Supported products and limitations

This page contains a table of products and services that are supported by VPC Service Controls, as well as a list of known limitations with certain services and interfaces.

List all supported services

To retrieve the complete list of all VPC Service Controls supported products and services, run the following command:

gcloud access-context-manager supported-services list

You get a response with a list of products and services.

NAME                 TITLE             SERVICE_SUPPORT_STAGE   AVAILABLE_ON_RESTRICTED_VIP      KNOWN_LIMITATIONS
SERVICE_ADDRESS      SERVICE_NAME      SERVICE_STATUS          RESTRICTED_VIP_STATUS            LIMITATIONS_STATUS
.
.
.

This response includes the following values:

Value Description
SERVICE_ADDRESS Service name of the product or service. For example, aiplatform.googleapis.com.
SERVICE_NAME Name of the product or service. For example, Gemini Enterprise Agent Platform API.
SERVICE_STATUS The status of the service integration with VPC Service Controls. The following are the possible values:
  • GA: The service integration is fully supported by VPC Service Controls perimeters.
  • PREVIEW: The service integration is ready for broader testing and use but is not fully supported for production environments by VPC Service Controls perimeters.
  • DEPRECATED: The service integration is scheduled to be shut down and removed.
RESTRICTED_VIP_STATUS Specifies if the service integration with VPC Service Controls is supported by the restricted VIP. The following are the possible values:
  • TRUE: The service integration is fully supported by the restricted VIP and can be protected by VPC Service Controls perimeters.
  • FALSE: The service integration is not supported by the restricted VIP.
For a complete list of the services available on the restricted VIP, see Services supported by the restricted VIP.
LIMITATIONS_STATUS Specifies if the service integration with VPC Service Controls has any limitations. The following are the possible values:
  • TRUE: The service integration with VPC Service Controls has known limitations. You can check the corresponding entry for the service in the Supported products table to learn more about these limitations.
  • FALSE: The service integration with VPC Service Controls has no known limitations.

List supported methods for a service

To retrieve the list of methods and permissions supported by VPC Service Controls for a service, run the following command:

gcloud access-context-manager supported-services describe SERVICE_ADDRESS

Replace SERVICE_ADDRESS with the service name of the product or service. For example, aiplatform.googleapis.com.

You get a response with a list of methods and permissions.

availableOnRestrictedVip: RESTRICTED_VIP_STATUS
knownLimitations: LIMITATIONS_STATUS
name: SERVICE_ADDRESS
serviceSupportStage: SERVICE_STATUS
supportedMethods:
METHODS_LIST
.
.
.
title: SERVICE_NAME

In this response, METHODS_LIST lists all the methods and permissions supported by VPC Service Controls for the specified service. For a complete list of all the supported service methods and permissions, see Supported service method restrictions.

For information about the service methods that VPC Service Controls can't control, see Service method exceptions.

Supported products

VPC Service Controls supports the following products:

Supported products Description

Infrastructure Manager

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name config.googleapis.com
Details

For more information about Infrastructure Manager, refer to the product documentation.

Limitations

To use Infrastructure Manager in a perimeter:

  • You must use a Cloud Build private pool for the worker pool used by Infrastructure Manager. You need to use the Infra Manager-maintained Terraform provider for Google Cloud if you don't want to enable public internet calls to download the HashiCorp-maintained Terraform providers and configurations. You cannot use the default Cloud Build worker pool.
  • The following must be in the same perimeter:
    • The service account that Infrastructure Manager uses.
    • The Cloud Build worker pool that Infrastructure Manager uses.
    • The storage bucket that Infrastructure Manager uses. You can use the default storage bucket.

App Design Center

Status Preview. The integration of this product with VPC Service Controls is in Preview and is ready for broader testing and use, but is not fully supported for production environments.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name designcenter.googleapis.com
Details

The API for App Design Center can be protected by VPC Service Controls and the product can be used normally inside service perimeters.

For more information about App Design Center, refer to the product documentation.

