4 ms·
> "Even CLI querying is not possible because CloudSQL has a private IP [...]" Uh, wat? https://cloud.google.com/sql/docs/mysql/configure-ip https://cloud.goog
by dossy 4y ago
> "Even CLI querying is not possible because CloudSQL has a private IP [...]"
Uh, wat? https://cloud.google.com/sql/docs/mysql/configure-ip https://cloud.google.com/sql/docs/mysql/configure-ip
# "You can configure your Cloud SQL instance to have a public IPv4 address, and to accept connections from specific IP addresses or a range of addresses by adding authorized addresses to your instance."
- diceduckmonk 4y agohttps://cloud.google.com/sql/docs/mysql/private-ip https://cloud.google.com/sql/docs/mysql/private-ip. CloudSQL does, in fact, have private IP. This is the right approach if you're serious about security and principal of least privilege. You're suggesting using a public IP then work backwards with an authorized list. This misses the point. This models starts with maximum privilege and scales back. Furthermore, you have to pay extra for a public IP and GCP once again forces people to pay extra to access the stuff they are already paying for. For example, the Serverless VPC connector requiring 2+ VMs defeats the scale-to-zero claim of CloudRun and the free-tier.