What I'm trying to set up:
- Cloud SQL instance with private IP, Postgresql database
- A VM with one public IP and one private IP on same VPC network as the SQL instance is on (VM, SQL instance and VPC are all in the same region)
- VM has a service account with sufficient Cloud SQL client/viewer permissions
- SQL proxy on VM connecting to SQL instance. I run it with the
-ip_address_types=PRIVATEargument I've found in some of the documentation.
Configuration code
Slightly simplified Terraform code for reproducing the state that confuses me is here: https://github.com/hallvors/gcp-network-issue-demo To test this, do the following:
- create a new throwaway Google Cloud project.
- For your convenience, you can run bootstrap.sh to enable the right services (it will ask for the ID of the Google project and assume you have a gcloud client which is logged in and has access).
- Create a service account in the project, just make it owner for convenience, and save a key file in
./local-secrets/google-project-credentials.json - Update terraform.tfvars with project ID and e-mail of service account
terraform workspace new stagingterraform initterraform apply
When Terraform is done, you should have a database and a VM set up in the project.
- SSH into the VM and run
sudo apt install postgresql-client-common postgresql-client - Look up the IP address of the DB instance
- Run this (modify details as needed)
psql --host 10.167.0.3 -U gcp-network-issue-demo-staging-db-user gcp-network-issue-demo-staging-database
What happens?
- Any attempt to actually use the connection, from for example psql client or db-migrate, times out
- If I remove the VM's public IP address from the setup, it connects fine. However, I need a publicly accessible VM for other services to connect to it..
What am I missing?