Use VPC Service Controls with data products

This page describes how to configure VPC Service Controls to secure your data products.

Use VPC Service Controls to prevent data exfiltration and ensure that communication between data products, data assets, and users stays within authorized perimeters.

A data product is a logical grouping of resources (data assets) that can span multiple projects. When your projects belong to different VPC Service Controls perimeters, you must configure ingress and egress rules to allow the Dataplex API to manage resources and metadata.

Before you begin

Service perimeter rules for creating data products

The following projects define the communication boundaries required to create a data product across service perimeters:

  • Project R (Caller): the project where the user, service account, or application resides that initiates the create request.

  • Project E (Data product): the project that hosts the data product resource.

An illustration showing two service perimeters. Perimeter 1 contains
  Project R (Caller) and perimeter 2 contains Project E (Data product).

To create a data product in a different project than your caller project, configure the following ingress and egress rules:

Project Rule required
Project R Egress rule for Project E
Project E Ingress rule for Project R

Service perimeter rules for managing data assets

When you manage data assets (such as adding a BigQuery table to a data product), the architecture involves three distinct project roles: