GCP outbound network access destinations
If you have limited outbound internet access (for example, due to using a firewall or proxy), the following tables describe which specific outbound destinations must be available to register a Cloudera environment.
Cloudera recommends hostname-based policies because some destination services do not have static IP addresses. IP address details in CIDR notation have been provided where static IPs are in use.
The following tables include general destinations and GCP-specific destinations.
| Description/Usage | Cloudera service | Destination | Protocol and Authentication | IP Protocol/Port | Comments |
|---|---|---|---|---|---|
|
Control Plane API |
All services |
US-based Control Plane:
EU-based Control Plane:
AP-based Control Plane:
|
HTTPS with Cloudera-generated access key. |
TCP/443 |
Cloudera Control Plane REST API. |
|
Cloudera CCMv2 Persistent Control Plane connection |
All services |
US-based Control Plane:
EU-based Control Plane:
AP-based Control Plane:
|
HTTPS with mutual authentication. |
TCP/443 |
Multiple long-lived/persistent connections. |
|
Cloudera Databus Telemetry, billing, and metering data |
All services |
US-based Control Plane:
EU-based Control Plane:
AP-based Control Plane:
|
HTTPS with Cloudera-generated access key for dbus. HTTPS for S3. |
TCP/443 |
Regular interval for telemetry, billing, metering services, and used for Cloudera Observability if enabled. Larger payloads are sent to a Cloudera-managed S3 bucket. |
|
Cloudera Observability Metrics System metrics collection |
All services |
US-based Control Plane:
EU-based Control Plane:
AP-based Control Plane:
|
HTTPS |
TCP/443 |
New as of March 2024 |
|
Cloudera Manager parcels Software distribution |
All services |
archive.cloudera.com |
HTTPS |
TCP/443 |
Cloudera's public software repository. CDN backed service; IP range not predictable. |
|
RPMs Cloudera RPMs for workload agents |
All services |
cloudera-service-delivery-cache.s3.amazonaws.com |
HTTPS |
TPC/443 |
RPM packages for some workload components |
|
APIs |
All services |
storage.googleapis.com iamcredentials.googleapis.com |
HTTPS |
TCP/443 |
In addition to adding the listed destinations, you need to configure Private Service Connect. Private Service Connect lets you send traffic to Google APIs using a Private Service Connect endpoint that is private to your VPC network. To configure Private Service Connect, see Configuring Private Service Connect. note This is mandatory. If you don't configure this option, environment registration will fail. |
