This page describes how to configure VPC Service Controls to secure your data products.
Use VPC Service Controls to prevent data exfiltration and ensure that communication between data products, data assets, and users stays within authorized perimeters.
A data product is a logical grouping of resources (data assets) that can span multiple projects. When your projects belong to different VPC Service Controls perimeters, you must configure ingress and egress rules to allow the Dataplex API to manage resources and metadata.
Before you begin
- Familiarize yourself with the VPC Service Controls.
- Understand the data products concepts.
- Ensure you have the necessary permissions to manage VPC Service Controls perimeters and Knowledge Catalog resources.
Service perimeter rules for creating data products
The following projects define the communication boundaries required to create a data product across service perimeters:
Project R (Caller): the project where the user, service account, or application resides that initiates the create request.
Project E (Data product): the project that hosts the data product resource.
To create a data product in a different project than your caller project, configure the following ingress and egress rules:
| Project | Rule required |
|---|---|
| Project R | Egress rule for Project E |
| Project E | Ingress rule for Project R |
Service perimeter rules for managing data assets
When you manage data assets (such as adding a BigQuery table to a data product), the architecture involves three distinct project roles: