Skip to main content
resource · gcp

VPC Subnet

schedulable
no
category
networking-services

Does ZopNight manage VPC Subnet?

A VPC subnet is a regional IP range and carries no charge of its own, but it decides which region cost-bearing VMs land in and how their egress is billed. ZopNight inventories every subnet via Cloud Asset Inventory and records its network, CIDR range (`ipCidrRange`), secondary range count, purpose and Private Google Access flag.

Rules that fire on VPC Subnet

no live rules

No active rule family targets VPC Subnet today. Rules that used to are retired, and retired rules publish no pages and fire no findings. Scheduling and permissions coverage are unaffected.

Browse every live recommendation for this platform →

A subnet is a regional IP range inside a VPC where instances and services get their addresses. Subnets are free but determine where cost-bearing resources can live and how traffic egress is charged.

A free range that decides where paid resources live

No meter runs on a subnet itself. Google charges nothing for creating one, however large its CIDR block. The cost consequences are all indirect, and they are real. A subnet pins its member resources to one region, so the subnet a team picks on day one determines which regional rates every VM, load balancer, and Cloud SQL instance in it pays from then on. Traffic between resources also inherits its price from subnet placement: two VMs in the same zone talk for free over internal IPs, while the same conversation across regions bills as inter-region egress. In that sense the subnet is the cheapest object in the project and one of the most expensive decisions.

What ZopNight records for each subnet

ZopNight discovers subnets through Cloud Asset Inventory and records each one’s network, primary CIDR range, secondary range count, purpose and Private Google Access flag; the same record is used to validate VPC choices when provisioning. Because a subnet has no lifecycle worth automating (there is nothing to stop and nothing metered to pause), it is discovery-only: no schedule ever touches one.

Hygiene findings that start at the subnet layer

Three patterns are worth a periodic look. Sprawl: dozens of near-empty subnets accumulated from abandoned experiments make topology reviews slower and mistakes likelier. Range exhaustion: a subnet that runs out of addresses forces workloads into a second subnet, sometimes in another region, quietly introducing inter-region egress. And accidental cross-region placement: a dev VM dropped into a distant region’s subnet pays that region’s rates and cross-region data charges nobody budgeted.

Reading subnet ranges in the console

Google Cloud console → VPC network → VPC networks lists each network; opening one shows its subnets with region, primary and secondary CIDR ranges, and the resources drawing addresses from them.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·