valar-psc-gateway.gcp.api.valarhq.ai over Private Service Connect instead of the public
internet. Your VPC needs no Cloud NAT, no external IPs, no egress firewall rules for Valar, and no
VPN or peering. Your IP ranges can overlap ours.
The connection is one-way: you connect to us, and nothing on our side can reach into your VPC.
Send us your project
We need two things:- The Google Cloud project ID your workloads run in.
- The region they run in.
Create the endpoint
valar-psc-gateway — it becomes your hostname. Keep the Service Directory
registration; it is what creates your DNS record.
Point your client at it
DNS is created for you inside your VPC. Set the base URL:Troubleshooting
The endpoint stays PENDING
The endpoint stays PENDING
PENDING means we have not allowlisted your project. Send us the project ID.The hostname does not resolve
The hostname does not resolve
Check the forwarding rule has a Service Directory registration — without it the endpoint works but
no DNS is created. Query from inside the VPC the endpoint lives in, and confirm the rule is named
valar-psc-gateway.Your workloads are in a different region from the attachment
Your workloads are in a different region from the attachment
Add
allow_psc_global_access = true to the forwarding rule (--allow-psc-global-access with
gcloud). Traffic crosses regions on Google’s backbone, which adds latency. Tell us your region and
we can place an attachment closer.