[google-appengine] Re: AppEngine Flex - Correct Firewall Configuration For Inter-Service-Communication

2019-04-10 Thread 'Nicolas (Google Cloud Platform Support)' via Google App Engine
Hi David, Thanks for bringing this to our attention, I will gladly submit this documentation improvement to the rightful team. Thanks again and have a great day! On Wednesday, April 10, 2019 at 6:37:14 AM UTC-4, dvd gsng wrote: > > Hi Nicolas, thanks for verifying our results. We think that

[google-appengine] Re: AppEngine Flex - Correct Firewall Configuration For Inter-Service-Communication

2019-04-10 Thread dvd gsng
Hi Nicolas, thanks for verifying our results. We think that the GAE documentation should be updated to reflect these restrictions more explicitly, are you in a position to forward this to the appropriate team by any chance? Thanks David On Wednesday, April 3, 2019 at 7:38:12 PM UTC+2,

[google-appengine] Re: AppEngine Flex - Correct Firewall Configuration For Inter-Service-Communication

2019-04-03 Thread 'Nicolas (Google Cloud Platform Support)' via Google App Engine
Hi, Thanks for the screenshots! I’ve reproduced this and was able to confirm that if you switch the App Engine Firewall rules to “Deny All” and then try to granularly allow some IP address the app will return 403s. This is most likely due to the internal App Engine infrastructure so I

[google-appengine] Re: AppEngine Flex - Correct Firewall Configuration For Inter-Service-Communication

2019-02-27 Thread dvd gsng
Hi George, thanks for replying. Unfortunately, we've tried that, but it didn't work out as expected. We added those two IPs (and two more, see initial post) to the GAE firewall as well as the regular VPC firewall. Please have a look that the images for reference: GAE firewall: [image:

[google-appengine] Re: AppEngine Flex - Correct Firewall Configuration For Inter-Service-Communication

2019-02-25 Thread 'George (Cloud Platform Support)' via Google App Engine
It is not immediately apparent, after reading the documentation page you link to, how certain IPs are to be whitelisted; targeted HTTP requests, service accounts, and Cloud Pub/Sub are mentioned, as recommended solutions. The firewall configuration page stipulates, for requests received in