Route traffic from Cloud Service Mesh workloads to Compute Engine VM
This page shows you how to securely route network traffic from Cloud Service Mesh workloads on GKE to Compute Engine VM fronted by a BackendService.
Note that when routing traffic from GKE to a Compute Engine VM, it is not required to have the Compute Engine VM or BackendService join the Cloud Service Mesh. However, the Compute Engine VM and BackendService must be in the same project as the Cloud Service Mesh GKE cluster. This limitation exists while this feature is available in public preview. MTLS isn't supported for Compute Engine VMs
Before you begin
The following sections assume that you have:
- A GKE cluster with Cloud Service Mesh enabled.
- Deployed a Compute Engine VM that is fronted by a BackendService.
Alternatively, you can run the following commands to deploy a sample Compute Engine VM fronted by a BackendService.
Deploy a sample Compute Engine VM and BackendService:
gcloud compute instance-templates create td-httpd-vm-template \ --scopes=https://www.googleapis.com/auth/cloud-platform \ --tags=http-td-server \ --image-family=debian-11 \ --image-project=debian-cloud \ --metadata=startup-script="#! /bin/bash sudo apt-get update -y sudo apt-get install apache2 -y sudo service apache2 restart echo ''\`
$(/bin/hostname)\`'