GCP.NetworkServices reference
AgentGateway
Section titled “AgentGateway”Source:
src/GCP/NetworkServices/AgentGateway.ts
A Network Services Agent Gateway — the proxy that governs access to agents, MCP servers, and tools.
Changing agentGatewayId or location replaces the gateway.
Description, labels, registries, network config, and deployment mode
update in place.
AgentGateway: Creating an AgentGateway
Section titled “AgentGateway: Creating an AgentGateway”Google-managed gateway
const gateway = yield* GCP.NetworkServices.AgentGateway("Agents", { googleManaged: { governedAccessPath: "AGENT_TO_ANYWHERE" },});Named gateway with labels
const gateway = yield* GCP.NetworkServices.AgentGateway("Agents", { agentGatewayId: "app-agents", location: "us-central1", description: "prod agents", labels: { env: "prod" }, googleManaged: { governedAccessPath: "CLIENT_TO_AGENT" },});AuthzExtension
Section titled “AuthzExtension”Source:
src/GCP/NetworkServices/AuthzExtension.ts
A Network Services AuthzExtension — forwards requests to a callout backend that makes an authorization decision for a load balancer.
Changing authzExtensionId, location, or loadBalancingScheme
replaces the extension. Description, labels, service, timeout,
authority, fail-open, metadata, headers, and wire format update in
place.
AuthzExtension: Creating an AuthzExtension
Section titled “AuthzExtension: Creating an AuthzExtension”Regional callout
const ext = yield* GCP.NetworkServices.AuthzExtension("Authz", { service: backend.selfLink, authority: "authz.example.com", timeout: "0.1s", loadBalancingScheme: "INTERNAL_MANAGED",});Named extension with labels
const ext = yield* GCP.NetworkServices.AuthzExtension("Authz", { authzExtensionId: "app-authz", location: "us-central1", description: "prod authz", labels: { env: "prod" }, service: backend.selfLink, authority: "authz.example.com", timeout: "0.2s", failOpen: true,});EndpointPolicy
Section titled “EndpointPolicy”Source:
src/GCP/NetworkServices/EndpointPolicy.ts
A Network Services EndpointPolicy — applies TLS and authorization configuration to Traffic Director endpoints that match a metadata selector.
Changing endpointPolicyId, location, or type replaces the
policy. Description, labels, matcher, port selector, and policy URLs
update in place.
EndpointPolicy: Creating an EndpointPolicy
Section titled “EndpointPolicy: Creating an EndpointPolicy”Sidecar proxy with a metadata matcher
const policy = yield* GCP.NetworkServices.EndpointPolicy("Sidecar", { type: "SIDECAR_PROXY", endpointMatcher: { metadataLabelMatcher: { metadataLabelMatchCriteria: "MATCH_ANY", metadataLabels: [{ labelName: "app", labelValue: "web" }], }, },});Named policy with a port selector
const policy = yield* GCP.NetworkServices.EndpointPolicy("Sidecar", { endpointPolicyId: "app-sidecar", description: "prod sidecars", labels: { env: "prod" }, type: "SIDECAR_PROXY", trafficPortSelector: { ports: ["8080"] }, endpointMatcher: { metadataLabelMatcher: { metadataLabelMatchCriteria: "MATCH_ANY", metadataLabels: [{ labelName: "app", labelValue: "web" }], }, },});Gateway
Section titled “Gateway”Source:
src/GCP/NetworkServices/Gateway.ts
A Network Services Gateway — the ip:port a Mesh or Secure Web Gateway proxy listens on, plus TLS and routing policy.
Changing gatewayId, location, type, network, or subnetwork
replaces the gateway. Description, labels, ports, scope, TLS, and
routing fields update in place.
Gateway: Creating a Gateway
Section titled “Gateway: Creating a Gateway”Open mesh gateway
const gateway = yield* GCP.NetworkServices.Gateway("Mesh", { type: "OPEN_MESH", ports: [443],});Named gateway with labels
const gateway = yield* GCP.NetworkServices.Gateway("Mesh", { gatewayId: "app-mesh", description: "prod mesh", labels: { env: "prod" }, type: "OPEN_MESH", ports: [80, 443], scope: "prod",});GrpcRoute
Section titled “GrpcRoute”Source:
src/GCP/NetworkServices/GrpcRoute.ts
A Network Services GrpcRoute — how a Mesh or Gateway routes gRPC traffic for a set of hostnames.
