Skip to main content

Using Terraform to Create a New VPC and Public Subnet in GCP

Hands-On Lab

 

Photo of

Training Architect

Length

01:15:00

Difficulty

Intermediate

Creating a virtual private network and subnetworks is the foundation of using resources or any infrastructure within GCP. In this hands-on lab, we will learn how to use Terraform to create a VPC and public subnet.

What are Hands-On Labs?

Hands-On Labs are scenario-based learning environments where learners can practice without consequences. Don't compromise a system or waste money on expensive downloads. Practice real-world skills without the real-world risk, no assembly required.

Using Terraform to Create a New VPC and Public Subnet in GCP

Introduction

Creating a virtual private network and subnetworks is the foundation of using resources or any infrastructure within GCP. In this hands-on lab, we will learn how to use Terraform to create a VPC and public subnet.

NOTE: Once you have the lab up and running, give it about five minutes for all the software to properly download in order to complete the lab.

How to Log in to Google Lab Accounts

On the lab page, right-click Open Google Console and select the option to open it in a new private browser window (this option will read differently depending on your browser — e.g., in Chrome, it says "Open Link in Incognito Window"). Then, sign in to Google Cloud Platform using the credentials provided on the lab page.

On the Welcome to your new account screen, review the text, and click Accept. In the "Welcome Cloud Student!" pop-up once you're signed in, check to agree to the terms of service, choose your country of residence, and click Agree and Continue.

Create a Service Account

  1. From Google Cloud console's main navigation, choose IAM & Admin > Service Accounts.
  2. Click Create service account.
  3. Give your service account the name "terraform".
  4. Click Create.
  5. In the roles dropdown, select Project > Owner.
  6. Click Continue and then Done.
  7. Copy the new service account's email address and paste it into a text file, as we'll need it later.
  8. At the top of the Google Cloud console, copy the project name that appears in the top navigation bar next to Google Cloud Platform. Paste it into the same text file — we'll need it later as well.

Log in to the Host Instance and Ensure Terraform Is Installed

  1. From Google Cloud navigation, choose Compute Engine > VM instances.

  2. Click SSH next to terraform-instance. This will open a terminal session in a new browser tab or window, automatically logging us in to the instance.

  3. Use root privileges:

    sudo -i
  4. Change into the root directory:

    cd /
  5. List its contents:

    ll

    Make sure you see both a downloads folder and a Terraform zip file.

  6. Input the path to communicate with Terraform into the /etc/profile file:

    echo "PATH='$PATH:/downloads/'" >> /etc/profile
  7. Run the following in order to be able to call Terraform:

    source /etc/profile
  8. Call Terraform:

    terraform

Create a Service Account Key within the Instance

  1. Allow the SDK to communicate with GCP:

    gcloud auth login
  2. Enter Y at the prompt.

  3. Click on the link in the output.

  4. Select the Cloud Student account.

  5. Click Allow.

  6. Copy the code provided.

  7. Paste the code into the terminal.

  8. Create the service account key, replacing <SERVICE_ACCOUNT_EMAIL> with the one you copied earlier in the lab:

    gcloud iam service-accounts keys create /downloads/instance.json --iam-account <SERVICE_ACCOUNT_EMAIL>

Create a main.tf File to Create VPC and Subnet Configuration, and Execute the Plan

  1. Create a main.tf file:

    vim main.tf
  2. To avoid adding unnecessary spaces and hashes, type :set paste and then i to enter insert mode.

  3. Paste the following configuration, replacing <PROJECT_NAME> with the project name you copied earlier:

    provider "google" {
      version = "3.5.0"
      credentials = file("/downloads/instance.json")
      project = "<PROJECT_NAME>"
      region  = "us-central1"
      zone    = "us-central1-c"
    }
    resource "google_compute_network" "vpc_network" {
      name = "terraform-network"
    }
    resource "google_compute_subnetwork" "public-subnetwork" {
      name          = "terraform-subnetwork"
      ip_cidr_range = "10.2.0.0/16"
      region        = "us-central1"
      network       = google_compute_network.vpc_network.name
      }
  4. Save and exit the file by pressing Escape followed by :wq.

  5. Initialize the configuration file:

    terraform init
  6. Validate the configuration file:

    terraform validate
  7. Create the execution plan:

    terraform plan
  8. Apply the changes:

    terraform apply
  9. Enter yes at the prompt. It will take a few minutes to complete.

  10. In the Google Cloud console, navigate to VPC network > VPC networks. We should see our terraform-network and terraform-subnetwork.

Conclusion

Congratulations on successfully completing this hands-on lab!