M2 · VPC-native networking
Module 2
10 / 61
2

Plan addresses before workloads arrive

GKE networking is simple only after node, Pod, Service and control-plane paths have enough address space and an explicit trust boundary.

vpc iconnat iconnetpol icon

Where do Pod IPs come from?

VPC-native clusters allocate them from subnet secondary ranges.

How does egress work?

Private nodes use Private Google Access and Cloud NAT or another NAT path.

Who enforces policy?

Dataplane V2 programs routing, load balancing and NetworkPolicy with eBPF.

Where does traffic land?

GKE Layer 7 load balancers send directly to Pod endpoints through NEGs.