Streamlined IP administration for GDC
With GDC IP handle administration, now you can plan, monitor, and monitor IP addresses for all of your workloads and infrastructure. IPAM for GDC is a precious device, since many air-gapped deployments devour IP addresses out of your group’s present personal IP handle area, which could be tough to handle, not very scalable, missing in safety, and finite. IPAM for GDC supplies the next capabilities:
- Automated and streamlined IP administration: Decrease handbook errors and pace up deployments with capabilities that embody Per-Org BYO-Exterior IP and Inside-only VPC subnets.
- Scalable IP administration: Increase your community for Day-2 IP development, free from duplicate IP handle conflicts, and with assist for non-contiguous subnets.
- Enhanced safety and compliance: Strengthen your posture and meet strict compliance necessities with strong IPAM controls, together with subnet delegation and personal IPs for zonal infrastructure.
- Optimized IP useful resource utilization: Cut back IP sprawl and maximize your finite IP assets.
IPAM for GDC supplies the clever automation and centralized oversight important for managing your full IP lifecycle in safe, air-gapped environments, serving to to make sure each operational excellence and adherence to essential laws.
Excessive availability with multi-zone load balancers
For essential purposes, downtime just isn’t an choice. Now, you’ll be able to assist your workloads stay resilient and accessible, even within the occasion of a zone failure.
Our new multi-zone load balancing functionality lets you distribute visitors throughout a number of availability zones inside your GDC setting. Each inner and exterior load balancers now assist this multi-zone performance, simplifying operations whereas maximizing uptime. This supplies:
-
Steady availability: Purposes stay accessible even throughout a whole zone failure.
-
Operational simplification: There’s a single Anycast IP handle for the applying (no matter the place backends are situated).
-
Optimized efficiency: Site visitors is routed to the closest out there occasion based mostly on community topology and routing metrics.
The load balancing system operates by creating load balancer (LB) objects, that are then dealt with by new LB API controllers. These controllers handle object circumstances, together with cross-references and digital IP handle (VIP) auto-reservations, and create Kubernetes providers throughout all clusters.
Workload-level community firewall insurance policies
To safe an setting, you want to management visitors not simply on the edge, however between each part inside. That is why we’re launching workload-level firewall insurance policies as a part of the GDC air-gapped product. This characteristic supplies fine-grained management over communication between particular person workloads, similar to VMs and pods, inside a challenge. This characteristic helps:
-
Strengthen your safety posture: Isolate workloads and restrict communication between them.
-
Simply apply insurance policies: Outline and apply insurance policies to particular workloads or teams of workloads.
-
Meet regulatory requirements: Assist adhere to regulatory necessities and inner requirements.
GDC air-gapped implements default base community insurance policies to create a safe structure. To be able to permit intra-project or cross-project visitors on the workload stage, you’ll be able to replace these default insurance policies as you would like. Insurance policies are multi-zone by default. This implies they have an effect on all zones the place your labeled workloads are current. You’ll be able to implement insurance policies on the workload stage utilizing labels and workload selectors.
A brand new period of community management
These new capabilities — GDC IPAM, multi-zone load balancing, and workload-level firewall insurance policies — characterize a major step ahead in offering a strong, resilient, and safe networking expertise for the air-gapped cloud. They work collectively to simplify your operations, strengthen your safety posture, and empower you to run your most delicate purposes with confidence.
To be taught extra about these options, please discuss with our documentation or contact your Google Cloud account staff.