---
sourceDocument: Zurich Workflow Data Fabric
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/integrate-applications

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Workflow Data Fabric

ft:clusterId :

    - crint

bundleId :

    - crint

workflow :

    - Creator


---

# Google Cloud Virtual Network Spoke

# Google Cloud Virtual Network Spoke {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Manage firewall, network, subnetwork, and IP address in Google Cloud Virtual Network from your ServiceNow instance.

## Request apps on the Store {#gcloudvirntwrk-spoke__section_z3j_k42_x3b}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#gcloudvirntwrk-spoke__inline-send-to-store}

## Integration Hub subscription {#gcloudvirntwrk-spoke__section_rsf_yvb_l3b}

This spoke requires an Integration Hub subscription. For more information, see [Legal schedules - IntegrationHub overview](https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/legal/snc-addendum-integrationhub.pdf).

## Spoke version {#gcloudvirntwrk-spoke__section_exv_4kv_bsb}

Google Cloud Virtual Network spoke v1.0.4 is the latest version.{#gcloudvirntwrk-spoke__gvir-netwrk}

## Spoke dependencies {#gcloudvirntwrk-spoke__section_rxy_bmq_glb}

If you're having trouble installing the app, ensure that these
dependent plugins are installed:

* ServiceNow IntegrationHub Action Template - Data Stream (com.glide.hub.action_type.datastream)
* ServiceNow IntegrationHub Action Step - REST (com.glide.hub.action_step.rest)
* ServiceNow IntegrationHub Runtime (com.glide.hub.integration.runtime)
* ServiceNow Flow Designer - Dynamic Inputs (com.glide.hub.dynamic_inputs)
* Complex Object (com.glide.cobject)
* [Google Persistent Disk Spoke](https://www.servicenow.com/docs/AB7NVvTJhr~6PMSxuPP3Ng "Manage disks, snapshots, and images in Google Persistent Disk from your ServiceNow instance.") (sn_gpdisk_spoke)
* [Google Compute Engine Spoke](https://www.servicenow.com/docs/T2hztlb9dTlbzyrGqfeFcA "Launch and manage virtual machines in Google Compute Engine spoke from your ServiceNow instance.") (sn_gcompute_spoke)

{#gcloudvirntwrk-spoke__ul_xpv_nfj_flb}  
Note:  
Some of these plugins are licensable features and require an appropriate license if used outside the spoke implementation. For information on licenses, contact your account manager.

## Google Cloud Virtual Network account requirements {#gcloudvirntwrk-spoke__section_rvj_b3t_kfba}

The Google Cloud Virtual Network spoke
requires a custom app that you create in the Google Cloud Platform.

## Supported versions {#gcloudvirntwrk-spoke__section_ccw_l34_zgb}

This spoke was built for API version v1, but may be compatible with later versions.

## Spoke actions {#gcloudvirntwrk-spoke__section_hrs_1gt_kfb}

The Google Cloud Virtual Network spoke provides actions to automate Google Cloud Virtual Network when events occur in ServiceNow. For the spoke actions to be performed, you must ensure that your project or
organization in Google Cloud Platform has the mentioned permissions. Available spoke actions include:  
{#gcloudvirntwrk-spoke__table_fcg_q52_4lb__entry__4}

| Category | Action | Description | Permissions required |
|-|-|-|-|
| Address Management | Create IP Address For Region | Creates an address resource in the specified project by using the data included in the request. | compute.addresses.create |
| Address Management | Delete IP Address | Deletes the specified address resource. | compute.addresses.delete |
| Address Management | Get IP Address | Retrieves details of the specified address resource. | compute.addresses.get |
| Firewall Management | Create Firewall For Egress | Creates a firewall for egress rule in the specified project. | compute.firewalls.create |
| Firewall Management | Create Firewall For Ingress | Creates a firewall for an ingress rule in the specified project. | compute.firewalls.create |
| Firewall Management | Delete Firewall | Deletes the specified firewall. | compute.firewalls.delete |
| Firewall Management | Get Firewall | Retrieves details of the specified firewall. | compute.firewalls.get |
| Firewall Management | Update Firewall For Egress | Updates a firewall for the egress rule in the specified project. | compute.firewalls.update |
| Firewall Management | Update Firewall For Ingress | Updates a firewall for the ingress rule in the specified project. | compute.firewalls.update |
| Metadata Retrieval Management | List Addresses | Retrieves a list of addresses contained within the specified region. | compute.addresses.list |
| Metadata Retrieval Management | List Firewalls | Retrieves a list of firewalls available to the specified project. | compute.firewalls.list |
| Metadata Retrieval Management | List Networks | Retrieves a list of networks available to the specified project. | compute.networks.list |
| Metadata Retrieval Management | List Subnetworks | Retrieves a list of subnetworks available to the specified project. | compute.subnetworks.list |
| Network Management | Create Network | Creates a network in the specified project. | compute.networks.create |
| Network Management | Delete Network | Deletes the specified network. | compute.networks.delete |
| Network Management | Get Network | Retrieves details of the specified network. | compute.networks.get |
| Subnetwork Management | Create Subnetwork | Creates a subnetwork in the specified project. | compute.subnetworks.create |
| Subnetwork Management | Delete Subnetwork | Deletes the specified subnetwork. | compute.subnetworks.delete |
| Subnetwork Management | Expand IP CIDR Range | Expands the IP CIDR range of the subnetwork to a specified value. | compute.subnetworks.expandIpCidrRange |
| Subnetwork Management | Get IAM Policy | Retrieves details of the access control policy for a resource. | compute.subnetworks.getIamPolicy |
| Subnetwork Management | Get Subnetwork | Retrieves details of the specified subnetwork. | compute.subnetworks.get |
| Subnetwork Management | Set IAM Policy | Sets the access control policy on the specified resource. | compute.subnetworks.setIamPolicy |
[ ]

{#gcloudvirntwrk-spoke__table_fcg_q52_4lb}For more information about the required permissions, see [IAM permissions reference](https://cloud.google.com/iam/docs/permissions-reference).

## Connection and credential alias requirements {#gcloudvirntwrk-spoke__section_akr_h3t_kfb}

Integration Hub uses aliases to manage connection and credential information, and OAuth credentials. Using an alias eliminates the need to configure multiple credentials and connection information
profiles when using multiple environments. If the connection or credential information changes, you don't need to update any actions that use the connection.

For information about setting up the spoke, see
[Set up the Google Cloud Virtual Network spoke](https://www.servicenow.com/docs/lD018CPregy_1dXE5WRN_w "Integrate the ServiceNow instance and Google Cloud Virtual Network spoke by using OAuth 2.0 credentials to authenticate ServiceNow requests.").