Limitations

To use App Design Center in a perimeter:

  • You must use a Cloud Build private pool for the worker pool used by App Design Center. Enable public internet calls to download HashiCorp-maintained Terraform providers and configurations. You cannot use the default Cloud Build worker pool.
  • The following resources must be restricted in the same perimeter:
    • The management project where you set up App Design Center.
    • The Cloud Build worker pool that App Design Center uses.

For more information, see Deploy resources in a secure perimeter.

Workload Identity API

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name workloadidentity.googleapis.com
Details

The Workload Identity API lets you trigger the creation of service agents for a specified service in a specified project, folder, or organization. When you restrict the Workload Identity API with a perimeter, you can't trigger service agent creation for projects inside the perimeter. This is true regardless of the service specified in the request.

VPC Service Controls doesn't support adding folder-level or organization-level resources into a service perimeter. As a result, you can't use a perimeter to prevent users from triggering the creation of service agents for folders or organizations.

For more information about Workload Identity API, refer to the product documentation.

Limitations

The Workload Identity API integration with VPC Service Controls has no known limitations.

Workload Manager

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name workloadmanager.googleapis.com
Details

To use Workload Manager in a VPC Service Controls perimeter:

  • You must use a Cloud Build private worker pool for your deployment environment in Workload Manager. You cannot use the default Cloud Build worker pool.
  • The Cloud Build private pool must have public internet calls enabled to download the Terraform configuration.

For more information, see Use a Cloud Build private worker pool in the Workload Manager documentation.

For more information about Workload Manager, refer to the product documentation.

Limitations

You must ensure that the following resources are in the same VPC Service Controls service perimeter:

  • Workload Manager service account.
  • Cloud Build private worker pool.
  • The Cloud Storage bucket that Workload Manager uses for deployment.

Google Cloud NetApp Volumes

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name netapp.googleapis.com
Details

The API for Google Cloud NetApp Volumes can be protected by VPC Service Controls and the product can be used normally inside service perimeters.

For more information about Google Cloud NetApp Volumes, refer to the product documentation.

Limitations

VPC Service Controls doesn't cover dataplane paths such as Network File System (NFS) and Server Message Block (SMB) reads and writes. Additionally, if your host and service projects are configured in different perimeters, you can experience a break in the implementation of Google Cloud services.

Google Cloud Search

Status GA
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name cloudsearch.googleapis.com
Details

Google Cloud Search supports Virtual Private Cloud Security Controls (VPC Service Controls) to enhance the security of your data. VPC Service Controls allows you to define a security perimeter around Google Cloud Platform resources to constrain data and help mitigate data exfiltration risks.

For more information about Google Cloud Search, refer to the product documentation.

Limitations

Because Cloud Search resources are not stored in a Google Cloud project, you must update the Cloud Search customer settings with the VPC perimeter protected project. The VPC project acts as a virtual project container for all your Cloud Search resources. Without building this mapping, VPC Service Controls won't work for the Cloud Search API.

For complete steps to enable VPC Service Controls with Google Cloud Search, refer to Enhance security for Google Cloud Search.

Cluster Director

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name hypercomputecluster.googleapis.com
Details

VPC Service Controls helps protect the Cluster Director API, letting you use Cluster Director inside service perimeters.

For more information about Cluster Director, refer to the product documentation.

Limitations

Connectivity Tests

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name networkmanagement.googleapis.com
Details

The API for Connectivity Tests can be protected by VPC Service Controls and the product can be used normally inside service perimeters.

For more information about Connectivity Tests, refer to the product documentation.

Limitations

The Connectivity Tests integration with VPC Service Controls has no known limitations.

AI Platform Prediction

Status
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name ml.googleapis.com
Details

VPC Service Controls supports online prediction, but not batch prediction.

For more information about AI Platform Prediction, refer to the product documentation.

Limitations
  • To fully protect AI Platform Prediction, add all of the following APIs to the service perimeter:

    • AI Platform Training and Prediction API (ml.googleapis.com)
    • Pub/Sub API (pubsub.googleapis.com)
    • Cloud Storage API (storage.googleapis.com)
    • Google Kubernetes Engine API (container.googleapis.com)
    • Container Registry API (containerregistry.googleapis.com)
    • Cloud Logging API (logging.googleapis.com)

    Read more about setting up VPC Service Controls for AI Platform Prediction.

