Arcade Trail: Containers & Load Balancing | GSP636

Solution for Arcade Trail: Containers & Load Balancing | GSP636. 1 lab: GSP636. Fast copy-paste commands for Google Cloud.

GSP636 — Implement Regional Internal Proxy NLB

Estimated time: 1 hour

# 🚀 Regional Internal Proxy Network Load Balancer | GSP636 > ⚠️ **Disclaimer:** This is an independent, community-made walkthrough created for educational purposes, hands-on practice, and Google Cloud certification preparation. This guide is designed to help learners understand regional internal proxy load balancing and complete practical exercises. Always attempt the lab yourself first and follow Google Cloud Skills Boost / Qwiklabs Terms of Service. This walkthrough is not affiliated with or

CYAN=


\033[0;36m'
GREEN=


\033[0;32m'
YELLOW=


\033[0;33m'
BOLD=


\033[1m'
RESET=


\033[0m'

clear
echo "${CYAN}${BOLD}"
echo "   ____        _   _ _            __   ___              "
echo "  / __ \      | | (_) |          / _| / _ \             "
echo " | |  | |_ __| |__  _| |_  ___   | |_ | | | |_ __ ___  "
echo " | |  | | '__| '_ \| | __| / _ \ |  _|| | | | '_ \ / __| "
echo " | |__| | |  | |_) | | |_ | (_) || |  | |_| | |_) \__ \ "
echo "  \____/|_|  |_.__/|_|\__| \___/ |_|   \___/| .__/|___/ "
echo "                                            | |         "
echo "                                            |_|         "
echo "${RESET}"
echo "${CYAN}${BOLD}==========================================================${RESET}"
echo "${CYAN}${BOLD} STAGE 1: Infrastructure Setup                            ${RESET}"
echo "${CYAN}${BOLD}==========================================================${RESET}"

echo "${YELLOW}▶ Detecting environment variables...${RESET}"
export REGION=$(gcloud compute project-info describe --format="value(commonInstanceMetadata.items[google-compute-default-region])")
export ZONE_A=$(gcloud compute project-info describe --format="value(commonInstanceMetadata.items[google-compute-default-zone])")
export ZONE_C=$(gcloud compute zones list --filter="region=($REGION)" --format="value(name)" | grep -v $ZONE_A | head -n 1)

echo "${YELLOW}▶ Creating custom VPC network...${RESET}"
gcloud compute networks create lb-network --subnet-mode=custom --quiet

echo "${YELLOW}▶ Creating backend and proxy-only subnets...${RESET}"
gcloud compute networks subnets create backend-subnet \
  --network=lb-network \
  --region=$REGION \
  --range=10.1.2.0/24 \
  --quiet

gcloud compute networks subnets create proxy-only-subnet \
  --network=lb-network \
  --region=$REGION \
  --range=10.129.0.0/23 \
  --purpose=REGIONAL_MANAGED_PROXY \
  --role=ACTIVE \
  --quiet

echo "${YELLOW}▶ Configuring firewall rules...${RESET}"
gcloud compute firewall-rules create fw-allow-ssh \
  --network=lb-network \
  --action=allow \
  --direction=ingress \
  --target-tags=allow-ssh \
  --source-ranges=0.0.0.0/0 \
  --rules=tcp:22 \
  --quiet

gcloud compute firewall-rules create fw-allow-health-check \
  --network=lb-network \
  --action=allow \
  --direction=ingress \
  --target-tags=allow-health-check \
  --source-ranges=130.211.0.0/22,35.191.0.0/16 \
  --rules=tcp:80 \
  --quiet

gcloud compute firewall-rules create fw-allow-proxy-only-subnet \
  --network=lb-network \
  --action=allow \
  --direction=ingress \
  --target-tags=allow-proxy-only-subnet \
  --source-ranges=10.129.0.0/23 \
  --rules=tcp:80 \
  --quiet

echo "${YELLOW}▶ Creating instance templates...${RESET}"
gcloud compute instance-templates create int-tcp-proxy-backend-template \
  --region=$REGION \
  --network=lb-network \
  --subnet=backend-subnet \
  --tags=allow-ssh,allow-health-check,allow-proxy-only-subnet \
  --metadata=startup-script='#! /bin/bash
apt-get update
apt-get install apache2 -y
a2ensite default-ssl
a2enmod ssl
vm_hostname="$(curl -H "Metadata-Flavor:Google" \
http://metadata.google.internal/computeMetadata/v1/instance/name)"
echo "Page served from: $vm_hostname" | \
tee /var/www/html/index.html
systemctl restart apache2' \
  --quiet

gcloud compute instance-templates create int-tcp-proxy-client-template \
  --region=$REGION \
  --network=lb-network \
  --subnet=backend-subnet \
  --tags=allow-ssh \
  --quiet

echo "${GREEN}${BOLD}✓ Stage 1 completed successfully.${RESET}"
CYAN=


\033[0;36m'
GREEN=


\033[0;32m'
YELLOW=


\033[0;33m'
BOLD=


\033[1m'
RESET=


\033[0m'

echo "${CYAN}${BOLD}==========================================================${RESET}"
echo "${CYAN}${BOLD} STAGE 2: Compute Resources                               ${RESET}"
echo "${CYAN}${BOLD}==========================================================${RESET}"