Changing grpcRouteId or location replaces the route. Hostnames,
rules, mesh/gateway attachments, description, and labels update in
place.
GrpcRoute: Creating a GrpcRoute
Section titled “GrpcRoute: Creating a GrpcRoute”Hostname with a retry policy
const route = yield* GCP.NetworkServices.GrpcRoute("Api", { hostnames: ["api.example.com"], rules: [ { action: { retryPolicy: { retryConditions: ["unavailable"], numRetries: 2 }, }, }, ],});Attach to a gateway
const route = yield* GCP.NetworkServices.GrpcRoute("Api", { grpcRouteId: "app-grpc", hostnames: ["api.example.com"], gateways: [gateway.name], labels: { env: "prod" }, rules: [ { matches: [{ method: { grpcService: "api.v1.Orders", grpcMethod: "Get" } }], action: { destinations: [{ serviceName: backend.selfLink }] }, }, ],});HttpRoute
Section titled “HttpRoute”Source:
src/GCP/NetworkServices/HttpRoute.ts
A Network Services HttpRoute — how a Mesh or Gateway routes HTTP traffic for a set of hostnames.
Changing httpRouteId or location replaces the route. Hostnames,
rules, mesh/gateway attachments, description, and labels update in
place.
HttpRoute: Creating an HttpRoute
Section titled “HttpRoute: Creating an HttpRoute”Redirect
const route = yield* GCP.NetworkServices.HttpRoute("Web", { hostnames: ["www.example.com"], rules: [ { matches: [{ prefixMatch: "/" }], action: { redirect: { hostRedirect: "example.com", httpsRedirect: true }, }, }, ],});Direct response
const route = yield* GCP.NetworkServices.HttpRoute("Health", { httpRouteId: "app-http", hostnames: ["health.example.com"], labels: { env: "prod" }, rules: [ { matches: [{ fullPathMatch: "/healthz" }], action: { directResponse: { status: 200, stringBody: "ok" } }, }, ],});LbEdgeExtension
Section titled “LbEdgeExtension”Source:
src/GCP/NetworkServices/LbEdgeExtension.ts
A Network Services LbEdgeExtension — a Service Extension that rewrites request headers so an Application Load Balancer can change backend selection and Cloud CDN cache keys.
Changing lbEdgeExtensionId, location, or loadBalancingScheme
replaces the extension. Description, labels, forwarding rules, and
extension chains update in place.
LbEdgeExtension: Creating an LbEdgeExtension
Section titled “LbEdgeExtension: Creating an LbEdgeExtension”const ext = yield* GCP.NetworkServices.LbEdgeExtension("Edge", { loadBalancingScheme: "EXTERNAL_MANAGED", forwardingRules: [rule.selfLink], extensionChains: [ { name: "chain1", matchCondition: { celExpression: "true" }, extensions: [ { name: "ext1", authority: "ext1.example.com", service: backend.selfLink, timeout: "0.1s", supportedEvents: ["REQUEST_HEADERS"], }, ], }, ],});LbRouteExtension
Section titled “LbRouteExtension”Source:
src/GCP/NetworkServices/LbRouteExtension.ts
A Network Services LbRouteExtension — a Service Extension that controls where an Application Load Balancer routes a given request.
Changing lbRouteExtensionId, location, or loadBalancingScheme
replaces the extension. Description, labels, forwarding rules,
extension chains, and metadata update in place.
LbRouteExtension: Creating an LbRouteExtension
Section titled “LbRouteExtension: Creating an LbRouteExtension”const ext = yield* GCP.NetworkServices.LbRouteExtension("Route", { location: "us-central1", loadBalancingScheme: "INTERNAL_MANAGED", forwardingRules: [rule.selfLink], extensionChains: [ { name: "chain1", matchCondition: { celExpression: "true" }, extensions: [ { name: "ext1", authority: "ext1.example.com", service: backend.selfLink, timeout: "0.1s", supportedEvents: ["REQUEST_HEADERS"], }, ], }, ],});LbTrafficExtension
Section titled “LbTrafficExtension”Source:
src/GCP/NetworkServices/LbTrafficExtension.ts
An LbTrafficExtension lets a Service Extension modify request and response headers and payloads without changing backend selection.
Changing lbTrafficExtensionId, location, or loadBalancingScheme
replaces the resource. Description, labels, forwarding rules, chains,
and metadata update in place.
LbTrafficExtension: Creating an LbTrafficExtension
Section titled “LbTrafficExtension: Creating an LbTrafficExtension”const extension = yield* GCP.NetworkServices.LbTrafficExtension("Inspect", { location: "us-central1", loadBalancingScheme: "INTERNAL_MANAGED", forwardingRules: [rule.selfLink ?? rule.name], extensionChains: [ { name: "all-traffic", matchCondition: { celExpression: "true" }, extensions: [ { name: "header-rewriter", service: callout.selfLink ?? callout.name, authority: "ext.example.com", timeout: "0.1s", failOpen: true, supportedEvents: ["REQUEST_HEADERS", "RESPONSE_HEADERS"], }, ], }, ],});Source:
src/GCP/NetworkServices/Mesh.ts
A Cloud Service Mesh configuration grouping for workload-to-workload traffic. Routes attached to the mesh decide how requests are routed inside this logical boundary.
Changing meshId or location replaces the mesh. Description,
labels, interception port, and Envoy header settings update in place.
Mesh: Creating a Mesh
Section titled “Mesh: Creating a Mesh”Generated name
const mesh = yield* GCP.NetworkServices.Mesh("Sidecar", {});Named mesh with interception port
const mesh = yield* GCP.NetworkServices.Mesh("Sidecar", { meshId: "app-mesh", description: "prod sidecar mesh", interceptionPort: 15001, labels: { env: "prod" },});MulticastConsumerAssociation
Section titled “MulticastConsumerAssociation”Source:
src/GCP/NetworkServices/MulticastConsumerAssociation.ts
A multicast consumer association attaches a consumer VPC to Cloud Multicast in a zone so VMs in that network can join multicast groups.
Changing multicastConsumerAssociationId, location, network, or
multicastDomainActivation replaces the association. Description and
labels update in place.
MulticastConsumerAssociation: Creating a MulticastConsumerAssociation
Section titled “MulticastConsumerAssociation: Creating a MulticastConsumerAssociation”const association = yield* GCP.NetworkServices.MulticastConsumerAssociation( "Consumers", { location: "us-central1-a", network: `projects/${vpc.project}/locations/global/networks/${vpc.networkName}`, labels: { env: "prod" }, },);MulticastGroupConsumerActivation
Section titled “MulticastGroupConsumerActivation”Source:
src/GCP/NetworkServices/MulticastGroupConsumerActivation.ts
A multicast group consumer activation lets VMs in an associated consumer VPC join a multicast group range in the same zone.
Changing multicastGroupConsumerActivationId, location,
multicastConsumerAssociation, or multicastGroupRangeActivation
replaces the activation. Description, labels, and log config update
in place.
MulticastGroupConsumerActivation: Creating a MulticastGroupConsumerActivation
Section titled “MulticastGroupConsumerActivation: Creating a MulticastGroupConsumerActivation”const activation = yield* GCP.NetworkServices.MulticastGroupConsumerActivation( "Join", { location: association.location, multicastConsumerAssociation: association.name, multicastGroupRangeActivation: rangeActivation.name, logConfig: { enabled: true }, labels: { env: "prod" }, },);ServiceBinding
Section titled “ServiceBinding”Source:
src/GCP/NetworkServices/ServiceBinding.ts
A ServiceBinding attaches a producer service (Service Directory, PSC, or Cloud Run) so Cloud Service Mesh or an Application Load Balancer can send traffic to it.
Changing serviceBindingId, location, or service replaces the
binding. Description and labels update in place.
ServiceBinding: Creating a ServiceBinding
Section titled “ServiceBinding: Creating a ServiceBinding”const binding = yield* GCP.NetworkServices.ServiceBinding("Api", { location: "global", description: "prod api", labels: { env: "prod" },});ServiceLbPolicy
Section titled “ServiceLbPolicy”Source:
src/GCP/NetworkServices/ServiceLbPolicy.ts
A ServiceLbPolicy holds global load-balancing and traffic-distribution settings that can be attached to a BackendService.
Changing serviceLbPolicyId or location replaces the policy.
Description, labels, algorithm, drain, failover, and isolation update
in place.
