Create a Looker (Google Cloud core) instance with Private Service Connect enabled to ensure secure and private connections for your production or non-production environments. You can set up your instance by using the Google Cloud console, the gcloud CLI, or Terraform. For other connection options, refer to the documentation for public secure connections or private services access.
Private Service Connect can be enabled for a Looker (Google Cloud core) instance that meets the following criteria:
- The Looker (Google Cloud core) instance must be new. Private Service Connect can be enabled only at the time of instance creation.
- The instance edition must be Enterprise (
core-enterprise-annual) or Embed (core-embed-annual).
Before you begin
- Work with Sales to ensure that your annual contract is completed and that you have quota allocated in your project.
- Make sure that billing is enabled for your Google Cloud project.
- In the Google Cloud console, on the project selector page, select the project where you want to create the Private Service Connect instance.
- Enable the Looker API for your project in the Google Cloud console. When enabling the API, you may need to refresh the console page to confirm that the API has been enabled.
- Set up an OAuth client and create authorization credentials. The OAuth client lets you authenticate and access the instance. You must set up OAuth to create a Looker (Google Cloud core) instance, even if you are using a different authentication method to authenticate users into your instance.
- If you want to use VPC Service Controls or customer-managed encryption keys (CMEK) with the Looker (Google Cloud core) instance that you are creating, additional setup is required prior to instance creation. Additional edition and network configuration may also be required during instance creation.
Required roles
To get the permissions that
you need to create a Looker (Google Cloud core) instance,
ask your administrator to grant you the
Looker Admin (roles/looker.admin) IAM role on the project the instance will reside in.
For more information about granting roles, see Manage access to projects, folders, and organizations.
You might also be able to get the required permissions through custom roles or other predefined roles.
You may also need additional IAM roles to set up VPC Service Controls or customer-managed encryption keys (CMEK). Visit the documentation pages for those features to learn more.
Create a Private Service Connect instance
console
- Navigate to the Looker (Google Cloud core) product page from your project in the Google Cloud console. If you have already created a Looker (Google Cloud core) instance within this project, the Instances page will open.
- Click CREATE INSTANCE.
- In the Instance name section, provide a name for your Looker (Google Cloud core) instance. The instance name isn't associated with the URL of the Looker (Google Cloud core) instance once it is created. The instance name cannot be changed after instance creation.
In the Region section, select the appropriate option from the drop-down menu to host your Looker (Google Cloud core) instance. Select the region that matches the region in the subscription contract, which is where the quota for your project is allocated. Available regions are listed on the Looker (Google Cloud core) locations documentation page.
You cannot change the region once the instance has been created.
In the Edition section, choose an Enterprise or Embed (production or non-production) edition option. The edition type affects some of the features that are available for the instance. Make sure that you choose the same edition type as listed in your annual contract and that you have quota allocated for that edition type.
- Enterprise: Looker (Google Cloud core) platform with enhanced security features for addressing a wide variety of internal BI and analytics use cases
- Embed: Looker (Google Cloud core) platform for deploying and maintaining reliable external analytics and custom applications at scale
- Non-production editions: If you want a staging and testing environment, select one of the non-production editions. For more information, see the Non-production instances documentation.
- Trial editions: A trial edition has the same feature support as its corresponding production edition, with the exception that trial editions are valid for 90 days.
Editions cannot be changed after instance creation. If you want to change an edition, you can use import and export to move your Looker (Google Cloud core) instance data into a new instance that is configured with a different edition.
In the Customize your instance section, click Show configuration options to display a group of additional settings that you can customize for the instance.
In the Connections section, under Instance IP assignment, choose either Use hybrid connections or Use private connections. The type of network connection that you select impacts the Looker features that are available to the instance. The following network connection options are available:
- Use public secure connections: Looker will have a public URL and use a public network for outbound connections.
Use hybrid connections: Looker will have a public URL and use PSC endpoints for outbound connections.
Use private connections: Assigns an internal, customer-defined IP address that is accessible in a Virtual Private Cloud (VPC) for ingress. To communicate to VPC and on-premises or multi-cloud workloads, you must deploy service attachments for egress traffic. If you want to use VPC Service Controls, you must select Use private connections.
