Manage endpoints used to access published services
After you have created a Private Service Connect endpointto access managed services, you can turn global access on or off. If you needto update other fields, delete the endpoint, and then create a new one.
Roles
The followingIAM role providesthe permissions needed to perform the tasks in this guide.
| Task | Roles |
|---|---|
| Update a Private Service Connect endpoint | Compute Network Admin (roles/compute.networkAdmin) |
Configure global access
You can turn global access on or off after an endpoint iscreated.
Turn on global access
You can turn on global access when youcreate an endpoint, or youcan turn on global access at any time after the endpoint is created.Turning on global access does not cause traffic disruption forexisting connections.
Console
In the Google Cloud console, go to thePrivate Service Connect page.
Click theConnected endpoints tab.
Click the endpoint that you want to update.
ClickEdit.
SelectEnable global access.
ClickSave.
gcloud
gcloud compute forwarding-rules updateENDPOINT_NAME \ --allow-psc-global-access \ --region=REGION
Turn off global access
You can turn off global access, which terminates any connections from regionsother than the region where the endpoint is located.
Console
In the Google Cloud console, go to thePrivate Service Connect page.
Click theConnected endpoints tab.
Click the endpoint that you want to update.
ClickEdit.
ClearEnable global access.
ClickSave.
gcloud
gcloud compute forwarding-rules updateENDPOINT_NAME \ --no-allow-psc-global-access \ --region=REGION
Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-02-19 UTC.