Repository navigation
docs(gcp): document VPC Service Controls requirements for GCP integrations - #25790
Conversation
…tions Customers with a VPC SC perimeter around their GCP project were hitting PERMISSION_DENIED errors with no documented way to resolve them, since neither the WIF nor service account setup guides mentioned VPC SC ingress rules. Documents the required APIs for each connection method (WIF needs sts.googleapis.com and iamcredentials.googleapis.com in addition to the four APIs shared with the service account flow).
|
Hi @nr-sparsi 👋 Thanks for your pull request! Your PR is in a queue, and a writer will take a look soon. We generally publish small edits within one business day, and larger edits within three days. Please ensure the propsed changes look good by building it first in your local environment. Refer to this contribution guide to get the site up and running in your local. If you really require a preview url, reach out to one of the writers and they will generate one for you. |
The V2 docs split moved this guidance to integrations-custom-roles.mdx and the service account page links to it, but the WIF page never got the same cross-reference — flagged in the VPC SC support thread. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Domain restriction constraints (iam.allowedPolicyMemberDomains / iam.managed.allowedPolicyMembers) only affect the service account connection method, since it adds New Relic's own service account as an external IAM member. WIF pools/providers are the customer's own org resources and are already part of their organization principal set, so the constraint doesn't apply — remove the misleading cross-reference from the WIF page instead of describing a no-op. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Netlify build fork |
|
✅ Your PR has been mirrored to our repository as PR #25887. |
Summary
sts.googleapis.com,iamcredentials.googleapis.com) beyond the four shared with the service account flow, since WIF uses them for token exchange and short-lived credential generation.PERMISSION_DENIED ... vpcServiceControlsUniqueIdentifiererror signature customers see when the perimeter blocks these calls, so it's searchable.Context
Raised from a customer support thread where a GCP WIF integration behind a VPC SC perimeter was failing with
PERMISSION_DENIEDerrors. Support (#help-aws-gcp) identified and confirmed the required ingress rules, and the customer separately confirmed neither the WIF nor service account setup docs mention VPC SC at all.Test plan
web_fetchthat neither the current WIF nor service account setup pages mention VPC SC.