Skip to content

GCP.NetworkServices reference

Source: src/GCP/NetworkServices/AgentGateway.ts

A Network Services Agent Gateway — the proxy that governs access to agents, MCP servers, and tools.

Changing agentGatewayId or location replaces the gateway. Description, labels, registries, network config, and deployment mode update in place.

Google-managed gateway

const gateway = yield* GCP.NetworkServices.AgentGateway("Agents", {
googleManaged: { governedAccessPath: "AGENT_TO_ANYWHERE" },
});

Named gateway with labels

const gateway = yield* GCP.NetworkServices.AgentGateway("Agents", {
agentGatewayId: "app-agents",
location: "us-central1",
description: "prod agents",
labels: { env: "prod" },
googleManaged: { governedAccessPath: "CLIENT_TO_AGENT" },
});

Source: src/GCP/NetworkServices/AuthzExtension.ts

A Network Services AuthzExtension — forwards requests to a callout backend that makes an authorization decision for a load balancer.

Changing authzExtensionId, location, or loadBalancingScheme replaces the extension. Description, labels, service, timeout, authority, fail-open, metadata, headers, and wire format update in place.

AuthzExtension: Creating an AuthzExtension

Section titled “AuthzExtension: Creating an AuthzExtension”

Regional callout

const ext = yield* GCP.NetworkServices.AuthzExtension("Authz", {
service: backend.selfLink,
authority: "authz.example.com",
timeout: "0.1s",
loadBalancingScheme: "INTERNAL_MANAGED",
});

Named extension with labels

const ext = yield* GCP.NetworkServices.AuthzExtension("Authz", {
authzExtensionId: "app-authz",
location: "us-central1",
description: "prod authz",
labels: { env: "prod" },
service: backend.selfLink,
authority: "authz.example.com",
timeout: "0.2s",
failOpen: true,
});

Source: src/GCP/NetworkServices/EndpointPolicy.ts

A Network Services EndpointPolicy — applies TLS and authorization configuration to Traffic Director endpoints that match a metadata selector.

Changing endpointPolicyId, location, or type replaces the policy. Description, labels, matcher, port selector, and policy URLs update in place.

EndpointPolicy: Creating an EndpointPolicy

Section titled “EndpointPolicy: Creating an EndpointPolicy”

Sidecar proxy with a metadata matcher

const policy = yield* GCP.NetworkServices.EndpointPolicy("Sidecar", {
type: "SIDECAR_PROXY",
endpointMatcher: {
metadataLabelMatcher: {
metadataLabelMatchCriteria: "MATCH_ANY",
metadataLabels: [{ labelName: "app", labelValue: "web" }],
},
},
});

Named policy with a port selector

const policy = yield* GCP.NetworkServices.EndpointPolicy("Sidecar", {
endpointPolicyId: "app-sidecar",
description: "prod sidecars",
labels: { env: "prod" },
type: "SIDECAR_PROXY",
trafficPortSelector: { ports: ["8080"] },
endpointMatcher: {
metadataLabelMatcher: {
metadataLabelMatchCriteria: "MATCH_ANY",
metadataLabels: [{ labelName: "app", labelValue: "web" }],
},
},
});

Source: src/GCP/NetworkServices/Gateway.ts

A Network Services Gateway — the ip:port a Mesh or Secure Web Gateway proxy listens on, plus TLS and routing policy.

Changing gatewayId, location, type, network, or subnetwork replaces the gateway. Description, labels, ports, scope, TLS, and routing fields update in place.

Open mesh gateway

const gateway = yield* GCP.NetworkServices.Gateway("Mesh", {
type: "OPEN_MESH",
ports: [443],
});

Named gateway with labels

const gateway = yield* GCP.NetworkServices.Gateway("Mesh", {
gatewayId: "app-mesh",
description: "prod mesh",
labels: { env: "prod" },
type: "OPEN_MESH",
ports: [80, 443],
scope: "prod",
});

Source: src/GCP/NetworkServices/GrpcRoute.ts

A Network Services GrpcRoute — how a Mesh or Gateway routes gRPC traffic for a set of hostnames.

