是否需将每个Data Fusion实例对等至共享VPC?如何规避25个对等配额限制
Let's break down your questions clearly based on GCP Data Fusion's networking model:
Core Answer
You absolutely can configure multiple Data Fusion instances to use the same Google-managed tenant project, requiring only one VPC peering connection between that tenant project's VPC and your shared VPC. This directly bypasses the 25 VPC peering quota limit.
1. Is the shared tenant project configuration controllable?
Yes, this configuration is fully controllable. As noted in GCP's official Data Fusion documentation, a single managed tenant project can host multiple Data Fusion instances. When creating new instances:
- Navigate to the network configuration section during instance setup
- Select the option to use an existing tenant project instead of creating a new one
- Specify the ID of your pre-existing managed tenant project
This ensures all new instances are provisioned within the same tenant project, sharing its VPC peering connection to your shared VPC.
2. How to avoid the 25 VPC peering quota limit?
The default VPC peering quota per project is 25, but since each managed tenant project only requires one peering connection to your shared VPC (regardless of how many Data Fusion instances it hosts), you can:
- Create one initial managed tenant project and set up its VPC peering to your shared VPC
- Provision all subsequent Data Fusion instances within this same tenant project
- This approach uses only 1 peering quota instead of one per instance, easily scaling beyond 25 instances without hitting quota limits
Key Considerations
- IP Address Availability: Ensure your shared VPC subnet has enough available IP addresses. All Data Fusion runtime resources (like Dataproc clusters) will draw IPs from this subnet, so insufficient capacity will block instance creation.
- Tenant Project Quotas: Keep an eye on resource quotas within the shared tenant project (e.g., compute resources, storage). Multiple instances sharing the tenant project will consume these quotas collectively.
- IAM Permissions: Verify that your team's IAM roles include permissions to manage instances within the shared tenant project. For example, users creating instances need the
datafusion.instances.createpermission on both your main project and the tenant project.
内容的提问来源于stack exchange,提问作者Sam-Tahir

