Adjusting routing within a GCP VPC
In the example setup, the current routing and firewall rules prevent our database servers from accessing the internet. However, to install software or apply patches, these servers need occasional internet connectivity. To achieve this, you will configure the bastion hosts as NAT instances to provide internet access to the database servers. This requires updating the routing configuration for the database servers within the VPC.
By default, GCP creates a route in the VPC pointing to the internet gateway, which is applied to all hosts in the network. However, since the database servers lack external public IP addresses and are restricted by firewall rules, they cannot access the internet through this default route. To resolve this, you will modify the routing for the database servers, directing their internet-bound traffic to the bastion hosts (acting as NAT instances). At the same time, you must retain the original default route, as it is used...