> ## Documentation Index
> Fetch the complete documentation index at: https://docs.valarhq.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# GCP Private Service Connect

> Reach the Valar API from a Google Cloud VPC with no internet egress

Reach `valar-psc-gateway.gcp.api.valarhq.ai` over Private Service Connect instead of the public
internet. Your VPC needs no Cloud NAT, no external IPs, no egress firewall rules for Valar, and no
VPN or peering. Your IP ranges can overlap ours.

The connection is one-way: you connect to us, and nothing on our side can reach into your VPC.

## Send us your project

We need two things:

1. The Google Cloud **project ID** your workloads run in.
2. The **region** they run in.

We allowlist the project. We need no access to your environment.

## Create the endpoint

<CodeGroup>
  ```hcl Terraform theme={"system"}
  resource "google_compute_address" "valar" {
    name         = "valar-psc-gateway"
    region       = var.region
    subnetwork   = var.subnet
    address_type = "INTERNAL"
  }

  resource "google_service_directory_namespace" "valar" {
    namespace_id = "valar-psc"
    location     = var.region
  }

  resource "google_compute_forwarding_rule" "valar" {
    name       = "valar-psc-gateway"
    region     = var.region
    network    = var.network
    ip_address = google_compute_address.valar.id
    target     = "projects/valar-cp-prod/regions/us-east4/serviceAttachments/valar-prod-gateway"

    load_balancing_scheme = ""

    service_directory_registrations {
      namespace = google_service_directory_namespace.valar.namespace_id
    }
  }
  ```

  ```bash gcloud theme={"system"}
  gcloud compute addresses create valar-psc-gateway \
    --region=REGION --subnet=SUBNET

  gcloud service-directory namespaces create valar-psc --location=REGION

  gcloud compute forwarding-rules create valar-psc-gateway \
    --region=REGION \
    --network=NETWORK \
    --address=valar-psc-gateway \
    --target-service-attachment=projects/valar-cp-prod/regions/us-east4/serviceAttachments/valar-prod-gateway \
    --service-directory-registration=projects/PROJECT/locations/REGION/namespaces/valar-psc
  ```
</CodeGroup>

<Warning>
  `load_balancing_scheme` must be the empty string. Omitting it builds an ordinary load balancer, and
  the error will not mention Private Service Connect.
</Warning>

Keep the name `valar-psc-gateway` — it becomes your hostname. Keep the Service Directory
registration; it is what creates your DNS record.

## Point your client at it

DNS is created for you inside your VPC. Set the base URL:

<CodeGroup>
  ```python Python theme={"system"}
  client = OpenAI(
      base_url="https://valar-psc-gateway.gcp.api.valarhq.ai/v1",
      api_key=os.environ["VALAR_API_KEY"],
  )
  ```

  ```typescript TypeScript theme={"system"}
  const client = new OpenAI({
    baseURL: "https://valar-psc-gateway.gcp.api.valarhq.ai/v1",
    apiKey: process.env.VALAR_API_KEY,
  });
  ```

  ```bash curl theme={"system"}
  curl https://valar-psc-gateway.gcp.api.valarhq.ai/v1/models \
    -H "Authorization: Bearer $VALAR_API_KEY"
  ```
</CodeGroup>

## Troubleshooting

<AccordionGroup>
  <Accordion title="The endpoint stays PENDING">
    ```bash theme={"system"}
    gcloud compute forwarding-rules describe valar-psc-gateway \
      --region=REGION --format='value(pscConnectionStatus)'
    ```

    `PENDING` means we have not allowlisted your project. Send us the project ID.
  </Accordion>

  <Accordion title="The hostname does not resolve">
    Check the forwarding rule has a Service Directory registration — without it the endpoint works but
    no DNS is created. Query from inside the VPC the endpoint lives in, and confirm the rule is named
    `valar-psc-gateway`.
  </Accordion>

  <Accordion title="Your workloads are in a different region from the attachment">
    Add `allow_psc_global_access = true` to the forwarding rule (`--allow-psc-global-access` with
    `gcloud`). Traffic crosses regions on Google's backbone, which adds latency. Tell us your region and
    we can place an attachment closer.
  </Accordion>
</AccordionGroup>
