Skip to main content

7 oktober 2026

Add and Deploy a Horizon Edge for Google Cloud Platform

To deploy edges from Horizon Cloud in Google Cloud Platform (GCP), you must set up your Horizon Cloud environment as described in the following sections and redeem the Horizon Cloud Welcome email sent to the administrator account.

Note: Horizon Cloud on Google Cloud Platform is currently available in Limited Availability (LA) mode only.

For information about redeeming the Horizon Cloud Welcome email, see Onboarding to Horizon Cloud.

To configure an Identity Provider for either Entra ID or Workspace ONE Access, see Identity and Access Management in Horizon Cloud.

For overall Horizon Cloud architecture information, see Architectural overview in Omnissa Tech Zone.

Prerequisites

Before you deploy a Horizon Edge for Google Cloud Platform, review and complete the following prerequisites.

  • Review and fulfill the requirements in the Requirements Checklist for Deploying a Horizon Cloud on Google Cloud Platform Edge and Port and Protocol Requirements for Horizon Cloud on Google Cloud Platform Edge topics in the Getting Started with Horizon Cloud product document.
  • Review and complete the Horizon Cloud access process described in Horizon Cloud on GCP Deployments, including the onboarding process and any networking specifications.
  • Complete the steps in the Configure Network Settings for GCP topic to set up the required VPCs, firewall rules, NAT, and VPC peering.
  • Confirm that you meet the following requirements:
    • A GCP service account is available with the required roles and permissions. You can either assign the Compute Admin and IAP-secured Tunnel User roles, or create a custom role with the mandatory permissions listed in the Requirements Checklist for Deploying a Horizon Cloud on GCP Edge topic.
    • The Compute Engine API and Cloud Identity-Aware Proxy API (iap.googleapis.com) are enabled on the GCP project.
    • A JSON key file has been generated for the service account and the following values are available from that file: Project ID, Client ID, Client Email, Private Key ID, and Private Key.
    • Three separate VPCs — Management, Desktop, and DMZ — have been created with the required subnets, firewall rules, Cloud NAT, and VPC peering connections as described in the Configure Network Settings for GCP topic. Active Directory can be configured on the Management VPC or on-premises; the AD VPC is part of the customer's internal setup.
    • The region where you plan to deploy Windows 11 VMs has sufficient Sole Tenant Node quota and available capacity to meet your deployment scale and performance requirements.
    • DNS is configured so that the Edge VM and Desktop VMs can resolve the Active Directory domain, and forward and reverse DNS records are available for the UAG external FQDN.
    • All documented URLs are reachable and necessary ports are open as described in the Port and Protocol Requirements for Horizon Cloud on GCP topic.
    • End users use a supported Horizon Client or browser to access their service-provided resources. See the Client Support section in the Horizon Cloud Service next-gen Release Notes.

Machine and User Identity Prerequisites

See Requirements Checklist for Deploying a Horizon Cloud on GCP Edge and Identity and Access Management in Horizon Cloud in Getting Started with Horizon Cloud.

Networking and VM Prerequisites

See Configure Network Settings for GCP in this Using and Managing Horizon Cloud guide.

Add and Deploy a GCP Horizon Edge

The Horizon Universal Console makes the Add Horizon Edge UI page available from various entry points. Your starting point depends on whether your environment is greenfield or has existing Horizon Edge deployments.

  • No Horizon Edges yet — click Start Deployment, or click Capacity > Add > Google Cloud Platform.
  • At least one Horizon Edge already exists — click Capacity > Horizon Edges > Add > Horizon Cloud > Google Cloud Platform.
  1. Log in to the Horizon Universal Console. See Log in to Horizon Cloud.
  2. Click Capacity > Horizon Edges in the left pane navigation.
  3. From the Horizon Edges tab, click Add and from the drop-down menu, select Horizon Cloud > Google Cloud Platform.
  4. Respond to all subsequent UI stepper pages as described below.

General Information

Enter the desired Horizon Edge name and description.

Primary Provider

  1. In the Provider dropdown, select Add New to create a new GCP provider, or select an existing provider if one has already been configured.