  • Batch prediction is not supported when you use AI Platform Prediction inside a service perimeter.

  • AI Platform Prediction and AI Platform Training both use the AI Platform Training and Prediction API, so you must configure VPC Service Controls for both products. Read more about setting up VPC Service Controls for AI Platform Training.

AI Platform Training

Status
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name ml.googleapis.com
Details

The API for AI Platform Training can be protected by VPC Service Controls and the product can be used normally inside service perimeters.

For more information about AI Platform Training, refer to the product documentation.

Limitations
  • To fully protect your AI Platform Training training jobs, add all of the following APIs to the service perimeter:

    • AI Platform Training and Prediction API (ml.googleapis.com)
    • Pub/Sub API (pubsub.googleapis.com)
    • Cloud Storage API (storage.googleapis.com)
    • Google Kubernetes Engine API (container.googleapis.com)
    • Container Registry API (containerregistry.googleapis.com)
    • Cloud Logging API (logging.googleapis.com)

    Read more about setting up VPC Service Controls for AI Platform Training.

  • Training with TPUs is not supported when you use AI Platform Training inside a service perimeter.

  • AI Platform Training and AI Platform Prediction both use the AI Platform Training and Prediction API, so you must configure VPC Service Controls for both products. Read more about setting up VPC Service Controls for AI Platform Prediction.

AlloyDB for PostgreSQL

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name alloydb.googleapis.com
Details

VPC Service Controls perimeters protect the AlloyDB API.

For more information about AlloyDB for PostgreSQL, refer to the product documentation.

Limitations

  • Service perimeters protect only the AlloyDB for PostgreSQL Admin API. They don't protect IP-based data access to underlying databases (such as AlloyDB for PostgreSQL instances). To restrict public IP access on AlloyDB for PostgreSQL instances, use an organization policy constraint.
  • Before you configure VPC Service Controls for AlloyDB for PostgreSQL, enable the Service Networking API.
  • When you use AlloyDB for PostgreSQL with Shared VPC and VPC Service Controls, the host project and service project must be in the same VPC Service Controls service perimeter.

Agent Runtime on Gemini Enterprise Agent Platform

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name aiplatform.googleapis.com
Details

The API for Agent Runtime on Gemini Enterprise Agent Platform can be protected by VPC Service Controls and the product can be used normally inside service perimeters.

For more information about Agent Runtime on Gemini Enterprise Agent Platform, refer to the product documentation.

Limitations

For more information about limitations, see limitations in the Agent Platform documentation.

Agent Platform Workbench

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name notebooks.googleapis.com
Details

The API for Agent Platform Workbench can be protected by VPC Service Controls and the product can be used normally inside service perimeters.

For more information about Agent Platform Workbench, refer to the product documentation.

Limitations

For information about the limitations of using Agent Platform Workbench with VPC Service Controls, see service perimeters for Agent Platform Workbench instances, service perimeters for user-managed notebooks (deprecated), and service perimeters for managed notebooks (deprecated).

Gemini Enterprise Agent Platform

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name aiplatform.googleapis.com
Details

The API for Agent Platform can be protected by VPC Service Controls and the product can be used normally inside service perimeters.

Colab Enterprise is a part of Gemini Enterprise Agent Platform. See Colab Enterprise.

For more information about Gemini Enterprise Agent Platform, refer to the product documentation.

Limitations

For more information about limitations, see limitations in the Agent Platform documentation.

Gemini Enterprise Agent Platform Vision

Status Preview. The integration of this product with VPC Service Controls is in Preview and is ready for broader testing and use, but is not fully supported for production environments.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name visionai.googleapis.com
Details

The API for Gemini Enterprise Agent Platform Vision can be protected by VPC Service Controls and the product can be used normally inside service perimeters.