echo "${YELLOW}▶ Setting environment variables...${RESET}"
export REGION=$(gcloud compute project-info describe --format="value(commonInstanceMetadata.items[google-compute-default-region])")
export ZONE_A=$(gcloud compute project-info describe --format="value(commonInstanceMetadata.items[google-compute-default-zone])")
export ZONE_C=$(gcloud compute zones list --filter="region=($REGION)" --format="value(name)" | grep -v $ZONE_A | head -n 1)

echo "${YELLOW}▶ Creating Managed Instance Group A ($ZONE_A)...${RESET}"
gcloud compute instance-groups managed create mig-a \
  --template=int-tcp-proxy-backend-template \
  --size=2 \
  --zone=$ZONE_A \
  --quiet

gcloud compute instance-groups managed set-named-ports mig-a \
  --named-ports=tcp80:80 \
  --zone=$ZONE_A \
  --quiet

echo "${YELLOW}▶ Creating Managed Instance Group C ($ZONE_C)...${RESET}"
gcloud compute instance-groups managed create mig-c \
  --template=int-tcp-proxy-backend-template \
  --size=2 \
  --zone=$ZONE_C \
  --quiet

gcloud compute instance-groups managed set-named-ports mig-c \
  --named-ports=tcp80:80 \
  --zone=$ZONE_C \
  --quiet

echo "${YELLOW}▶ Reserving internal IP address...${RESET}"
gcloud compute addresses create int-tcp-ip-address \
  --region=$REGION \
  --subnet=backend-subnet \
  --purpose=SHARED_LOADBALANCER_VIP \
  --quiet

echo "${YELLOW}▶ Creating Client VM (satisfies optional Task 6)...${RESET}"
gcloud compute instances create client-vm \
  --zone=$ZONE_A \
  --source-instance-template=int-tcp-proxy-client-template \
  --quiet

echo "${GREEN}${BOLD}✓ Compute resources deployed.${RESET}"
echo "${YELLOW}▶ Waiting 20 seconds for API propagation...${RESET}"
sleep 20
CYAN=


\033[0;36m'
GREEN=


\033[0;32m'
YELLOW=


\033[0;33m'
BOLD=


\033[1m'
RESET=


\033[0m'

echo "${CYAN}${BOLD}==========================================================${RESET}"
echo "${CYAN}${BOLD} STAGE 3: Load Balancer Configuration                     ${RESET}"
echo "${CYAN}${BOLD}==========================================================${RESET}"

echo "${YELLOW}▶ Setting environment variables...${RESET}"
export REGION=$(gcloud compute project-info describe --format="value(commonInstanceMetadata.items[google-compute-default-region])")
export ZONE_A=$(gcloud compute project-info describe --format="value(commonInstanceMetadata.items[google-compute-default-zone])")
export ZONE_C=$(gcloud compute zones list --filter="region=($REGION)" --format="value(name)" | grep -v $ZONE_A | head -n 1)

echo "${YELLOW}▶ Creating Load Balancer Health Check...${RESET}"
gcloud compute health-checks create tcp tcp-health-check \
  --region=$REGION \
  --port=80 \
  --quiet

echo "${YELLOW}▶ Creating Regional Backend Service...${RESET}"
gcloud compute backend-services create my-int-tcp-lb \
  --load-balancing-scheme=INTERNAL_MANAGED \
  --protocol=TCP \
  --region=$REGION \
  --health-checks=tcp-health-check \
  --health-checks-region=$REGION \
  --port-name=tcp80 \
  --quiet

echo "${YELLOW}▶ Attaching MIGs to Backend Service...${RESET}"
gcloud compute backend-services add-backend my-int-tcp-lb \
  --region=$REGION \
  --instance-group=mig-a \
  --instance-group-zone=$ZONE_A \
  --balancing-mode=UTILIZATION \
  --max-utilization=0.8 \
  --quiet

gcloud compute backend-services add-backend my-int-tcp-lb \
  --region=$REGION \
  --instance-group=mig-c \
  --instance-group-zone=$ZONE_C \
  --balancing-mode=UTILIZATION \
  --max-utilization=0.8 \
  --quiet

echo "${YELLOW}▶ Creating Target TCP Proxy...${RESET}"
gcloud compute target-tcp-proxies create my-int-tcp-lb-proxy \
  --region=$REGION \
  --backend-service=my-int-tcp-lb \
  --quiet

echo "${YELLOW}▶ Creating Forwarding Rule (Frontend)...${RESET}"
gcloud compute forwarding-rules create int-tcp-forwarding-rule \
  --region=$REGION \
  --load-balancing-scheme=INTERNAL_MANAGED \
  --network=lb-network \
  --subnet=backend-subnet \
  --address=int-tcp-ip-address \
  --ports=110 \
  --target-tcp-proxy=my-int-tcp-lb-proxy \
  --target-tcp-proxy-region=$REGION \
  --quiet

export LB_IP=$(gcloud compute addresses describe int-tcp-ip-address --region=$REGION --format='value(address)')

echo "${GREEN}${BOLD}✓ Stage 3 completed successfully.${RESET}"
echo "${CYAN}${BOLD}==========================================================${RESET}"
echo "${GREEN}${BOLD}                  LAB SETUP COMPLETE                      ${RESET}"
echo "${CYAN}${BOLD}==========================================================${RESET}"
echo "${YELLOW}To test the Load Balancer, wait ~5 minutes for backend instances to become healthy, then run:${RESET}"
echo "gcloud compute ssh client-vm --zone=$ZONE_A"
echo "curl $LB_IP:110"
echo "${CYAN}${BOLD}==========================================================${RESET}"