# Connect Your GCP VPC to ScyllaDB Cloud

This guide explains how to create a PSC endpoint in your GCP project to
connect your application to a ScyllaDB Cloud cluster over GCP Private
Service Connect.

**Before you begin:** Complete
[Configure GCP Private Service Connect in ScyllaDB Cloud](https://cloud.docs.scylladb.com/stable/cluster-connections/private-connectivity/private-connectivity-gcp/configure-gcp-private-service-connect.md) and have the
**Service Attachment ID** ready.

## Prerequisites

* The **Service Attachment ID** from the ScyllaDB Cloud PSC configuration.
  See [Retrieve the Service Attachment ID](https://cloud.docs.scylladb.com/stable/cluster-connections/private-connectivity/private-connectivity-gcp/configure-gcp-private-service-connect.md#private-connectivity-gcp-retrieve-id)
  for details.
* A ScyllaDB driver that supports Private Connectivity. See below for details.

<a id="private-connectivity-driver-requirement"></a>

**Driver Requirement**

Private Connectivity is a ScyllaDB Cloud capability that maintains token
and shard awareness over PrivateLink and Private Service Connect. To use the
feature, a native ScyllaDB Cloud driver that supports Private Connectivity is
required. Other drivers, including Cassandra and DataStax drivers, are
incompatible with the ScyllaDB Cloud Private Connectivity feature.

The following ScyllaDB drivers currently support Private Connectivity:

| Driver                                                    | Since Version                                                 | Documentation                                                                                                             |
|-----------------------------------------------------------|---------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------|
| [Python Driver](https://python-driver.docs.scylladb.com/) | 3.29.9                                                        | Documentation coming soon                                                                                                 |
| [Java Driver 4.x](https://java-driver.docs.scylladb.com/) | 4.19.0.7                                                      | Documentation coming soon                                                                                                 |
| [Go Driver](https://gocql-driver.docs.scylladb.com/)      | 1.17.1 (recommended 1.18.1 or later)                          | [Client Routes (PrivateLink / Private Service Connect)](https://gocql-driver.docs.scylladb.com/stable/client-routes.html) |
| [Rust Driver](https://rust-driver.docs.scylladb.com/)     | 1.6.0 with the `unstable-client-routes` Cargo feature enabled | [Client Routes (Private Networking)](https://rust-driver.docs.scylladb.com/stable/connecting/client-routes.html)          |

Support for additional drivers will be added in future releases.

## Step 1: Create the PSC Endpoint

You can create the endpoint in the Google Cloud UI or using the `gcloud`
command.

Google Cloud UI

1. Open the [Google Cloud Console](https://console.cloud.google.com/).
2. Go to **Network Services > Private Service Connect**.
3. Select the **Connected endpoints** tab.
4. Click **Connect endpoint**.
5. Configure the settings:
   * **Target** — Make sure to select **Published Service**.
   * **Target details** — Enter the Service Attachment ID you obtained in
     ScyllaDB Cloud.
   * **Endpoint name** — A tag to identify the endpoint.
   * **Network** — Select the VPC from which you’ll access the endpoint
     service. See the [GCP documentation on VPC networks](https://cloud.google.com/vpc/docs/vpc)
     for details on creating and managing VPC networks.
   * **Subnetwork** — Select the subnet in your VPC that will host the PSC
     endpoint. The endpoint receives an internal IP address from this subnet.
     See the [GCP documentation on working withsubnetworks](https://docs.cloud.google.com/vpc/docs/create-modify-vpc-networks#subnet-rules).
   * **IP address** — Create a new internal IP address or select
     an existing reserved internal IP.
   * **Enable global access** (optional) — Enabling global access can allow
     access from different regions, but this also adds latency and cross-
     regional traffic. Leave unchecked. The recommended setup is one PSC
     connection per datacenter.
     ![Add Private Service Connect dialog](cluster-connections/images/private-connectivity/private-service-connect-connect-endpoint.png)
6. Click **Add endpoint**.

