All skills
google avatar

/cloud-sql-basics

@becc4b8
by googlegoogle/skills21k stars
1,698

This file generates or explains Cloud SQL resources. Use this file when the user asks to create a Cloud SQL instance or database for MySQL, PostgreSQL, or SQL Server. Cloud SQL manages third-party MySQL, PostgreSQL, and SQL Server instances as resources in Cloud SQL. For example, when Cloud SQL creates an open-source MySQL instance, the resulting resource is a Cloud SQL for MySQL instance that Google Cloud manages. Cloud SQL handles backups, high availability, and secure connectivity for relational database workloads.

Use this Skill: https://skilld.dev/gh/google/skills/cloud-sql-basics

This session only. Nothing lands on disk.

referencesiac-usage.md

≈694 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Cloud SQL Infrastructure as Code

Cloud SQL resources can be provisioned and managed using Terraform and other IaC tools.

Terraform

The Google Cloud Terraform provider supports Cloud SQL instances, databases, and users.

Cloud SQL Instance Example

resource "google_sql_database_instance" "default" {
  name                = "master-instance"
  region              = "us-central1"
  database_version    = "POSTGRES_18"
  deletion_protection = false # Set to true for production to prevent accidental destruction

  settings {
    tier    = "db-custom-1-3840"
    edition = "ENTERPRISE"

    # Required database flag to enable IAM database authentication
    database_flags {
      name  = "cloudsql.iam_authentication"
      value = "on"
    }

    backup_configuration {
      enabled                        = true
      point_in_time_recovery_enabled = true
    }
  }
}

resource "google_sql_database" "database" {
  name     = "my-database"
  instance = google_sql_database_instance.default.name
}

# IAM Database Authentication (Requires cloudsql.iam_authentication = "on" database flag)
resource "google_sql_user" "iam_user" {
  name     = "user-email@example.com"
  instance = google_sql_database_instance.default.name
  type     = "CLOUD_IAM_USER"
}

Key Terraform Configuration Notes

  • IAM Database Authentication Flag: Enabling IAM Database Authentication requires setting the database flag cloudsql.iam_authentication = "on" (for PostgreSQL) or cloudsql_iam_authentication = "on" (for MySQL) inside the settings.database_flags block. The user or service account must also be granted the roles/cloudsql.instanceUser IAM role.
  • Deletion Protection: By default, the Terraform Google provider sets deletion_protection = true. Set deletion_protection = false in dev/test environments if you intend to run terraform destroy.
  • Point-in-Time Recovery (PITR): Setting enabled = true in backup_configuration enables automated daily backups. Explicitly set point_in_time_recovery_enabled = true to enable continuous WAL archiving for PITR.
  • Edition Selection: Explicitly declare edition = "ENTERPRISE" or edition = "ENTERPRISE_PLUS" inside settings to define the feature set and SLA level.

Reference Documentation

Source: SKILL.md on GitHub

No alerts10d3 checks · Risk SAFE
  • Gen Agent Trust Hub10d

    This skill provides comprehensive documentation and administrative patterns for managing Google Cloud SQL resources. It includes security-focused guidance on the principle of least privilege, IAM-based authentication, and secure connectivity practices. While the skill references external package installations and powerful administrative tools, these are standard components of the service and are documented alongside relevant security considerations.

  • Socket10d

    No alerts

  • Snyk10d

    Risk: LOW · No issues

Signed by skilld at becc4b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
metadata
{
  "version": "1.0.0",
  "category": "Databases"
}

README badge

README badge for google/skills/cloud-sql-basics