5 ms·
It's also a shame you can't use their own firewall rules with CloudSQL, or even specify instance tags to allow traffic inbound to CloudSQL. You have to specify
by coleca 11y ago
It's also a shame you can't use their own firewall rules with CloudSQL, or even specify instance tags to allow traffic inbound to CloudSQL. You have to specify IP ranges (CIDR) for each of your hosts. Makes it near impossible to allow an auto-scaling group to access CloudSQL since you have no control over the public IP that will be assigned to a new host being spun up in the ASG.
- Beldur 11y agoIt seems they approached the problem with a new solution: https://cloud.google.com/sql/docs/sql-proxy https://cloud.google.com/sql/docs/sql-proxy ,,The Cloud SQL Proxy provides secure access to your Cloud SQL Second Generation instances. ... It is especially useful when connecting from clients with dynamic IP address, such as Managed VM and Google Container Engine applications."
- simonmorley 11y agoThe proxy solution looks OK, shame it wasn't mentioned in the blog unless I'm blind. Lack of private IPs has been the single reason why we've not moved our current dbs over. I'm sure it's hard but you're Google after all o_0