←Marketplace

Private Service Consumer

Description

Connects this environment to a Private Service Publisher, so installations here can call services in the publisher's environment over a private link.

The link runs over the cloud's private network (Private Service Connect on GCP, PrivateLink on AWS) to the internal gateway of the publisher's environment. Installations here call a service at the same internal URL it has there, like https://<name>.<publisherDomain>.

Setup

  1. Get the publisherId and publisherDomain outputs of the Private Service Publisher you want to reach. It must be on the same cloud as this environment, and on GCP in the same region. If this environment is in another GCP project or AWS account, or in another AWS region, the publisher must allow it first.
  2. Install this blueprint with those two values, copied exactly.
  3. Check linkState. It shows ACCEPTED on GCP or available on AWS once the publisher accepts the connection.

Each install connects to one publisher. To reach more, install this once per publisher.

Call a service

  • Use the service's internal URL from the publisher's environment. Names under publisherDomain resolve to the link inside this environment, and the certificate is publicly trusted, so clients need no extra setup.
  • Every service with an internal Route in the publisher's environment is reachable.
  • The link carries HTTP, including gRPC. It doesn't carry other protocols, like direct database connections.
  • Calls can fail for a few minutes after the link first connects, while DNS updates.

What to expect

  • If linkState stays PENDING on GCP, or the install can't find the publisher on AWS, the publisher doesn't allow this environment's project, account, or region yet.
  • Uninstall this before the publisher is uninstalled or stops allowing this environment. On AWS, updating or uninstalling this fails until the publisher allows this environment again.

Configuration Inputs

This blueprint accepts 2 configurable inputs to customize the installation for your environment.

publisherIdstring

The `publisherId` output of the Private Service Publisher to connect to.

publisherDomainstring

The `publisherDomain` output of the same publisher.

Outputs

This blueprint exposes 2 outputs that other services can reference.

consumerIdstring

Endpoint this environment connects through.

linkStatestring

Whether the publisher accepted the connection.