In the OAuth Application Credentials section, enter the OAuth client ID and OAuth secret that you created when you set up your OAuth client.
If you are creating an instance that uses only private connections, set at least one allowed VPC that will be granted inbound connections into the instance. Under Configure inbound connections, in the Project 1 field, select the project in which this network was created.
To add additional inbound connections, click Add Item to add each VPC. In the Project X field, select the project in which the network was created. In the Network drop-down menu, select the network.
If you select Use hybrid connections in the Connections section, the Configure inbound connections section doesn't appear. You can set up access to the instance through the instance's web URL.
In the Local FQDN section, specify one or more service attachments that expose an endpoint for outbound connections that Looker can connect to. In the Local FQDN 1 field, enter the fully qualified domain name of the service, and in the Target Service Attachment URI 1 field, enter the full service attachment URI for the external service.
To add additional service attachments, click Add Item to add each service attachment. In the Local FQDN field, enter the fully qualified domain name of the service. In the Target Service Attachment URI field, enter the full service attachment URI for the external service.
In the Encryption section, you can select the type of encryption to use on your instance. The following encryption options are available:
- Google-managed encryption key: This option is the default and doesn't require any additional configuration.
- Customer-managed encryption key (CMEK): See the Using customer-managed encryption keys with Looker (Google Cloud core) documentation page for more information on CMEK and how to configure it during instance creation. The type of encryption cannot be changed after instance creation.
- Enable FIPS 140-3 level 1 Validated Encryption: See the Enable FIPS 140-3 level 1 compliance on a Looker (Google Cloud core) instance documentation page for more information on FIPS 140-3 level 1 support on Looker (Google Cloud core).
In the Release Channel section, select the release channel that best fits your needs:
- Rapid: Earliest access to features. Recommended for non-production instances.
- Regular: Balanced stability. Recommended for production instances.
- No channel: No release channel. During the preview, No channel is the default.
In the Maintenance Window section, you can optionally specify the day of the week and the hour in which Looker (Google Cloud core) schedules maintenance. Maintenance windows last for one hour. By default, the Preferred Window option in the Maintenance Window is set to Any window.
In the Deny Maintenance Period section, you can optionally specify a block of days on which Looker (Google Cloud core) doesn't schedule maintenance. Deny maintenance periods can be up to 60 days long. You must allow at least 14 days of maintenance availability between any 2 deny maintenance periods. You cannot set a deny maintenance period if you are also enrolling the instance in the Rapid release channel or using the Accelerated Security Patching (ASP) configuration flag with the Regular release channel.
In the Gemini in Looker section, you can optionally make Gemini in Looker features available for the Looker (Google Cloud core) instance. To enable Gemini in Looker, select Gemini, and then select Trusted Tester features. When Trusted Tester features is enabled, users can access the Trusted Tester capabilities of Gemini in Looker. You may request access to the non-public Trusted Tester capabilities through the Gemini in Looker preview form on a per-user basis. You must enable this setting to use Gemini during the pre-GA preview. Optionally, select Trusted Tester data use. When this setting is enabled, you consent to your data being used by Google as described in the Gemini for Google Cloud Trusted Tester Program termsTo disable Gemini for a Looker (Google Cloud core) instance, clear the Gemini setting.
In the Knowledge Catalog integration section, you can optionally select the Opt out of Knowledge Catalog integration checkbox if you want Looker (Google Cloud core) to disable the integration with Knowledge Catalog. The integration between Looker (Google Cloud core) and Knowledge Catalog is enabled by default.
Click Create.
