Skip to main content
Google Cloud
/
  • English
  • Deutsch
  • Español
  • Español – América Latina
  • Français
  • Indonesia
  • Italiano
  • Português
  • Português – Brasil
  • 中文 – 简体
  • 中文 – 繁體
  • 日本語
  • 한국어
Console Sign in
  • Google Distributed Cloud
Overview Documentation Reference
Contact Us Start free
Google Cloud
  • Docs
    • Overview
    • Documentation
    • Reference
  • Console
  • Contact Us
  • Start free
  • Discover
  • Product overview
  • Documentation audiences
  • Security
  • Release notes
    • 1.14.8
    • 1.14.7
    • 1.14.6
      • 1.14.6 release notes
      • 1.14.6 hotfixes
    • 1.14.5
    • 1.14.4
    • 1.14.3
      • 1.14.3 release notes
      • 1.14.3 hotfixes
    • 1.13.12
    • 1.13.11
    • 1.13.10
    • 1.13.9
    • 1.13.8
    • 1.13.7
    • 1.13.6
    • 1.13.5
    • 1.13.4
    • 1.13.3
    • 1.13.1
    • 1.12.4
    • 1.12.2
    • 1.12.1
    • 1.12.0
    • 1.9.21
    • 1.9.20
    • 1.9.19
    • 1.9.18
    • 1.9.17
    • 1.9.16
    • 1.9.15
    • 1.9.14
    • 1.9.13
    • 1.9.12
    • 1.9.11
    • 1.9.10
    • 1.9.9
    • 1.9.8
    • 1.9.7
    • 1.9.6
    • 1.9.5
    • 1.9.4
    • 1.9.3
    • 1.9.2
    • 1.9.1
    • 1.9.0
  • Glossary
  • Accessibility
  • Feature stages
  • Resource hierarchy and access control
    • Resource hierarchy
    • Design access boundaries
    • Design workload separation
    • Design permissioning setup
  • Manage multi-zone universe
    • Zones in GDC air-gapped
    • Global and zonal resources
    • Data protection
    • Network traffic management
    • Global permissions
    • Manage resources across zones
  • gdcloud Command-Line Interface (CLI)
    • Overview
    • Download
    • Install
    • Manage configurations
    • Manage properties
    • Upgrade
    • Autocompletion
    • View and switch context
    • Authentication
    • Enable accessibility features
  • Provision GDC resources with Terraform
    • Terraform overview
    • Configure Terraform
  • Request support
  • Software support and deprecation policy
  • Administer
  • Control access
    • Connect to an identity provider
    • Sign in
    • Grant and revoke access
    • Predefined role descriptions
    • Role definitions
    • Create a custom role
    • Authenticate with service accounts
    • Secure service account keys
  • Manage projects
    • Overview
    • Create a project
    • Select and view projects
    • Edit a project
    • Delete a project
  • Secure and protect
    • Fetch trust bundles
    • Encryption
      • Encryption at rest
      • Client-side encryption
      • Encryption in transit
    • Manage KMS keys
      • Key management system
      • Rotate a root key
    • Control HSM keys
    • Request threat prevention
    • Manage PKI certs
      • Web TLS certificate configurations
      • Transition to different modes
      • Change the default issuer
      • Reissue PKI web certificates
  • Manage networking
    • Networking overview
    • Manage DNS zones and records
      • About DNS zones and records
      • Prepare IAM permissions
      • Create DNS zones
      • Create DNS records
    • Control data exfiltration
    • Configure project network policies
      • Overview
      • Create intra-project network policies
      • Create cross-project network policies
      • Create organization-external network policies
      • Create allow-all network policies
      • Create network policies for managed services
    • View the virtual network
    • View NAT settings
    • Create organization network policies
    • Manage IP addresses
      • Subnets and IP addresses
      • Planning and architecture
      • Provision internal IP addresses
      • Bring your own external IP addresses
    • Manage flow logs
    • Manage load balancers
      • Overview
      • Configure internal load balancers
      • Configure external load balancers
      • Create global subnets for load balancers
        • About subnets for load balancing
        • Create a global subnet for internal load balancing
        • Create a global subnet for external load balancing
    • Manage outbound traffic from workloads
    • Configure GDC VPN
      • Overview
      • Create a VPN gateway and peer gateway
      • Create a VPN BGP session
      • Create the secret with a PSK
      • Create a VPN tunnel
      • Control egress and ingress traffic
      • Access user VMs
      • Supported IKE ciphers
    • Establish connectivity with interconnects
      • Overview
      • Create an attachment group
      • Create a VLAN attachment
  • Manage Kubernetes clusters
    • Overview
    • Create a Kubernetes cluster
    • Delete a Kubernetes cluster
    • Manage node pools
    • Node isolation
      • Node isolation overview
      • Isolate container workloads
    • Cluster node machines
  • Store data
    • Overview
    • Install the storage CLI
    • Manage buckets
      • Create buckets
      • Delete buckets
      • List and view buckets
      • Set bucket retention periods
      • Manage encrypted buckets
      • Grant and obtain bucket access
      • Create WORM buckets
    • Manage objects