For more information about Gemini Enterprise Agent Platform Vision, refer to the product documentation.

Limitations
When constraints/visionai.disablePublicEndpoint is on, we disable the cluster's public endpoint. Users must manually connect to the PSC target and access the service from the private network. You can get the PSC target from the cluster resource.

Colab Enterprise

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name aiplatform.googleapis.com
Details

The API for Colab Enterprise can be protected by VPC Service Controls and the product can be used normally inside service perimeters.

Colab Enterprise is a part of Gemini Enterprise Agent Platform. See Agent Platform.

Colab Enterprise uses Dataform for storing notebooks. See Dataform.

For more information about Colab Enterprise, refer to the product documentation.

Limitations

For information about limitations, see Known limitations in the Colab Enterprise documentation.

Agent Registry

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name agentregistry.googleapis.com
Details

Agent Registry is a centralized catalog for discovering and registering agents and MCP servers.

For more information about Agent Registry, refer to the product documentation.

Limitations

Make sure that your project for Agent Registry and the enabled APIs are included in your VPC Service Controls service perimeter.

Apigee and Apigee hybrid

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name apigee.googleapis.com,
apigeeconnect.googleapis.com
Details

The API for Apigee and Apigee hybrid can be protected by VPC Service Controls and the product can be used normally inside service perimeters.

For more information about Apigee and Apigee hybrid, refer to the product documentation.

Limitations

Apigee integrations with VPC Service Controls have the following limitations:

  • Integrated portals require additional steps to configure.
  • You must deploy Drupal portals within the service perimeter.

Apigee API hub

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name apihub.googleapis.com
Details

The API for Apigee API hub can be protected by VPC Service Controls and the product can be used normally inside service perimeters.

For more information about Apigee API hub, refer to the product documentation.

Limitations
All Apigee runtime projects associated with an API hub instance must reside within the same VPC Service Controls service perimeter as the API hub host project.

BigQuery sharing

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name analyticshub.googleapis.com
Details VPC Service Controls protects data exchanges and listings. To protect shared and linked datasets using a service perimeter, use the BigQuery API. For more information, see sharing VPC Service Controls rules.

For more information about BigQuery sharing, refer to the product documentation.

Limitations
BigQuery sharing doesn't support method-based rules and you must allow all methods. For more information, see sharing VPC Service Controls rules limitations.

Cloud Service Mesh

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name meshca.googleapis.com,
meshconfig.googleapis.com,
trafficdirector.googleapis.com,
networkservices.googleapis.com,
networksecurity.googleapis.com
Details

The API for Cloud Service Mesh can be protected by VPC Service Controls, and the product can be used normally inside service perimeters.

You can use mesh.googleapis.com to enable the required APIs for Cloud Service Mesh. You don't need to restrict mesh.googleapis.com in your perimeter as it doesn't expose any APIs.

For more information about Cloud Service Mesh, refer to the product documentation.

Limitations

The Cloud Service Mesh integration with VPC Service Controls has no known limitations.

Artifact Registry

Status GA. This product integration is fully supported by VPC Service Controls.
Protect with perimeters? Yes. You can configure your perimeters to protect this service.
Service name artifactregistry.googleapis.com
Details

In addition to protecting the Artifact Registry API, Artifact Registry can be used inside service perimeters with GKE and Compute Engine.

For more information about Artifact Registry, refer to the product documentation.

Limitations
  • For Artifact Registry repositories that use the pkg.dev domain, you must configure DNS for *.pkg.dev to map to either private.googleapis.com or restricted.googleapis.com. For more information, see Securing repositories in a service perimeter.
  • In addition to the artifacts inside a perimeter that are available to Artifact Registry, the following read-only repositories are available to all projects regardless of service perimeters:

    • gcr.io/anthos-baremetal-release
    • gcr.io/asci-toolchain
    • gcr.io/cloud-airflow-releaser
    • gcr.io/cloud-builders
    • gcr.io/cloud-dataflow
    • gcr.io/cloud-ingest
    • gcr.io/cloud-marketplace
    • gcr.io/cloud-ssa