This page describes how to create a Cloud Data Fusion instance with a private IP address. Creating a private IP instance provides the following features and benefits:
Connections to the Cloud Data Fusion instance are established over a private VPC network in your Google Cloud project. Traffic over this network does not go through the public internet.
The instance can connect to your on-premises resources, such as relational databases, by connecting your on-premises network to the Google Cloud private VPC network using Cloud VPN or Cloud Interconnect. You securely access your on-premises resources, such as databases, over the private network without opening up access to Google Cloud.
VPC peering with Cloud Data Fusion
Cloud Data Fusion uses VPC Network Peering to establish network connectivity to your VPC network. This allows Cloud Data Fusion to access resources on your network through private IP addresses.
Get your Cloud Data Fusion project ID and VPC network name
When you create a VPC peering connection, you'll need your Cloud Data Fusion project ID and VPC network name, which you can get from the Cloud Data Fusion Instance Details page. Take note of these values for use later on in this guide.
Go to the Cloud Data Fusion Instances page in the Cloud Console.
Click the instance name of your private IP instance.
In the Instance details page, get your Project ID and VPC network name. Take note of these values.
- Project ID - This is the portion of the service account that is
- VPC network name - This is composed of the region,
followed by a dash
-, followed by the Cloud Data Fusion instance name. For example: In this example, the Project ID is
r35f61489d3747a5d-tpand the VPC network name is
- Project ID - This is the portion of the service account that is between the
Create a VPC peering connection
Go to the VPC web UI in the Cloud Console.
Click Create connection.
Fill in the Create peering connection form.
- In the Name field, enter a name for your VPC Network Peering connection.
- Under Your VPC network, select the same network you selected when you created your Cloud Data Fusion instance.
- Under Peered VPC network, select In another project.
- In the Project ID field, enter the project ID you noted in the section above.
- In the VPC network name field, enter the VPC network name you noted in the section above.
- Under Exchange custom routes, select Import custom routes and Export custom routes.
- Click Create.
Create the instance
- Go to the Create Data Fusion instance page in the Cloud Console.
- At the bottom of the page, click Advanced Options.
- Check Enable Private IP.
Cloud Data Fusion creates a
google-managed-services-defaultVPC private service connection with an IP address range defined by a CIDR prefix of
- Click Create to create the private IP instance.