      • Upload and download objects
      • List objects
      • Copy, modify, and move objects
      • Delete objects
      • Set object lifecycle policy
    • Track storage health alerts
    • Transfer data
    • Replicate volumes asynchronously
  • Monitor metrics and logs
    • Overview
    • Prepare IAM permissions
    • Collect and query metrics
      • Monitoring overview
      • Collect metrics
      • Query and view metrics
      • Encrypt metrics
      • Label metrics
      • Create metrics from metrics
      • Create dashboards
    • Collect and query logs
      • Logging overview
      • Collect logs
      • Query and view logs
      • Create metrics from logs
      • Export logs to a SIEM system
      • Secure and restore audit logs
    • Create and manage alerts
      • Alerting overview
      • Create alert rules
      • Configure notification channels
      • Query and view open alerts
      • Manage policies and groups
    • Logs, metrics, and dashboards
      • View component logs
        • Operational logs overview
        • Audit logs overview
        • Audited components
          • List of components
          • ADD
          • BACK
          • BLOCK
          • CSM
          • DNS
          • DS
          • FW
          • GIS
          • HSM
          • IAM
          • KMS
          • KUB
          • LOG and AL
          • MKS
          • MKT
          • MON
          • NTP
          • OBJ
          • OPA
          • OS
          • RM
          • TS
          • VAI
          • VMM
          • VNET
        • Audit log sources
          • List of audit log sources
          • GKE Identity Service
          • Kubernetes
          • Observability audit logger
          • Service Mesh Envoy
          • Syslog audit logs
      • View component metrics
        • Metrics overview
        • ADD
        • BACK
        • DBS
        • KUB
        • MHS
        • OBJ
        • UPG
        • VAIS
        • VMM
      • View component dashboards
        • Dashboards overview
        • Monitor Harbor metrics
        • Monitor Kubernetes cluster metrics
        • Monitor VM metrics
  • Configure organization policies
  • Configure an upgrade
  • Disaster recovery
    • Overview
    • Configure disaster recovery for a cluster
    • Set up backup repository for database services
    • Import backup repository for database services
  • Billing
    • Create and link accounts
    • Access billing reports
    • View invoices
    • Estimate projected costs
    • Track resource consumption
    • Calculate resource usage
    • Query billing metrics
    • Manage billing alerts
  • Migrate VMs
    • Discover and assess VMs
  • Develop
  • Control access to project resources
    • Sign in
    • Grant access to resources
    • Predefined role descriptions
    • Role definitions
    • Manage service accounts
    • Secure service account keys
  • Deploy container workloads
    • Container workloads in GDC
    • Manage stateless workloads
      • Create stateless workloads
      • Inspect stateless workloads
      • Update stateless workloads
      • Scale stateless workloads
      • Delete stateless workloads
    • Manage stateful workloads
      • Create stateful workloads
      • Inspect stateful workloads
      • Update stateful workloads
      • Scale stateful workloads
      • Delete stateful workloads
    • Deploy GPU container workloads
    • Configure container storage
      • Access persistent storage
      • Create volume snapshots
  • Deploy virtual machine workloads
    • VMs overview
    • Prepare IAM permissions
    • Create VMs
      • Create and start a VM
      • Supported VM images
      • Create custom images
      • Create and manage Windows VMs
      • Import virtual disks
      • Manage VM boot disks
        • Create a boot disk
        • Replace a boot disk
    • Connect to VMs
      • Connect to a VM
      • Transfer files
      • Enable IP addresses
      • Set network policies
    • Manage VMs
      • Manage VM lifecycles
      • Start and stop a VM
      • Minimize the VM start time
      • View VM properties
      • Update VM properties
      • View VM machine type
      • View and maintain VM metadata
      • Delete a VM
      • Securely boot a VM
      • Add a disk to a VM
      • Expand VM disks
    • Manage the OS
      • Manage guest environment
      • Manage OS packages
      • Use a startup script on Linux VMs
      • Use a startup script on Windows VMs
    • Monitor VM metrics
  • Store data
    • Overview
    • Install the storage CLI
    • Manage buckets
      • Create buckets
      • Delete buckets
      • List and view buckets
      • Set bucket retention periods
      • Manage encrypted buckets
      • Grant and obtain bucket access
      • Create WORM buckets
    • Manage objects
      • Upload and download objects
      • List objects
      • Copy, modify, and move objects
      • Delete objects
      • Set object lifecycle policy
    • Track storage health alerts
    • Replicate volumes asynchronously
  • Manage databases
    • Create database clusters
    • Start and stop database clusters
