What is a virtual private cloud (VPC)?

Last updated: 10/09/2026

A virtual private cloud (VPC) provides an isolated logical partition within a public cloud environment. Depending on the cloud provider, a VPC can function as a global virtual network spanning all regions or be confined to a single geographic region. This architecture provides the scalable infrastructure of a public cloud provider while maintaining the control and network security of a private network.

How a virtual private cloud works

A VPC uses virtualization to create a logical network overlay on top of a public cloud physical hardware. This overlay allows administrators to define a private network space with custom IP addresses, subnets, and routing rules. A VPC relies on three primary components.

Compute

Compute refers to the virtual machines (VMs) running applications. Within a VPC, compute resources are launched into specific subnets. This placement ensures they are isolated and communicate only according to established network rules.

Storage

VPCs integrate with cloud storage solutions, including object storage for files and block storage for VMs. Placing storage resources within the VPC ensures that data is accessible only from authorized applications within that network.

Networking

Networking defines the virtual network IP address space. The space is divided into subnets, while route tables direct traffic between them. Gateways connect the VPC to the internet or on-premises networks.

VPC features

VPCs include specific features for network topology and security. Google Cloud VPCs provide the following capabilities:

Automatically sets up virtual topology, configures allocating prefix ranges for subnets alongside network policies, and allows CIDR range expansion without downtime.

Captures information about IP traffic flowing to and from virtual machine network interfaces. Logs are aggregated at set intervals and used for network monitoring.

Configures private communication between separate entities or internal groups, avoiding single points of failure and eliminating bandwidth constraints.

Allows a single virtual network to be shared securely across multiple departments or teams in an organization, managing routing and firewalls from a central point.

Enables organizations to move their existing IP address reputation and ranges into the cloud provider to reduce migration friction.

Segments networks with a globally distributed firewall to restrict instance access. VPC firewall records connection events when traffic matches an allow or deny rule, helping you audit network security and troubleshoot traffic.

Forwards traffic between instances within the same network, including across subnets, without requiring external IP addresses.

Troubleshoots existing VPCs by collecting and inspecting large-scale network traffic for application performance monitoring, compliance enforcement, and intrusion detection.

Establishes encrypted IPsec connections to link an existing network to a VPC network.

Provides private access to services like storage, big data, analytics, or machine learning without assigning a public IP address to the service.

Reduces the risk of unauthorized data exfiltration by establishing a secure perimeter to isolate multi-tenant service resources.

Deploys VPC resources across different isolated locations (availability zones) to build fault-tolerant applications.

Internet gateways allow public subnet resources to reach the internet, while network address translation (NAT) gateways allow outbound internet traffic for private subnets while blocking inbound requests.

Dissecting the three-tier VPC architecture

The three-tier architecture separates an application into three logical computing tiers, each isolated in its own subnet.

Presentation tier

The presentation tier hosts web servers that handle incoming user requests. It is typically placed in a public subnet and accessed through an internet gateway.

Application tier

The application tier contains the application's business logic. These servers process requests from the presentation tier and interact with the data tier. It resides in a private subnet and cannot be reached directly from the internet.


Data tier

The data tier stores databases and is placed in a private subnet with strict access rules. Only the application tier is permitted to communicate with the data tier.

VPC versus other networking models

A VPC is a customizable network environment hosted within a shared public cloud. A virtual private network (VPN) is a secure connection established between two networks. A private cloud is fully dedicated hardware and infrastructure for a single organization.

Building a VPC environment with Google Cloud

Building a VPC environment occurs in phases, starting with foundational services and adding advanced capabilities based on workload requirements.

Phase 1: Laying the foundation

  • VPC: Creates the private, isolated network space for resource deployment
  • Compute engine: Provisions virtual machines (VMs) to run code or applications on the network
  • Cloud NGFW: Controls inbound and outbound traffic reaching the VMs with advanced security capabilities
  • Cloud IAM: Defines permissions for creating or modifying the VPC and its associated resources

Phase 2: Building and connecting a real application

  • Cloud load balancing: Distributes incoming traffic across multiple VMs to maintain performance and reliability
  • Cloud VPN: Establishes a secure connection between an on-premises network and the Google Cloud VPC

Phase 3: Scaling with advanced services

  • Google Kubernetes Engine (GKE): Manages and scales applications packaged in containers
  • Cloud run: Runs serverless code while connecting securely to the VPC to access private resources
  • Cloud interconnect: Provides a dedicated, private physical link to the Google network for environments requiring higher reliability than a standard VPN

Phase 4: Gaining insight and adding advanced security

  • VPC flow logs: Provides visibility into network traffic for troubleshooting and security analysis
  • Cloud Monitoring: Observes the health and performance of resources using dashboards and alerts
  • Google Cloud Armor: Supplies a Web Application Firewall (WAF) and DDoS protection for public-facing applications
  • VPC service controls: Creates a protective perimeter around Google Cloud services to help lower the risk of data exfiltration
  • Cloud network insights: Delivers end-to-end cross-cloud observability using active synthetic probing to monitor network performance, validate SLAs, and track digital experience metrics across hybrid and multi-cloud environments

Solve your business challenges with Google Cloud

New customers get $300 in free credits to spend on Google Cloud.
Talk to a Google Cloud sales specialist to discuss your unique challenge in more detail.

Benefits of virtual private cloud

Using a VPC provides several specific operational benefits:

Enhanced security

Administrators define private IP address spaces, create subnets, and configure route tables and network firewalls to protect resources from unauthorized access.

Infrastructure cost reduction

VPCs utilize a public cloud provider hardware, eliminating the need to purchase physical servers or networking gear. Features like bring your own IPs further reduce networking infrastructure costs during migration.

Scalability and flexibility

Administrators can scale resources up or down, adding or removing virtual machines and storage as demands change.

Hybrid cloud integration

Dedicated interconnects or secure VPN connections extend on-premises data centers into the cloud. This enables applications to run across both environments on a single network.

Centralized management

Administrators manage cloud resources, monitor security, and control access from a single console. Shared VPCs allow centralized management of connectivity routes and firewalls across multiple projects.

Take the next step

Start building on Google Cloud with $300 in free credits and 20+ always free products.

  • Produits Google Cloud
  • Parcourez plus de 100 produits. Les nouveaux clients bénéficient de 300 $ de crédits gratuits pour exécuter, tester et déployer des charges de travail. Tous les clients peuvent utiliser plus de 25 produits gratuitement, dans les limites mensuelles spécifiées.
Google Cloud