Private nodes still need an explicit path to dependencies
Private cluster connectivity is easiest to understand by separating the Kubernetes contract from the Google Cloud implementation. Private nodes have no external IP addresses. Private Google Access covers supported Google services, while Cloud NAT or another controlled egress design is needed for general internet destinations. The Kubernetes objects stay familiar, but GKE supplies controllers, infrastructure and safe defaults around them. This is why a team can move from an on-premises cluster without rewriting every workload, while still needing to redesign networking, identity and operational ownership for the cloud environment.
A useful inspection step is `gcloud container clusters describe shopwave-prod --format='yaml(privateClusterConfig,masterAuthorizedNetworksConfig)'`. Read the output as evidence, not as a ritual: first confirm the desired object exists, then look at status conditions, events and the Google Cloud resource it represents. In production, capture the expected result in a runbook or automated check so an operator can distinguish slow reconciliation from a configuration error.
Production gotcha: A cluster can be healthy while application startup fails because an injected sidecar or package repository lacks an egress path. The safe habit is to verify quotas, regional availability and feature support against current Google Cloud documentation before rollout. Next, Dataplane V2 explains packet processing inside each node.