    • Configure database extensions
    • Update database cluster attributes
    • List database clusters
    • Configure high availability
    • Build generative AI applications
    • Call models using model endpoints in AlloyDB
    • Delete database clusters
    • Connect to a database cluster
    • Create a user
    • Clone a database cluster
    • Plan maintenance windows
    • Enable cross-project connections
    • Enable external connections
    • Sign and upload a server certificate
    • Export a database cluster
    • Import from a dump file
    • Preserve database clusters before an upgrade
    • Manage advanced migration
    • Observe metrics
    • Distribute Oracle images
    • Enable backup for database services
  • Marketplace services
    • Marketplace overview
    • Life cycle of a Marketplace deployment
    • Dataproc Container for Spark
    • Marketplace shared responsibility model
  • Manage KMS keys
    • Key management system
    • Create and delete keys
    • Encrypt and decrypt data
    • Sign and verify data
    • Import and export keys
  • Certificate Authority Service
    • Certificate Authority Service overview
    • Create a root certificate authority
    • Create a subordinate certificate authority
    • Request a certificate
  • Billing
    • View billing reports
    • Review resource consumption
    • Calculate resource costs
  • Integrate with partner software
    • Deploy GitLab Enterprise Edition
  • Operate
  • Deploy highly available applications
    • High availability for your apps
    • Deploy an HA VM app
    • Deploy an HA container app
    • Kubernetes workloads for HA
  • Respond to storage incidents
  • Back up and restore
    • Overview
    • Clusters
      • Overview
      • Install backup and restore components
      • Add a backup repository
      • Define custom backup and restore logic
        • Customize backup and restore
        • Protected application strategies
      • Plan a set of backups
      • Back up your workloads
      • Plan a set of restores
      • Create a manual restore
        • Overview
        • Create a restore
        • Create a fine-grained restore
      • View and delete a restore
    • Harbor instances
      • Overview
      • Create a backup repository
      • Create a backup plan
      • Manage a backup plan
      • Create a manual backup
      • Manage a backup
      • Create a restore
    • Virtual machines
      • Overview
      • Create a backup repository
      • Manage a backup respository
      • Create a backup plan
      • Back up VMs
      • Back up disks
      • Create a VM from a backup
      • Restore from a snapshot
      • Create scoped and scheduled backups
        • Overview
        • Create a scoped backup plan
        • Create a manual backup
        • Create a restore
        • Create a fine-grained restore
      • Clean up labels after restoring VM-attached disks
  • Create and manage Harbor resources
    • Overview
    • Create Harbor registry instances
    • Create Harbor projects
    • Manage Harbor registry instances
    • Manage container images
      • Configure Docker to trust the Harbor root CA
      • Sign in to Docker and Helm
      • Push an image
      • Pull an image with Docker
    • Configure access control
    • Scan for vulnerabilities
    • Configure tag retention rules
  • Maintain Kubernetes clusters
  • Wipe out KMS keys
  • Supportability
  • Deploy a container app
  • VM workload deployment overview
  • Implement Vertex AI
  • Overview
  • Get started
    • Prepare IAM permissions
    • Set up a project
    • Enable APIs
    • View service status and endpoints
    • Install client libraries
    • Authenticate API requests
  • Generative AI
    • Generative AI overview
    • Available models
    • Text embeddings
      • Text embeddings overview
      • Get text embeddings
      • Choose a task type
      • Supported text embedding languages
  • Online Prediction
    • Learn about online predictions
    • Create the prediction cluster
    • Export model artifacts
    • Deploy a model
    • Format your prediction requests
    • Get an online prediction
    • Delete a model
  • Optical Character Recognition
    • Learn about character recognition features
    • Set up a character recognition project
    • Detect text in images
    • Detect text in files
    • Supported languages
  • Speech-to-Text
    • Learn about speech recognition features
    • Set up a speech recognition project
    • Transcribe audio
    • Supported languages
  • Translation
    • Learn about translation features
    • Set up a translation project
    • Translate text
    • Translate documents
    • Supported languages
    • Define terms to translate
      • Create and use a glossary
      • Identify glossary stopwords
  • Vertex AI Workbench
    • Learn about Vertex AI Workbench
    • Control access
    • Manage notebooks
    • Create a backup and restore data
  • View Vertex AI logs and metrics
  • Home
  • Documentation
  • Distributed, hybrid, and multicloud
  • Google Distributed Cloud
  • Google Distributed Cloud air-gapped

