Using cloud_sql_proxy behind corporate firewall - can't connect to mysql instances

Viewed 2764

I've been able to use the google cloud sdk behind a corporate fire wall when I set my http_proxy an https_proxy variables to the right values. It also looks like the inital Oauth connection for the service account works with those proxy vars set. However when I attempt to use a mysql client connection to the machine running the proxy the connection to the google mysql instance fails.

Here is my command for the proxy, BTW(verified the proxy cmd/setup works on a system that isn't behind the corporate firewall) :

cloud_sql_proxy -instances=api-project-1054727403053:us-east1:mysql-google-v1=tcp:3306 -credential_file=c:\tools\myeditor.json

2017/09/14 09:39:29 using credential file for authentication; email=myeditor@api
-project-1054727403053.iam.gserviceaccount.com
2017/09/14 09:39:29 Listening on 127.0.0.1:3306 for api-project-1054727403053:us
-east1:mysql-google-v1
2017/09/14 09:39:29 Ready for new connections
2017/09/14 09:39:34 New connection for "api-project-1054727403053:us-east1:mysql
-google-v1"
2017/09/14 09:39:57 couldn't connect to "api-project-1054727403053:us-east1:mysq
l-google-v1": dial tcp 35.190.176.161:3307: connectex: A connection attempt fail
ed because the connected party did not properly respond after a period of time,
or established connection failed because connected host has failed to respond.
2017/09/14 09:39:58 New connection for "api-project-1054727403053:us-east1:mysql
-google-v1"
2017/09/14 09:40:19 Throttling refreshCfg(api-project-1054727403053:us-east1:mys
ql-google-v1): it was only called 43.386s ago
2017/09/14 09:40:40 couldn't connect to "api-project-1054727403053:us-east1:mysq
l-google-v1": dial tcp 35.190.176.161:3307: connectex: A connection attempt fail
ed because the connected party did not properly respond after a period of time,
or established connection failed because connected host has failed to respond.
2017/09/14 09:40:41 New connection for "api-project-1054727403053:us-east1:mysql
-google-v1"
2017/09/14 09:41:23 couldn't connect to "api-project-1054727403053:us-east1:mysq
l-google-v1": dial tcp 35.190.176.161:3307: connectex: A connection attempt fail
ed because the connected party did not properly respond after a period of time,
or established connection failed because connected host has failed to respond.

The error looks like ... dial tcp 35.190.176.161:3307: connectex: A connection attempt fail ed because the connected party did not properly respond after a period of time

Again, I have verified the above proxy setup works on a system that isn't behind the corporate firewall, so I'm wondering is there anyway to configure the cloud proxy to use the http_proxy/https_proxy to establish connections and communicate?

Thanks

1 Answers

MySQL has it's own protocol that is completely independent from HTTP, typically on port 3306. While the Cloud SQL proxy uses HTTP for initial auth setup, the actual SQL connection wraps this protocol in TLS on port 3307. Unfortunatly there is no way to run the MySQL protocol through an HTTP proxy. Instead you will need an exception to the corporate firewall.

If you just need to access Cloud SQL on the command line, I recommend doing this from Cloud Shell as described at https://cloud.google.com/sql/docs/mysql/connect-admin-ip#cloud-shell.

If you want to build a more complex application that accesses Cloud SQL from behind the firewall, you could build a GAE app that exposes an HTTP API. You can then use that API through the proxy and the GAE app can connect to Cloud SQL.

Related