  2. In the Provider name field, enter a unique name for this provider.

  3. In the Project ID field, enter your GCP Project ID. This is the ID string, not the project number.

  4. In the GCP Region dropdown, select the region where the Horizon Edge will be deployed.

  5. Under the GCP Identity and Access Management (IAM) section, enter the service account credentials from your GCP Service Account JSON key file:

    • Client email — found in the JSON key file as client_email
    • Client ID — found in the JSON key file as client_id
    • Private Key ID — found in the JSON key file as private_key_id
    • Private Key — paste the full RSA private key value from private_key. Include the full -----BEGIN RSA PRIVATE KEY----- and -----END RSA PRIVATE KEY----- header and footer lines without modification.
  6. Click Next to validate the credentials and proceed.

Site

If you have a site already created, you can use that in this step. If not, create a new site using the options provided.

Connectivity

Connectivity defaults to Internet.

Horizon Edge Gateway

This step deploys the Horizon Edge Gateway — the internal management VM that handles session brokering, VM provisioning, and communication with the Horizon Cloud control plane.

Deployment

  1. In the Zone dropdown, select the GCP zone within your provider region where the Horizon Edge Gateway VM will be deployed. The zone must have the management subnet available.

Networking

  1. In the Management Virtual Private Network (VPC) dropdown, select the VPC network that will carry management traffic between the Horizon Edge Gateway and the Horizon Cloud control plane.
  2. In the Management Subnet dropdown, select the subnet within the Management VPC where the Horizon Edge Gateway VM's network interface will be attached.

SSO

  1. Review the Use Single sign-on toggle:

    • Enabled — users authenticate once through the configured Identity Provider and access desktops without additional credential prompts. Requires an Identity Provider to be configured under Identity & Access.
    • Disabled (default) — users are prompted to authenticate separately when launching desktops or applications.

Unified Access Gateway

This step configures the Unified Access Gateway (UAG) — the access layer that provides secure, encrypted connectivity for end users connecting to their virtual desktops and applications via Horizon Client or a browser.

Deployment

  1. Deployment type defaults to Basic.
    • Basic — Load balancer is configured in "session persistence/source IP affinity" distribution mode. Traffic from same client IP is routed through the same UAG instance.
  2. In the Zone dropdown, select the GCP zone where the UAG VMs will be deployed. It is recommended to use the same zone as the Horizon Edge Gateway.

Gateway Access

  1. In the Access type dropdown, select one of the following:

    • Internal access over a corporate network — a Layer 4 load balancer will be deployed with a frontend in the Desktop network.
    • External access over the internet — a Layer 4 load balancer will be deployed with a public IP.
    • Internal and external access — allows both internal and external access.

Access Configuration

  1. In the External FQDN field, enter the fully qualified domain name that end users will use to connect (for example, horizon.yourcompany.com). This FQDN must resolve to the UAG load balancer's public IP address via a DNS A record you control.

Gateway VMs

  1. In the Certificate type dropdown, select:
    • CA Signed — recommended for production.
    • Self-Signed — for development or testing only. End users will see a browser security warning.
  2. Click Browse next to Certificate to upload your PEM-format certificate file including the full certificate chain.
  3. In the VM Model dropdown, select the GCP machine type for each UAG VM.
  4. In the UAG VMs field, enter the number of UAG VM instances to deploy. A minimum of 2 is strongly recommended for production environments to ensure high availability.

Networking

  1. In the VM VPC and VM Subnet dropdowns, select the VPC network and subnet for the UAG VM's primary network interface.

  2. In the Management VPC and Management Subnet dropdowns, select the VPC network and subnet for management plane communication between the UAG and the Horizon Edge Gateway.

  3. In the DMZ VPC and DMZ Subnet dropdowns, select the VPC network and subnet for the DMZ-facing network interface.

    Note: The DMZ VPC and DMZ Subnet fields are not required when the Access type is Internal access over a corporate network only. They are required when the Access type is External access over the internet or Internal and external access. The Management VPC and Management Subnet fields are always required.

  4. Click Save. Horizon Cloud will begin deploying the Horizon Edge Gateway and UAG VMs in your GCP project. Deployment typically takes 20–40 minutes. You can monitor progress on the Horizon Edges list page.

Before clicking Save: Ensure that all VPC networks and subnets referenced in the Networking section are pre-created in your GCP project. Horizon Cloud deploys VMs into existing GCP network infrastructure — it does not create VPC or subnet resources.

