Vertex AI Vector Search: export custom routes on VPC peering or queries drop (private_services_access)
Vector Search online queries inside your VPC need private services access with a /16 subnet sized for them, advertised from Cloud Router as a custom advertised route.
Vertex AI Vector Search: export custom routes on VPC peering or queries drop (privateservicesaccess)
TL;DR
[Google Cloud docs (Vector Search private services access)]: Vector Search online queries inside your VPC need private services access with a /16 subnet sized for them, advertised from Cloud Router as a custom advertised route. Then update the VPC peering connection to export custom routes to the service producer network. By default the service producer only learns subnet routes, so anything not from a subnet IP range gets dropped.
Use this when you run into the situation in the title.
When not to use this skill: unrelated tasks. It covers only the procedure above.
Compatibility
The steps above apply to the commands named in them. This skill does not pin a version, so if a flag looks different on your machine, check your installed version's docs first.
Details
That peering export is the bit people miss.
Context: Google Cloud docs (Vector Search private services access): online queries need private services access set up with the right subnet sizing. Size the subnet at /16 for Vector Search online queries and advertise it from Cloud Router as a custom advertised route. On VPC Network Peering, update the peering connection to export custom routes to the service producer network. By default the service producer only learns subnet routes, so any request not from a subnet IP range gets dropped.