Private Service Connect is the GCP counterpart to AWS PrivateLink: same principle, different cloud. If your Pega Cloud runs in a GCP deployment region and your enterprise resources live in a GCP VPC, this is the connectivity option designed for you.
What it means
Pega Cloud Secure Connect enables Private Service Connect as a cost-effective and reliable way to connect Pega Cloud to your existing GCP VPC. GCP itself recommends it for connections to SaaS providers when traffic originates and terminates in GCP.
Availability is the first thing to check. GCP Private Service Connect is available in Pega Cloud on GCP deployment regions only. Clients on AWS deployment regions continue with the other Secure Connect options — PrivateLink, Direct Connect public VIF, or Cloud Exchange.
As with PrivateLink, the appeal is that traffic stays inside the cloud provider’s network, and the connection is simple enough to be dependable.
What it does
- Very high bandwidth with two endpoints configured.
- Connectivity within the GCP network, providing high stability, security, and reliability.
- Low maintenance requirements.
It can also carry connectivity between Pega Cloud and enterprise resources outside GCP, via the standard hybrid-network endpoint access patterns.
How it works
The GCP vocabulary is the main hurdle here, so it is worth being explicit. A producer service attachment publishes a service. A consumer endpoint consumes one. Which side plays which role flips depending on direction.
Outbound (Pega Cloud → your GCP VPC). You configure a producer service attachment; Pega configures the matching consumer endpoint. Raise a Cloud Change ticket stating your DNS resolution approach, and — if using Private DNS — the FQDN of your service attachment. Pega returns a GCP ProjectID. You complete your service attachment configuration, then update the ticket with your ServiceAttachmentID. Pega completes the connection; if you published with explicit project approval, you accept the request, otherwise it completes automatically.
Inbound (your GCP VPC → Pega Cloud). The roles reverse: you configure a consumer endpoint, Pega configures the producer service attachment. Raise a Cloud Change ticket with the GCP ProjectID. Pega returns a ServiceAttachmentID. You create the consumer endpoint in your VPC using it, confirm in the ticket, and Pega activates and verifies.
What to remember
- GCP deployment regions only. Confirm this before offering it as an option.
- Same region as your Pega Cloud for both producer service attachments and consumer endpoints.
- One consumer endpoint per Pega Cloud environment on the inbound side.
- DNS approach is a decision, not a detail. Public DNS requires your service attachment to use a private IP address Pega provides. Private DNS supports either a split zone — where every public record in the private zone needs manual entry or it will fail — or dedicated subdomains reserved for Private Service Connect. Decide before you raise the ticket.
- Check Private Service Connect compatibility against your intended connections early; it constrains some designs.
Technical documentation: Private connectivity using GCP Private Service Connect