Request threat prevention

To request threat prevention to manage traffic on an organization and enable Intrusion Detection and Prevention System (IDPS) services for customer workloads, contact your Infrastructure Operator (IO).

Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2025-10-16 UTC.

  • Why Google

    • Choosing Google Cloud
    • Trust and security
    • Modern Infrastructure Cloud
    • Multicloud
    • Global infrastructure
    • Customers and case studies
    • Analyst reports
    • Whitepapers
  • Products and pricing

    • See all products
    • See all solutions
    • Google Cloud for Startups
    • Google Cloud Marketplace
    • Google Cloud pricing
    • Contact sales
  • Support

    • Community forums
    • Support
    • Release Notes
    • System status
  • Resources

    • GitHub
    • Getting Started with Google Cloud
    • Google Cloud documentation
    • Code samples
    • Cloud Architecture Center
    • Training and Certification
    • Developer Center
  • Engage

    • Blog
    • Events
    • X (Twitter)
    • Google Cloud on YouTube
    • Google Cloud Tech on YouTube
    • Become a Partner
    • Google Cloud Affiliate Program
    • Press Corner
  • About Google
  • Privacy
  • Site terms
  • Google Cloud terms
  • Manage cookies
  • Our third decade of climate action: join us
  • Sign up for the Google Cloud newsletter Subscribe
  • English
  • Deutsch
  • Español
  • Español – América Latina
  • Français
  • Indonesia
  • Italiano
  • Português
  • Português – Brasil
  • 中文 – 简体
  • 中文 – 繁體
  • 日本語
  • 한국어