Cloud Intelligence™Cloud Intelligence™

Announcement

This page is also available in Deutsch, Español, Français, Italiano, 日本語, and Português.

Fixed outbound IPs and documented VPC Service Controls support

Cloud Intelligence™ now publishes fixed outbound IPs for any cloud and a documented VPC Service Controls configuration for Google Cloud.

By Vadim Solovey

·

Shipped by

Laura Seidler

Every security review of a third-party platform hits the same two questions. What IP addresses do you connect from, and how do we let you through our perimeter without loosening it. Until now, Cloud Intelligence™ had no published answer to the first, and the second meant guesswork: VPC Service Controls blocks cross-boundary API calls by design, so features like BigQuery Intelligence would fail at the perimeter with violation entries in the audit log and a support thread to untangle them.

Both questions now have documented answers, on a single Network access page.

A fixed outbound IP list, for every cloud

This is the first time we publish one, and there's a reason it took a while. Cloud Intelligence™ serves thousands of customers in more than 75 countries, and it's a large distributed system. Pinning every outbound connection to ten fixed addresses, routed globally, and keeping them fixed as the platform grows, took real engineering work.

The list applies regardless of where you run. If you restrict inbound access by source IP, with AWS security groups, Azure NSG rules, firewall rules, or API access lists, you now have the exact addresses to allowlist.

VPC Service Controls support, for Google Cloud

If you protect your Google Cloud environment with a service perimeter, the Network access page has the tested configuration: one access level covering both Cloud Intelligence™ VPC networks, plus two directional policies depending on what your perimeter restricts. An egress rule for the IAM Service Account Credentials API, and an ingress rule for the org-level log sink writer if you restrict BigQuery APIs. The access level bounds everything, so only requests arriving from Cloud Intelligence™ networks can match the rules, and IAM still controls who can generate tokens for each service account.

Get started

  1. Allowlist the outbound IP addresses from the Network access page in your firewall or API access lists.
  2. On Google Cloud with VPC Service Controls, follow the same page to configure your access level and directional policies.
  3. Set up BigQuery Intelligence and let it run against your real workloads.

This is available to all customers today.

PerfectScale™ for Kubernetes

Ready to optimize?

Get your free Kubernetes savings analysis