Skip to content

docs(gcp): document VPC Service Controls requirements for GCP integrations - #25790

Merged
tejaswaroop-nr merged 3 commits into
newrelic:developfrom
nr-sparsi:docs/gcp-vpc-service-controls
Sep 29, 2026
Merged

tejaswaroop-nr merged 3 commits into
newrelic:developfrom
nr-sparsi:docs/gcp-vpc-service-controls

Conversation

@nr-sparsi

Copy link
Copy Markdown
Contributor

Summary

  • Documents the VPC Service Controls (VPC SC) ingress rules required for GCP integrations, for both the Workload Identity Federation and New Relic service account connection methods. This information wasn't documented anywhere previously.
  • WIF requires two additional APIs (sts.googleapis.com, iamcredentials.googleapis.com) beyond the four shared with the service account flow, since WIF uses them for token exchange and short-lived credential generation.
  • Includes the PERMISSION_DENIED ... vpcServiceControlsUniqueIdentifier error signature customers see when the perimeter blocks these calls, so it's searchable.

Context

Raised from a customer support thread where a GCP WIF integration behind a VPC SC perimeter was failing with PERMISSION_DENIED errors. Support (#help-aws-gcp) identified and confirmed the required ingress rules, and the customer separately confirmed neither the WIF nor service account setup docs mention VPC SC at all.

Test plan

  • Verified via web_fetch that neither the current WIF nor service account setup pages mention VPC SC.
  • Docs preview build renders the new sections correctly (Callout, headings, code block).

…tions

Customers with a VPC SC perimeter around their GCP project were hitting
PERMISSION_DENIED errors with no documented way to resolve them, since
neither the WIF nor service account setup guides mentioned VPC SC ingress
rules. Documents the required APIs for each connection method (WIF needs
sts.googleapis.com and iamcredentials.googleapis.com in addition to the
four APIs shared with the service account flow).
@github-actions

Copy link
Copy Markdown
Contributor

Hi @nr-sparsi 👋

Thanks for your pull request! Your PR is in a queue, and a writer will take a look soon. We generally publish small edits within one business day, and larger edits within three days.

Please ensure the propsed changes look good by building it first in your local environment. Refer to this contribution guide to get the site up and running in your local.

If you really require a preview url, reach out to one of the writers and they will generate one for you.

@nr-sparsi
nr-sparsi marked this pull request as draft September 22, 2026 08:34
The V2 docs split moved this guidance to integrations-custom-roles.mdx
and the service account page links to it, but the WIF page never got
the same cross-reference — flagged in the VPC SC support thread.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@nr-sparsi
nr-sparsi marked this pull request as ready for review September 24, 2026 15:19
Domain restriction constraints (iam.allowedPolicyMemberDomains /
iam.managed.allowedPolicyMembers) only affect the service account
connection method, since it adds New Relic's own service account as
an external IAM member. WIF pools/providers are the customer's own
org resources and are already part of their organization principal
set, so the constraint doesn't apply — remove the misleading
cross-reference from the WIF page instead of describing a no-op.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@tejaswaroop-nr

Copy link
Copy Markdown
Contributor

Netlify build fork

@svc-docs-eng-opensource-bot

Copy link
Copy Markdown
Contributor

✅ Your PR has been mirrored to our repository as PR #25887.
Commit: 1269764ad0a30420a75a25e99bf2eb492872ad06 (1269764)
Our workflows will run in the mirrored PR linked above.
🚀 If the build is successful, a Netlify preview will be available shortly at: https://nr-sparsi-docs-gcp-vpc-service-control--docs-website-netlify.netlify.app

@tejaswaroop-nr tejaswaroop-nr left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@tejaswaroop-nr tejaswaroop-nr added content requests related to docs site content from_internal Identifies issues/PRs from Relics (except writers) labels Sep 29, 2026
@tejaswaroop-nr
tejaswaroop-nr merged commit 72fb187 into newrelic:develop Sep 29, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

content requests related to docs site content from_internal Identifies issues/PRs from Relics (except writers)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants