Creating and Managing Shared VPCs Across Google Cloud Projects: A Step-by-Step Guide
4 min readApr 11, 2023
Step 1: Create the GCP projects
- Log in to the Google Cloud Console (https://console.cloud.google.com/).
- Click the project drop-down and select or create the organization you want to use.
- Open the navigation menu (the three horizontal lines on the upper left corner), and click on “IAM & Admin” > “Manage resources.”
- Click “Create Project” and enter “ntwk-common” as the project name. Choose your organization, billing account, and location if necessary. Click “Create.”
- Repeat step 1.4, but this time, enter “intr-banking” as the project name.
Step 2: Enable the Compute Engine API and Shared VPC
- 2.1. Navigate to the “ntwk-common” project.
- Open the navigation menu, and go to “APIs & Services” > “Dashboard.”
- Click “+ ENABLE APIS AND SERVICES” and search for “Compute Engine API.” Click on it and click “Enable.”
- Open the navigation menu, and go to “VPC network” > “Shared VPC.”
- Click “Setup Shared VPC” and choose the “ntwk-common” project as the host project. Click “Save.”
Step 3: Create VPC and subnets in the ntwk-common project
- In the “ntwk-common” project, open the navigation menu and go to “VPC network” > “VPC networks.”
- Click “Create VPC network” and enter a name for your VPC (e.g., “ntwk-common-vpc”).
- Configure the subnets as required (e.g., name, region, IP range). Click “Add subnet” if you need more subnets.
- Click “Create” to finalize the VPC creation.
Step 4: Share the VPC with the intr-banking project
- In the “ntwk-common” project, open the navigation menu and go to “VPC network” > “Shared VPC.”
- Click “Add Project” and select the “intr-banking” project.
- Click “Add” to add the project as a service project.
- Once the project is added, you’ll see a list of available subnets. Click on the pencil icon next to each subnet you want to share, and select the “intr-banking” project in the “Service project access” section.
- Click “Save” to apply the changes.
Step 5: Set up IAM permissions
- In the “ntwk-common” project, open the navigation menu and go to “IAM & Admin” > “IAM.”
- Click “Add” and enter the email address of the user you want to grant permissions to (it could be your own email or a team member’s email).
- In the “Role” drop-down, select “Compute Shared VPC Admin” and “Compute Network Admin” roles.
- Click “Save” to apply the changes.
- Repeat steps 5.2 to 5.4 in the “intr-banking” project, but this time, assign the “Compute Shared VPC User” role instead.
Step 6: Create resources in the intr-banking project using the shared VPC
- In the “intr-banking” project, open the navigation menu and go to “Compute Engine” > “VM instances.”
- Click “Create Instance” to create a new VM instance.
- Under the “Networking” section, click on the “Network interfaces” tab.
- Click “Edit” next to the default network interface.
- In the “Network” drop-down, select the shared VPC (e.g., “ntwk-common-vpc”) from the “ntwk-common” project.
- In the “Subnetwork” drop-down, select the appropriate shared subnet.
- Click “Done” and then “Create” to finalize the VM instance creation.
Step 7: Create firewall rules in the ntwk-common project
- In the “ntwk-common” project, open the navigation menu and go to “VPC network” > “Firewall.”
- Click “Create firewall rule” and enter a name for the rule.
- Select the shared VPC (e.g., “ntwk-common-vpc”) in the “Network” drop-down.
- Configure the targets, source filter, source IP ranges, and allowed protocols and ports as needed.
- Click “Create” to finalize the firewall rule.
Step 8: Monitoring your network
- In the “ntwk-common” project, open the navigation menu and go to “VPC network” > “VPC networks.”
- Click on the shared VPC (e.g., “ntwk-common-vpc”) to view its details, including subnets, firewall rules, and routes.
- You can also monitor network traffic and performance by going to “VPC network” > “Monitoring” and configuring the desired metrics and filters.
Step 9: Managing resources across projects
- Use labels to tag resources in both the “ntwk-common” and “intr-banking” projects (or any other projects sharing the VPC) to make it easier to manage and organize resources.
- Use Google Cloud’s Operations Suite (formerly Stackdriver) to monitor, troubleshoot, and improve application performance across projects.
Step 10: Scaling your infrastructure
- As your organization grows and you create more projects, you can follow the same process to share the VPC and subnets from the “ntwk-common” project with the new projects, ensuring a consistent networking setup across all your projects.
- You can also create additional subnets, firewall rules, and other networking resources in the “ntwk-common” project as needed to accommodate the growth of your infrastructure.
By following these steps, you can maintain a scalable, organized, and consistent networking setup across all your projects sharing the VPC and subnets from the “ntwk-common” project. This approach makes it easier to manage resources, monitor performance, and troubleshoot issues while also allowing for greater flexibility and control over your infrastructure.
If you find this post helpful, please consider clap and following me. :)