ServiceLbPolicy: Creating a ServiceLbPolicy
Section titled “ServiceLbPolicy: Creating a ServiceLbPolicy”Generated name
const policy = yield* GCP.NetworkServices.ServiceLbPolicy("Spread", {});Spray-to-region with failover
const policy = yield* GCP.NetworkServices.ServiceLbPolicy("Spread", { serviceLbPolicyId: "app-lb-policy", loadBalancingAlgorithm: "SPRAY_TO_REGION", autoCapacityDrain: { enable: true }, failoverConfig: { failoverHealthThreshold: 70 }, labels: { env: "prod" },});TcpRoute
Section titled “TcpRoute”Source:
src/GCP/NetworkServices/TcpRoute.ts
A TcpRoute describes how a Mesh or Gateway routes TCP traffic.
Changing tcpRouteId or location replaces the route. Description,
labels, rules, meshes, and gateways update in place.
TcpRoute: Creating a TcpRoute
Section titled “TcpRoute: Creating a TcpRoute”Original-destination sidecar route
const route = yield* GCP.NetworkServices.TcpRoute("Passthrough", { meshes: [mesh.name], rules: [ { matches: [{ address: "0.0.0.0/0", port: "443" }], action: { originalDestination: true }, }, ],});Weighted backend destinations
const route = yield* GCP.NetworkServices.TcpRoute("Split", { meshes: [mesh.name], rules: [ { action: { destinations: [ { serviceName: backend.name, weight: 80 }, { serviceName: canary.name, weight: 20 }, ], }, }, ],});TlsRoute
Section titled “TlsRoute”Source:
src/GCP/NetworkServices/TlsRoute.ts
A TlsRoute routes TLS traffic based on SNI and ALPN for a Mesh, Gateway, or TargetTcpProxy.
Changing tlsRouteId or location replaces the route. Description,
labels, rules, meshes, gateways, and target proxies update in place.
TlsRoute: Creating a TlsRoute
Section titled “TlsRoute: Creating a TlsRoute”const route = yield* GCP.NetworkServices.TlsRoute("Secure", { meshes: [mesh.name], rules: [ { matches: [{ sniHost: ["api.example.com"], alpn: ["h2"] }], action: { destinations: [{ serviceName: backend.name, weight: 1 }], }, }, ],});WasmPlugin
Section titled “WasmPlugin”Source:
src/GCP/NetworkServices/WasmPlugin.ts
A Network Services WasmPlugin — a Service Extensions plugin that runs a customer-provided Wasm module.
Changing wasmPluginId or location replaces the plugin.
Description, labels, mainVersionId, logConfig, and an explicit
versions map update in place. Child WasmPluginsVersion resources
are preserved unless versions is set on this plugin.
WasmPlugin: Creating a WasmPlugin
Section titled “WasmPlugin: Creating a WasmPlugin”Generated name
const plugin = yield* GCP.NetworkServices.WasmPlugin("Edge", { description: "edge plugin",});Named plugin with logging
const plugin = yield* GCP.NetworkServices.WasmPlugin("Edge", { wasmPluginId: "app-edge", description: "prod edge", labels: { env: "prod" }, logConfig: { enable: true, sampleRate: 1, minLogLevel: "WARN" },});WasmPlugin: Inline versions
Section titled “WasmPlugin: Inline versions”const plugin = yield* GCP.NetworkServices.WasmPlugin("Edge", { mainVersionId: "v1", versions: { v1: { imageUri: "us-central1-docker.pkg.dev/my-project/plugins/edge:v1", }, },});WasmPluginsVersion
Section titled “WasmPluginsVersion”Source:
src/GCP/NetworkServices/WasmPluginsVersion.ts
An immutable WasmPluginVersion nested under a WasmPlugin. Each version points at a Wasm module in Artifact Registry and optionally a runtime config.
There is no patch API. Changing the parent plugin, version id, location, image URI, or plugin config replaces the version. Description and labels are applied at create time.
WasmPluginsVersion: Creating a WasmPluginsVersion
Section titled “WasmPluginsVersion: Creating a WasmPluginsVersion”Version from a Docker image
const version = yield* GCP.NetworkServices.WasmPluginsVersion("V1", { wasmPlugin: plugin.name, imageUri: "us-central1-docker.pkg.dev/my-project/plugins/edge:v1",});Named version with config
const version = yield* GCP.NetworkServices.WasmPluginsVersion("V1", { wasmPlugin: plugin.name, wasmPluginVersionId: "v1", description: "prod edge v1", labels: { env: "prod" }, imageUri: "projects/my-project/locations/us-central1/repositories/plugins/genericArtifacts/edge:v1", pluginConfigData: "e30=",});