gcloud
To create a Private Service Connect instance, run the gcloud looker instances create command with all the following flags:
gcloud looker instances create INSTANCE_NAME \ --psc-enabled \ --oauth-client-id=OAUTH_CLIENT_ID \ --oauth-client-secret=OAUTH_CLIENT_SECRET \ --region=REGION \ --edition=EDITION \ [--psc-allowed-vpcs=ALLOWED_VPC,ADDITIONAL_ALLOWED_VPCS]\ [--no-public-ip-enabled]\ [--public-ip-enabled]\ [--release-channel=RELEASE_CHANNEL]\ --async
Replace the following:
INSTANCE_NAME: a name for your Looker (Google Cloud core) instance; it is not associated with the instance URL.OAUTH_CLIENT_IDandOAUTH_CLIENT_SECRET: the OAuth client ID and OAuth secret that you created when you set up your OAuth client. After the instance has been created, enter the instance's URL in the Authorized redirect URIs section of the OAuth client.REGION: the region in which your Looker (Google Cloud core) instance is hosted. Select the region that matches the region in the subscription contract. Available regions are listed on the Looker (Google Cloud core) locations documentation page.EDITION: the edition, environment type (production or non-production), and whether this is a trial edition for the instance. Its available values arecore-enterprise-annual,core-embed-annual,nonprod-core-enterprise-annual,nonprod-core-embed-annual,core-trial-enterprise, andcore-trial-embed. Editions cannot be changed after instance creation. If you want to change an edition, you can use import and export to move your Looker (Google Cloud core) instance data into a new instance that is configured with a different edition.ALLOWED_VPC: If you are creating an instance that uses only private connections, list a VPC that will be allowed inbound (ingress) access into Looker (Google Cloud core). To access the instance from outside the VPC that the instance is located in, you must list at least one VPC. Specify a VPC using one of the following formats:projects/{project}/global/networks/{network}https://www.googleapis.com/compute/v1/projects/{project}/global/networks/{network}
If you are creating an instance that uses hybrid connections, you don't need to set an allowed VPC.
ADDITIONAL_ALLOWED_VPCS: any additional VPCs to be allowed inbound access into Looker (Google Cloud core) can be added to the--psc-allowed-vpcsflag in a comma-separated list.RELEASE_CHANNEL: the release channel for the instance. Available values arerapid,regular, andno-channel. The default during the preview isno-channel. If you don't include this flag in yourcreatecommand, the instance will be created with the default channel. This feature is in preview.
You must also include one of the following flags to enable or disable public connections:
--public-ip-enabledenables public connections. If you enable public connections for the instance, incoming traffic will be routed through public connections, and outgoing traffic will be routed through Private Service Connect.--no-public-ip-enableddisables public connections.
If you want, you can add more parameters to apply other instance settings:
[--maintenance-window-day=MAINTENANCE_WINDOW_DAY
--maintenance-window-time=MAINTENANCE_WINDOW_TIME]
[--deny-maintenance-period-end-date=DENY_MAINTENANCE_PERIOD_END_DATE
--deny-maintenance-period-start-date=DENY_MAINTENANCE_PERIOD_START_DATE
--deny-maintenance-period-time=DENY_MAINTENANCE_PERIOD_TIME]
[--kms-key=KMS_KEY_ID]
[--accelerated-security-patch-enabled]
[--no-accelerated-security-patch-enabled]
[--fips-enabled]
[--catalog-integration-enabled]
[--no-catalog-integration-enabled]
Replace the following:
MAINTENANCE_WINDOW_DAY: Must be one of the following:friday,monday,saturday,sunday,thursday,tuesday,wednesday. See the Manage maintenance policies for Looker (Google Cloud core) documentation page for more information about maintenance window settings.MAINTENANCE_WINDOW_TIMEandDENY_MAINTENANCE_PERIOD_TIME: Must be in UTC time in 24-hour format (for example,13:00,17:45). You cannot set a deny maintenance period if you are also enrolling the instance in the Rapid release channel or using the Accelerated Security Patching (ASP) configuration flag with the Regular release channel.DENY_MAINTENANCE_PERIOD_START_DATEandDENY_MAINTENANCE_PERIOD_END_DATE: Must be in the formatYYYY-MM-DD.KMS_KEY_ID: Must be the key that is created when setting up customer-managed encryption keys (CMEK).
The following flags enable other settings:
--accelerated-security-patch-enabledand--no-accelerated-security-patch-enabled: Include one of these flags if your instance is on theregularchannel and you want to receive or disable security patches bi-weekly. This feature is in preview.--fips-enabled: enable FIPS 140-3 level 1 compliance.- replace the
--catalog-integration-enabledflag with the--no-catalog-integration-enabledflag to disable the Looker (Google Cloud core) and Knowledge Catalog integration. This feature is in preview.