App Volumes Application Storage

For GCP deployments, customers must provide and register existing SMB file shares from their environment and register them for App Volumes application storage.

Unlike Azure and AWS deployments, Horizon Cloud does not provision file shares for GCP environments. Customers bring their own file shares and register them with Horizon Cloud.

Before configuring App Volumes application storage, ensure that:

  • The required SMB file shares already exist in your environment.
  • You have the UNC file share path for each file share. Example: \\smbfileserver.example.com\share
  • A service account from the domain to which the SMB file shares are joined is available.

On the App Volumes Application Storage page, configure the service account and file share information used for App Volumes application storage.

  1. To enable App Volumes application storage configuration, turn on Configure App Volumes application storage.
  2. Under Service account details, provide the credentials for the service account used by App Volumes:
    • Domain name — Enter the Active Directory domain name associated with the service account.
    • Service Account username — Enter the username for the service account.
    • Service Account password — Enter the password for the service account.
  3. Under File share registration details, click Add to register a file share.
  4. In the Add fileshare dialog box, provide the following information:
    • Fileshare path — Enter the UNC path for the SMB file share.
    • Category — Select Staging or Delivery.
  5. Click Add to register the file share. Verify that the registered file shares appear in the list.
  6. Repeat the registration process as needed.
  7. Click Save & Close to save the App Volumes application storage configuration, or click Next to continue to the next section.

Notes:

  • You must register a Staging file share before you can register Delivery file shares.
  • Until a Staging file share is registered, the Delivery option is disabled.
  • Only one Staging file share can be configured. After Staging is configured, you can register one or more Delivery file shares.
  • Registered file shares appear in the File share registration details list. From the action menu, you can Edit or Unregister a file share.
  • If a Delivery file share is unregistered, application delivery continues using the remaining registered Delivery file shares. Application delivery stops only when all registered file shares are unregistered.
  • Unregistering the Staging file share removes application information and related inventory entries from Horizon Cloud. Application packages remain in the customer SMB file share and are not deleted.
  • A Staging file share cannot be unregistered while Delivery file shares are still registered. To unregister a Staging file share, first unregister all Delivery file shares.
  • Turning off Configure App Volumes application storage removes the App Volumes application storage configuration from Horizon Cloud. You can then configure and register file shares again.
  • These behaviors apply only to GCP deployments. In Azure and AWS deployments, Horizon Cloud provisions and manages file shares, and customers do not provide or register their own file shares.

Advanced Unified Access Gateway Configuration

Source note: The advanced UAG guidance below is from the Omnissa documentation Add and Deploy an Amazon WorkSpaces Core Edge.

Prerequisites for Configuring UAG Advanced Mode

  • Ensure that all Horizon Clients connecting to the Edge (for which UAG Advanced mode is being configured) have been upgraded to Horizon HAI agent version 24.12 or above. See the Horizon Cloud Release Notes for related information about HAI agent version requirements.
  • UAG Advanced Mode is available across all supported platforms, including Native Desktop, Mobile, and Web clients.
  • When editing a deployed Horizon Edge, if there is a change in the deployment type from Basic to Advanced or Advanced to Basic, the load balancer IP address in the Unified Access Gateway section of the Edge deployment UI page might change. If a change in the load balancer IP does occur, you must update the DNS record with the new IP address.

Deployment Type — Basic or Advanced

In the Deployment section, select the Deployment Type of Basic or Advanced as described in the onscreen help. The deployment type setting specifies that load balancer distribution uses either source-ip-affinity or hash.

  • Basic — Load balancer is configured in "session persistence/source IP affinity" distribution mode. Traffic from same client IP is routed through the same UAG instance. Supports up to 2000 connections for each Horizon Edge if NAT gateway or firewall configured in front of a load balancer.
  • Advanced — Load balancer is configured in "hash-based" distribution mode. Supports up to 2000 connections for each Horizon Edge. Use of this option requires that you use a new management subnet with a subnet mask of /28. This UAG management subnet should be in the same VPC, or in a peered VPC, as the Edge management subnet. The new UAG management subnet must be provided with a /28 subnet mask selected from the list.