Google Cloud CLI

1. Reserve an internal IP in a subnet of your VPC.
   ```shell
   gcloud compute addresses create my-psc-ip \
     --project <PROJECT> --region <REGION> \
     --subnet <SUBNET> \
     --addresses <Desired IP>
   ```

   The region must match the service attachment’s region. For example,
   a `us-east1` attachment needs a `us-east1` subnet.
2. Create the endpoint (forwarding rule) in the VPC:
   ```shell
   gcloud compute forwarding-rules create my-psc-endpoint \
     --project <PROJECT> \
     --region <REGION> \
     --network <YOUR_VPC_NAME> \
     --address my-psc-ip \
     --target-service-attachment=projects/<PRODUCER_PROJECT>/regions/<REGION>/serviceAttachments/<ATTACHMENT_NAME>
   ```
3. Verify that the endpoint has been successfully created:
   ```shell
   gcloud compute forwarding-rules describe my-psc-endpoint \
     --project <PROJECT> --region <REGION> \
     --format='value(pscConnectionStatus,IPAddress)'
   ```

See also [Access published services through endpoints](https://cloud.google.com/vpc/docs/configure-private-service-connect-services)
in the Google Cloud documentation.

## Step 2: Verify the PSC Endpoint (Optional)

To review the PSC endpoint configuration in your GCP project, run the
following command:

```bash
gcloud compute forwarding-rules describe <psc-endpoint-name> \
  --project <PROJECT> --region <REGION> \
  --format='value(pscConnectionStatus,IPAddress)'
```

It will display the status of the attachment and the endpoint’s IP address.
Example:

```default
gcloud compute forwarding-rules describe test-psc-endpoint \
  --project scyllaproduct --region us-east1 --format='value(pscConnectionStatus,IPAddress)'

ACCEPTED        10.142.0.8
```

You can also use a Network Intelligence Center connectivity test to verify
that a VM can reach the cluster via PSC endpoint on TCP port `9000`,
the ScyllaDB CQL port. Replace the placeholder values with values from your
GCP environment:

```bash
gcloud network-management connectivity-tests create scylladb-cloud-psc-test \
  --source-instance=projects/<gcp-project>/zones/<zone>/instances/<vm> \
  --destination-ip-address=<psc-endpoint-ip> \
  --destination-port=9000 \
  --protocol=TCP \
  --project=<gcp-project>
```

To run the test again after changing your network configuration:

```bash
gcloud network-management connectivity-tests rerun scylladb-cloud-psc-test \
  --project=<gcp-project>
```

A successful result confirms that the specified VM can reach the PSC endpoint
on the ScyllaDB CQL port. It does not verify driver authentication or
application-level connectivity.

## Step 3: Connect Using a Compatible Driver

Use one of the ScyllaDB drivers that support Private Connectivity.
See [Driver requirement](#private-connectivity-driver-requirement).

Follow the instructions provided in the **Connect** tab in your cluster’s UI.
See [Connect to Your Cluster](https://cloud.docs.scylladb.com/stable/cloud-setup/connect-to-cluster.md) for
details.

You’ll need to provide the endpoint IP address directly in the driver
connection.

See the illustrative examples below.

Python

Example for Python:

```python
from cassandra.cluster import Cluster
from scylladb.cloud import ClientRoutesOptions, ClientRoutesEndpoint

options = ClientRoutesOptions(
    endpoints=[
        ClientRoutesEndpoint(
            connection_id="<connection-uuid>",
            connection_addr="<endpoint-ip>",
        )
    ]
)
cluster = Cluster(client_routes_options=options)
```

Go

Example for Go:

```go
cluster := gocql.NewCluster()
cluster.WithOptions(gocql.WithClientRoutes(
    gocql.WithEndpoints(gocql.ClientRoutesEndpoint{
        ConnectionID:   "<connection-uuid>",
        ConnectionAddr: "<endpoint-ip-or-dns>",
    }),
))
```

Refer to your driver documentation for details:

* [ScyllaDB Drivers](https://docs.scylladb.com/stable/drivers/cql-drivers.html)
* [Connect an Application](https://docs.scylladb.com/stable/get-started/develop-with-scylladb/connect-apps.html)

## Deleting a Cluster with a Private Service Connect Connection

Connections are not automatically deleted when you delete a cluster, as they
may be used by other clusters.

Remove any connections you no longer need from **Connections** to avoid
unnecessary GCP charges.
