OrchestrAI Live

Google Cloud · Cloud service

Google Cloud VPC with OrchestrAI

Catalog exported 2026-09-02

Create VPC networks and subnetworks on Google Cloud from chat, and list or remove subnets as layouts change.

OrchestrAI exposes 4 VPC operations: 1 is low-risk (read-only or low-impact), and 3 create or modify resources and run only after you confirm the plan.

4operations
1low risk
3create or modify
0destructive
0step-level approval

What teams use it for

Infrastructure teams use OrchestrAI to lay out a custom-mode VPC with regional subnets and secondary ranges for GKE pods and services, described in prose rather than a CIDR spreadsheet. Removing an unused subnet after a migration is a common cleanup, and listing subnetworks answers which ranges are already taken. Firewall rules, peering, and Cloud NAT are not in the toolset, and there is no operation to delete a VPC network itself, so those are handled in the console.

Every VPC operation, with its risk level

Google Cloud VPC operations available through OrchestrAI
Operation What it does Risk Step-level approval
List VPC Subnetworks List GCP VPC subnetworks Low risk No
Create VPC Network Create a GCP VPC network Creates resources No
Create VPC Subnetwork Create a GCP VPC subnetwork Creates resources No
Delete VPC Subnetwork Delete a GCP VPC subnetwork Creates resources No

Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.

Prompts that work

  • Create a custom-mode VPC called prod-net with a subnet prod-us-east1 at 10.10.0.0/20 in us-east1
  • List the subnetworks in prod-net and their CIDR ranges
  • Delete the subnet legacy-west in us-west1 from the staging-net VPC

Before anything runs

Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.

Frequently asked questions

Does OrchestrAI confirm before deleting a VPC subnetwork?
Subnet deletion is rated medium, the same as creating one, because a subnet with no attached resources can be recreated. OrchestrAI presents the plan and blast radius before running it.
Can OrchestrAI create firewall rules for a GCP VPC?
Not yet, the VPC operations available are create network, create subnetwork, delete subnetwork, and list subnetworks.
Which VPC operations need an extra approval step?
None of the VPC operations currently carries a step-level approval gate; they are read-only or run after plan confirmation like any other change.

Other Google Cloud services

Related integrations

Try it on your own account

Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.

Start for $5

Unused credits refunded in your first 14 days.