Changing grpcRouteId or location replaces the route. Hostnames, rules, mesh/gateway attachments, description, and labels update in place.

Hostname with a retry policy

const route = yield* GCP.NetworkServices.GrpcRoute("Api", {
hostnames: ["api.example.com"],
rules: [
{
action: {
retryPolicy: { retryConditions: ["unavailable"], numRetries: 2 },
},
},
],
});

Attach to a gateway

const route = yield* GCP.NetworkServices.GrpcRoute("Api", {
grpcRouteId: "app-grpc",
hostnames: ["api.example.com"],
gateways: [gateway.name],
labels: { env: "prod" },
rules: [
{
matches: [{ method: { grpcService: "api.v1.Orders", grpcMethod: "Get" } }],
action: { destinations: [{ serviceName: backend.selfLink }] },
},
],
});

Source: src/GCP/NetworkServices/HttpRoute.ts

A Network Services HttpRoute — how a Mesh or Gateway routes HTTP traffic for a set of hostnames.

Changing httpRouteId or location replaces the route. Hostnames, rules, mesh/gateway attachments, description, and labels update in place.

Redirect

const route = yield* GCP.NetworkServices.HttpRoute("Web", {
hostnames: ["www.example.com"],
rules: [
{
matches: [{ prefixMatch: "/" }],
action: {
redirect: { hostRedirect: "example.com", httpsRedirect: true },
},
},
],
});

Direct response

const route = yield* GCP.NetworkServices.HttpRoute("Health", {
httpRouteId: "app-http",
hostnames: ["health.example.com"],
labels: { env: "prod" },
rules: [
{
matches: [{ fullPathMatch: "/healthz" }],
action: { directResponse: { status: 200, stringBody: "ok" } },
},
],
});

Source: src/GCP/NetworkServices/LbEdgeExtension.ts

A Network Services LbEdgeExtension — a Service Extension that rewrites request headers so an Application Load Balancer can change backend selection and Cloud CDN cache keys.

Changing lbEdgeExtensionId, location, or loadBalancingScheme replaces the extension. Description, labels, forwarding rules, and extension chains update in place.

LbEdgeExtension: Creating an LbEdgeExtension

Section titled “LbEdgeExtension: Creating an LbEdgeExtension”
const ext = yield* GCP.NetworkServices.LbEdgeExtension("Edge", {
loadBalancingScheme: "EXTERNAL_MANAGED",
forwardingRules: [rule.selfLink],
extensionChains: [
{
name: "chain1",
matchCondition: { celExpression: "true" },
extensions: [
{
name: "ext1",
authority: "ext1.example.com",
service: backend.selfLink,
timeout: "0.1s",
supportedEvents: ["REQUEST_HEADERS"],
},
],
},
],
});

Source: src/GCP/NetworkServices/LbRouteExtension.ts

A Network Services LbRouteExtension — a Service Extension that controls where an Application Load Balancer routes a given request.

Changing lbRouteExtensionId, location, or loadBalancingScheme replaces the extension. Description, labels, forwarding rules, extension chains, and metadata update in place.

LbRouteExtension: Creating an LbRouteExtension

Section titled “LbRouteExtension: Creating an LbRouteExtension”
const ext = yield* GCP.NetworkServices.LbRouteExtension("Route", {
location: "us-central1",
loadBalancingScheme: "INTERNAL_MANAGED",
forwardingRules: [rule.selfLink],
extensionChains: [
{
name: "chain1",
matchCondition: { celExpression: "true" },
extensions: [
{
name: "ext1",
authority: "ext1.example.com",
service: backend.selfLink,
timeout: "0.1s",
supportedEvents: ["REQUEST_HEADERS"],
},
],
},
],
});

Source: src/GCP/NetworkServices/LbTrafficExtension.ts

An LbTrafficExtension lets a Service Extension modify request and response headers and payloads without changing backend selection.