The process for creating a Private Service Connect instance differs from the process for creating a Looker (Google Cloud core) (private services access) instance in the following ways:
- With Private Service Connect setup, the
--consumer-networkand--reserved-rangeflags are not necessary. - Private Service Connect instances require an additional flag:
--psc-enabled. - The
--psc-allowed-vpcsflag is a comma-separated list of VPCs. You can specify as many VPCs as you like in the list.
Terraform
Use the following Terraform resource to provision a Enterprise Looker (Google Cloud core) instance that uses PSC:
Enter values for the following:
name: a name for your Looker (Google Cloud core) instance; it is not associated with the instance URL.platform_edition: the edition, environment type (production or non-production), and whether this is a trial edition for the instance. Its possible values areLOOKER_CORE_ENTERPRISE_ANNUAL,LOOKER_CORE_EMBED_ANNUAL,LOOKER_NONPROD_CORE_ENTERPRISE_ANNUAL,LOOKER_NONPROD_CORE_EMBED_ANNUAL,LOOKER_CORE_TRIAL_ENTERPRISE, orLOOKER_CORE_TRIAL_EMBED. This example usesLOOKER_CORE_ENTERPRISE_ANNUAL. Editions cannot be changed after instance creation. If you want to change an edition, you can use import and export to move your Looker (Google Cloud core) instance data into a new instance that is configured with a different edition.region: the region in which your Looker (Google Cloud core) instance is hosted. Select the region that matches the region in the subscription contract. This example usesus-central1. Available regions are listed on the Looker (Google Cloud core) locations documentation page.client_idandclient_secret: the OAuth client ID and OAuth secret that you created when you set up your OAuth client. After the instance has been created, enter the instance's URL in the Authorized redirect URIs section of the OAuth client.allowed_vpcs: If you are creating an instance that uses only private connections, list a VPC that will be allowed inbound (ingress) access into the Looker (Google Cloud core) instance. To access the instance from outside the VPC that the instance is located in, you must list at least one VPC. Specify a VPC using one of the following formats:projects/{project}/global/networks/{network}https://www.googleapis.com/compute/v1/projects/{project}/global/networks/{network}
If you are creating an instance that uses hybrid connections, you don't need to set an allowed VPC. You can update and add additional VPC IPs later.
You will also need to update the instance to make outbound connections.
Check the status of the instance
It takes approximately 40-60 minutes for the instance to be created.
console
As the instance is being created, you can view its status on the Instances page within the console. You can also see your instance creation activity by clicking on the notifications icon in the Google Cloud console menu. On the Details page for the instance, its status will show Active once it's created.
gcloud
To check the status, use the gcloud looker instances describe command:
gcloud looker instances describe INSTANCE_NAME --region=REGION
Replace the following:
INSTANCE_NAME: the name of your Looker (Google Cloud core) instance.REGION: the region in which your Looker (Google Cloud core) instance is hosted.
The instance is ready once it reaches the ACTIVE state.
In addition, you can make other changes after instance creation by editing the instance settings.
Configure inbound connections
Once your Looker (Google Cloud core) Private Service Connect instance has been created, you can configure inbound connections.
If you use hybrid connections in the Looker (Google Cloud core) instance, the instance can be accessed over public secure connections. If you chose to use only private connections in the Looker (Google Cloud core) instance, you must allow at least one VPC access to the instance. Complete the following steps to update the VPCs that have access to the instance. More than one VPC can have access to the instance.
console
- On the Instances page, click the name of the instance for which you want to update the VPCs that are allowed inbound access.
- Click Edit.
- Expand the Connections section.
- Navigate to the Configure inbound connections section.
- Click Add Item. Then, select the project in which the VPC is located in the Project field, and select the network from the Network drop-down menu.
- To delete a VPC, click the Delete item trash icon that appears when you hold the pointer over the network.
- Click Save.
gcloud
Use the --psc-allowed-vpcs flag to update the list of VPCs that have authorized inbound access into the instance.
When you update the allowed VPCs, you must specify the entire list that you want to be in effect after your update. For example, suppose VPC ALLOWED_VPC_1 is already allowed, and you want to add VPC ALLOWED_VPC_2. To add VPC ALLOWED_VPC_1 while making sure that VPC