Roll out Cloud NAT to other environments
At the time of writing, we use Cloud NAT for gstg, gprd, and CI private runners. It's arguably not essential to roll out NAT to other environments, but shouldn't be too difficult and is good for consistency.
About DR: if we were to fail over to it without having rolled out Cloud NAT, customer firewall rules that whitelisted our NAT ranges would be broken. However, there are arguably far more problems we'd have in such an event. Similarly, if we do roll out NAT, do we advertise DR's ranges if we do roll it out there?
RFC @hphilipps @ansdval