Changing lbTrafficExtensionId, location, or loadBalancingScheme replaces the resource. Description, labels, forwarding rules, chains, and metadata update in place.

LbTrafficExtension: Creating an LbTrafficExtension

Section titled “LbTrafficExtension: Creating an LbTrafficExtension”
const extension = yield* GCP.NetworkServices.LbTrafficExtension("Inspect", {
location: "us-central1",
loadBalancingScheme: "INTERNAL_MANAGED",
forwardingRules: [rule.selfLink ?? rule.name],
extensionChains: [
{
name: "all-traffic",
matchCondition: { celExpression: "true" },
extensions: [
{
name: "header-rewriter",
service: callout.selfLink ?? callout.name,
authority: "ext.example.com",
timeout: "0.1s",
failOpen: true,
supportedEvents: ["REQUEST_HEADERS", "RESPONSE_HEADERS"],
},
],
},
],
});

Source: src/GCP/NetworkServices/Mesh.ts

A Cloud Service Mesh configuration grouping for workload-to-workload traffic. Routes attached to the mesh decide how requests are routed inside this logical boundary.

Changing meshId or location replaces the mesh. Description, labels, interception port, and Envoy header settings update in place.

Generated name

const mesh = yield* GCP.NetworkServices.Mesh("Sidecar", {});

Named mesh with interception port

const mesh = yield* GCP.NetworkServices.Mesh("Sidecar", {
meshId: "app-mesh",
description: "prod sidecar mesh",
interceptionPort: 15001,
labels: { env: "prod" },
});

Source: src/GCP/NetworkServices/MulticastConsumerAssociation.ts

A multicast consumer association attaches a consumer VPC to Cloud Multicast in a zone so VMs in that network can join multicast groups.

Changing multicastConsumerAssociationId, location, network, or multicastDomainActivation replaces the association. Description and labels update in place.

MulticastConsumerAssociation: Creating a MulticastConsumerAssociation

Section titled “MulticastConsumerAssociation: Creating a MulticastConsumerAssociation”
const association = yield* GCP.NetworkServices.MulticastConsumerAssociation(
"Consumers",
{
location: "us-central1-a",
network: `projects/${vpc.project}/locations/global/networks/${vpc.networkName}`,
labels: { env: "prod" },
},
);

Source: src/GCP/NetworkServices/MulticastGroupConsumerActivation.ts

A multicast group consumer activation lets VMs in an associated consumer VPC join a multicast group range in the same zone.

Changing multicastGroupConsumerActivationId, location, multicastConsumerAssociation, or multicastGroupRangeActivation replaces the activation. Description, labels, and log config update in place.

MulticastGroupConsumerActivation: Creating a MulticastGroupConsumerActivation

Section titled “MulticastGroupConsumerActivation: Creating a MulticastGroupConsumerActivation”
const activation = yield* GCP.NetworkServices.MulticastGroupConsumerActivation(
"Join",
{
location: association.location,
multicastConsumerAssociation: association.name,
multicastGroupRangeActivation: rangeActivation.name,
logConfig: { enabled: true },
labels: { env: "prod" },
},
);

Source: src/GCP/NetworkServices/ServiceBinding.ts

A ServiceBinding attaches a producer service (Service Directory, PSC, or Cloud Run) so Cloud Service Mesh or an Application Load Balancer can send traffic to it.

Changing serviceBindingId, location, or service replaces the binding. Description and labels update in place.

const binding = yield* GCP.NetworkServices.ServiceBinding("Api", {
location: "global",
description: "prod api",
labels: { env: "prod" },
});

Source: src/GCP/NetworkServices/ServiceLbPolicy.ts

A ServiceLbPolicy holds global load-balancing and traffic-distribution settings that can be attached to a BackendService.

Changing serviceLbPolicyId or location replaces the policy. Description, labels, algorithm, drain, failover, and isolation update in place.

