnetworkName], limit: "4", }, labels: { env: "prod", role: "psc" }, },);ServiceConnectionToken
Section titled “ServiceConnectionToken”Source:
src/GCP/NetworkConnectivity/ServiceConnectionToken.ts
A PSC Service Connection Token that authenticates a consumer to create connections in a producer Service Connection Map.
Changing serviceConnectionTokenId, location, or network
replaces the token. The API has no patch method.
ServiceConnectionToken: Creating a ServiceConnectionToken
Section titled “ServiceConnectionToken: Creating a ServiceConnectionToken”const network = yield* GCP.Compute.Network("AppVpc", { autoCreateSubnetworks: false,});const token = yield* GCP.NetworkConnectivity.ServiceConnectionToken( "Consumer", { network: network.selfLink ?? network.networkName, description: "psc token", labels: { env: "prod" }, },);Source:
src/GCP/NetworkConnectivity/Spoke.ts
A Network Connectivity Center spoke — one VPC, VPN tunnel set, VLAN attachment set, router-appliance set, producer VPC, or gateway attached to a hub.
Set exactly one of linkedVpcNetwork, linkedVpnTunnels,
linkedInterconnectAttachments, linkedRouterApplianceInstances,
linkedProducerVpcNetwork, or gateway. VPC spokes live at
location: "global"; hybrid spokes are regional.
Changing spokeId, location, hub, group, or the linked
resource identity replaces the spoke. Description, labels, and
include/exclude CIDR ranges update in place.
Spoke: Creating a Spoke
Section titled “Spoke: Creating a Spoke”VPC spoke on a generated name
const network = yield* GCP.Compute.Network("AppVpc", { autoCreateSubnetworks: false,});const hub = yield* GCP.NetworkConnectivity.Hub("Mesh", {});const spoke = yield* GCP.NetworkConnectivity.Spoke("AppVpcSpoke", { hub: hub.name, linkedVpcNetwork: { uri: network.selfLink! },});Named VPC spoke with labels and export filters
const spoke = yield* GCP.NetworkConnectivity.Spoke("AppVpcSpoke", { spokeId: "app-vpc", location: "global", hub: hub.name, description: "app vpc", labels: { env: "prod" }, linkedVpcNetwork: { uri: network.selfLink!, includeExportRanges: ["10.0.0.0/8"], },});Spoke: Updating a Spoke
Section titled “Spoke: Updating a Spoke”const spoke = yield* GCP.NetworkConnectivity.Spoke("AppVpcSpoke", { spokeId: "app-vpc", location: "global", hub: hub.name, description: "app vpc v2", labels: { env: "prod", role: "spoke" }, linkedVpcNetwork: { uri: network.selfLink!, includeExportRanges: ["10.0.0.0/8", "192.168.0.0/16"], },});SpokesGatewayAdvertisedRoute
Section titled “SpokesGatewayAdvertisedRoute”Source:
src/GCP/NetworkConnectivity/SpokesGatewayAdvertisedRoute.ts
A route a Network Connectivity Center gateway spoke advertises to a hub (or other recipient).
Changing parent, gatewayAdvertisedRouteId, ipRange, labels, or
description replaces the route (GCP does not allow updating labels or
the description). priority and recipient update in place.
SpokesGatewayAdvertisedRoute: Creating a GatewayAdvertisedRoute
Section titled “SpokesGatewayAdvertisedRoute: Creating a GatewayAdvertisedRoute”const hub = yield* GCP.NetworkConnectivity.Hub("Mesh", {});const spoke = yield* GCP.NetworkConnectivity.Spoke("Gw", { location: "us-central1", hub: hub.name, gateway: { capacity: "CAPACITY_1_GBPS", ipRangeReservations: [{ ipRange: "10.200.0.0/23" }], },});const route = yield* GCP.NetworkConnectivity.SpokesGatewayAdvertisedRoute( "OnPrem", { parent: spoke.name, ipRange: "192.168.0.0/16", recipient: "ADVERTISE_TO_HUB", labels: { env: "prod" }, },);SpokesGatewayAdvertisedRoute: Updating a GatewayAdvertisedRoute
Section titled “SpokesGatewayAdvertisedRoute: Updating a GatewayAdvertisedRoute”const route = yield* GCP.NetworkConnectivity.SpokesGatewayAdvertisedRoute( "OnPrem", { parent: spoke.name, ipRange: "192.168.0.0/16", priority: 200, recipient: "ADVERTISE_TO_HUB", description: "on-prem v2", labels: { env: "prod" }, },);Transport
Section titled “Transport”Source:
src/GCP/NetworkConnectivity/Transport.ts
A Network Connectivity Partner Cross-Cloud Interconnect transport.
Transports attach a VPC (or NCC hub, on the beta API) to a remote
cloud-service-provider profile such as AWS or Azure. transportId,
location, network, remoteProfile, providedActivationKey, and
remoteAccountId are immutable. Description, labels, bandwidth,
stack type, and advertised routes update in place. Creating a
transport without an activation key typically leaves it in
PENDING_KEY until the remote provider accepts the generated key.
Transport: Creating a Transport
Section titled “Transport: Creating a Transport”Generated name with an AWS profile
const network = yield* GCP.Compute.Network("Vpc", { autoCreateSubnetworks: false,});const transport = yield* GCP.NetworkConnectivity.Transport("Aws", { location: "us-east4", network: network.selfLink ?? network.networkName, remoteProfile: "aws-us-east-1", bandwidth: "BPS_1G", remoteAccountId: "123456789012", advertisedRoutes: ["10.0.0.0/8"],});Named transport with labels
const transport = yield* GCP.NetworkConnectivity.Transport("Aws", { transportId: "app-aws", location: "us-east4", network: "projects/{project}/global/networks/app-vpc", remoteProfile: "aws-us-east-1", bandwidth: "BPS_1G", remoteAccountId: "123456789012", description: "prod aws interconnect", labels: { env: "prod" },});Transport: Activation key
Section titled “Transport: Activation key”const transport = yield* GCP.NetworkConnectivity.Transport("Azure", { location: "us-east4", network: network.networkName, providedActivationKey: "ABC1234",});Transport: Updating a Transport
Section titled “Transport: Updating a Transport”const transport = yield* GCP.NetworkConnectivity.Transport("Aws", { transportId: "app-aws", location: "us-east4", network: "app-vpc", remoteProfile: "aws-us-east-1", bandwidth: "BPS_2G", remoteAccountId: "123456789012", advertisedRoutes: ["10.0.0.0/8", "192.168.0.0/16"], description: "prod aws interconnect v2", labels: { env: "prod", role: "cci" },});