For example, in scenarios where you deploy a NAT gateway or firewall in front of a load balancer with Basic/source-ip-affinity UAG enabled, only 2000 connections are supported for each Horizon Edge. With Advanced/hash UAG deployment enabled, up to 2000 connections can be supported for each Horizon Edge.

If you select Advanced, you can perform one or more of the following operations:

  • If you are deploying the UAG as Blast Extreme, you can specify that port 443 be used.
  • The deployer service automatically enables 8445 inbound UDP port via a firewall rule on the UAG management network.
  • You can specify an NTP server.

When you click Save to configure the UAG Advanced mode, a message appears stating that UAG advanced mode configuration is in progress. The UAG Advanced mode configuration may take up to 15 minutes to complete.

After the successful configuration of the UAG Advanced mode, the UAG Load balancer IP might change. If so, you might have to update the DNS record with the new IP Address.

Edit the Unified Access Gateway (UAG)

If using the API, the following fields are editable for the UAG deployment:

  • Internal FQDN
  • Certificate type
  • Certificate update
  • VM model
  • UAG VMs
  • NTP Servers
  • Cipher Suites

Additional Information

You can expand the Advanced node to perform the following operations:

  • If you are deploying the Unified Access Gateway as Blast Extreme, you can use port 443.
  • You can specify an NTP server, as shown and described in the onscreen help for those options.
  • You can manage Google resource labels as needed, which includes viewing inherited labels, editing and deleting existing tags, and adding tags to be applied to the resource groups specific to this Unified Access Gateway. For related information, see Use GCP Resource Labels.

Sole Tenant Nodes Setup

Sole-tenancy provides exclusive access to a sole-tenant node — a physical Compute Engine server dedicated to hosting only your project's VMs.

To get started, navigate to Capacity > Horizon Edges, select your GCP edge, and click the Sole tenant node groups tab.

Accessing the Sole Tenant Node Groups Tab

  1. In the left navigation, click Capacity and select Horizon Edges.
  2. Select your GCP edge from the list.
  3. Click the Sole tenant node groups tab.
  4. Click Start to proceed to the node groups list view, or click Learn more for additional documentation.

Sole Tenant Node Groups List Columns

ColumnDescription
Group nameThe name assigned to the node group
StatusCurrent state — Ready, Creating, or Deleting
ZoneThe GCP zone where the node group is provisioned
Node templateThe sole-tenant node template the group is based on. Click the template name to view its full configuration.
Share typeHow nodes are shared — Local or Organization
NodesThe number of nodes in the group. Click the number to view individual node details.

Option A: Adding a New Sole Tenant Node Group

  1. In the Sole tenant node groups tab toolbar, click Add.

  2. In the Group name field, enter a unique name for this node group.

  3. The Region field is pre-populated and read-only.

  4. In the Zone dropdown, select the GCP zone.

  5. In the Sole tenant node template section, select or create a template. If creating new:

    1. Template Name
    2. Region — defaulted to the region of GCP provider
    3. Node type — e.g., c2-node-60-240, c3-node-176-352, c3-node-176-704
    4. CPU overcommit — toggle on to enable CPU overcommit
    5. SSD disk count — number of local SSD scratch disks per node
    6. GPU accelerator — GPU type, or None for CPU-only nodes
    7. GPU accelerator count — number of GPU units per node (appears when GPU is selected)
  6. In the Share type dropdown, select Local or Organization.

  7. In the Number of nodes field, enter the number of physical sole-tenant nodes to provision.

  8. Click Save. The group appears with Creating status, transitioning to Ready when complete.

Note: GCP sole-tenant node provisioning can take several minutes per node. GPU nodes may have limited regional availability — verify GCP quota for your chosen zone before adding a node group with GPU accelerators.

Option B: Importing an Existing Sole Tenant Node Group

  1. In the Sole tenant node groups tab toolbar, click Import.
  2. Follow the prompts to select the existing GCP node group(s) to import.
  3. Once imported, the node group appears in the list with its existing configuration values populated from GCP.

Note: Structural changes to imported node groups must be made directly in the GCP Console and will be reflected in Horizon Cloud after a refresh.

A node group must show a Ready status before it can be selected as a destination for pool VM provisioning.

Was deze pagina nuttig?

Feedback geven over dit onderwerp

Was dit onderwerp nuttig?

Vermeld geen persoonlijke of vertrouwelijke informatie.

Link genereren…