ServiceLbPolicy: Creating a ServiceLbPolicy

Section titled “ServiceLbPolicy: Creating a ServiceLbPolicy”

Generated name

const policy = yield* GCP.NetworkServices.ServiceLbPolicy("Spread", {});

Spray-to-region with failover

const policy = yield* GCP.NetworkServices.ServiceLbPolicy("Spread", {
serviceLbPolicyId: "app-lb-policy",
loadBalancingAlgorithm: "SPRAY_TO_REGION",
autoCapacityDrain: { enable: true },
failoverConfig: { failoverHealthThreshold: 70 },
labels: { env: "prod" },
});

Source: src/GCP/NetworkServices/TcpRoute.ts

A TcpRoute describes how a Mesh or Gateway routes TCP traffic.

Changing tcpRouteId or location replaces the route. Description, labels, rules, meshes, and gateways update in place.

Original-destination sidecar route

const route = yield* GCP.NetworkServices.TcpRoute("Passthrough", {
meshes: [mesh.name],
rules: [
{
matches: [{ address: "0.0.0.0/0", port: "443" }],
action: { originalDestination: true },
},
],
});

Weighted backend destinations

const route = yield* GCP.NetworkServices.TcpRoute("Split", {
meshes: [mesh.name],
rules: [
{
action: {
destinations: [
{ serviceName: backend.name, weight: 80 },
{ serviceName: canary.name, weight: 20 },
],
},
},
],
});

Source: src/GCP/NetworkServices/TlsRoute.ts

A TlsRoute routes TLS traffic based on SNI and ALPN for a Mesh, Gateway, or TargetTcpProxy.

Changing tlsRouteId or location replaces the route. Description, labels, rules, meshes, gateways, and target proxies update in place.

const route = yield* GCP.NetworkServices.TlsRoute("Secure", {
meshes: [mesh.name],
rules: [
{
matches: [{ sniHost: ["api.example.com"], alpn: ["h2"] }],
action: {
destinations: [{ serviceName: backend.name, weight: 1 }],
},
},
],
});

Source: src/GCP/NetworkServices/WasmPlugin.ts

A Network Services WasmPlugin — a Service Extensions plugin that runs a customer-provided Wasm module.

Changing wasmPluginId or location replaces the plugin. Description, labels, mainVersionId, logConfig, and an explicit versions map update in place. Child WasmPluginsVersion resources are preserved unless versions is set on this plugin.

Generated name

const plugin = yield* GCP.NetworkServices.WasmPlugin("Edge", {
description: "edge plugin",
});

Named plugin with logging

const plugin = yield* GCP.NetworkServices.WasmPlugin("Edge", {
wasmPluginId: "app-edge",
description: "prod edge",
labels: { env: "prod" },
logConfig: { enable: true, sampleRate: 1, minLogLevel: "WARN" },
});
const plugin = yield* GCP.NetworkServices.WasmPlugin("Edge", {
mainVersionId: "v1",
versions: {
v1: {
imageUri: "us-central1-docker.pkg.dev/my-project/plugins/edge:v1",
},
},
});

Source: src/GCP/NetworkServices/WasmPluginsVersion.ts

An immutable WasmPluginVersion nested under a WasmPlugin. Each version points at a Wasm module in Artifact Registry and optionally a runtime config.

There is no patch API. Changing the parent plugin, version id, location, image URI, or plugin config replaces the version. Description and labels are applied at create time.

WasmPluginsVersion: Creating a WasmPluginsVersion

Section titled “WasmPluginsVersion: Creating a WasmPluginsVersion”

Version from a Docker image

const version = yield* GCP.NetworkServices.WasmPluginsVersion("V1", {
wasmPlugin: plugin.name,
imageUri: "us-central1-docker.pkg.dev/my-project/plugins/edge:v1",
});

Named version with config

const version = yield* GCP.NetworkServices.WasmPluginsVersion("V1", {
wasmPlugin: plugin.name,
wasmPluginVersionId: "v1",
description: "prod edge v1",
labels: { env: "prod" },
imageUri:
"projects/my-project/locations/us-central1/repositories/plugins/genericArtifacts/edge:v1",
pluginConfigData: "e30=",
});