Slide 30 of 38Cloud Console SignalOpen full tutorial

Firewall rules, tags, and Cloud NAT

Firewall policies at the org level override project-level rules just like org policies do, service-account targeting beats network tags, and Cloud NAT is what makes no-public-IP still functional.

Raw HTML

Speaker notes

  • Cloud NGFW covers both basic VPC firewall rules and hierarchical firewall policies that can be applied at the organization or folder level — firewall policies at a higher level take precedence over project-level rules, the network-layer equivalent of org policies overriding project configuration.
  • Firewall rules target instances by network tag or by service account — prefer service account targeting wherever both would work, since a network tag is just a string anyone with edit access can add or remove, while a service account binding inherits the same IAM rigor as everything else in this course.
  • Cloud NAT provides outbound-only internet access for resources with no public IP — without it, every --no-address instance following the org policy from earlier couldn't even pull an OS package update. NAT is what makes 'no public IP' and 'still functional' compatible, with no inbound path ever exposed back to the instance.

Deck map

01
GCP foundations in one line
02
How the ACE exam maps to this course
03
GCP's geography and the project as the unit of isolation
04
Organization, folders, and projects
05
Org policies and how inheritance works
06
Labels, network tags, and resource manager tags
07
Billing accounts, budgets, and cost control
08
gcloud CLI, Cloud Shell, and client libraries
09
Terraform on GCP and the end of Deployment Manager
10
Gemini CLI, Cloud Assist, and Application Design Center
11
Principals, roles, bindings, and policies
12
Primitive, predefined, custom roles, and IAM conditions
13
Service accounts, keys, and impersonation
14
Workload Identity Federation
15
Break-glass access and IAM auditing
16
Choosing a machine family: E2, N4, C4
17
Disks, OS Login, and VM Manager
18
Spot VMs and managed instance groups
19
Autoscaling policies, health checks, GPUs and TPUs
20
GKE Autopilot vs Standard vs the 2026 hybrid option
21
Node pools and pod autoscaling
22
Cloud Run revisions, traffic splitting, and functions
23
Choosing between GKE, Cloud Run, and Compute Engine
24
Cloud Storage classes and lifecycle management
25
Choosing a managed database
26
The managed database lineup
27
Connection pooling, read replicas, and Pub/Sub
28
Backup, regional failover, and CMEK
29
VPC networks, subnets, and Shared VPC
30
Firewall rules, tags, and Cloud NAT
31
Load balancers, Cloud DNS, and Cloud CDN
32
VPN, Interconnect, and private access
33
How a request actually reaches shipment-api
34
Cloud Monitoring: metrics, dashboards, alerts
35
Cloud Logging: router, buckets, and audit logs
36
Trace, Profiler, Error Reporting, and Managed Prometheus
37
How the five Cloud Operations products fit together
38
Readiness checklist