restrict connections to Cloud SQL MySQL instance

Viewed 816

Is there a way to restrict which compute engine instance can connect to my Cloud SQL instance? It looks like as long as the compute engine is connecting to my Cloud SQL instance using private IP, it goes thru.

Is there a way to restrict it by saying only allow those compute engine instances to connect to my Cloud SQL instance that has specified service account attached?

3 Answers

Is there a way to restrict it by saying only allow those compute engine instances to connect to my Cloud SQL instance that has specified service account attached?

There's already a feature request that the same of your concern. You can star the public issue tracker feature requests to ensure that you will receive the updates about it.

As alternative way, create a new VPC Network for your Cloud SQL instance connection and Compute Engine instance. Or host your Cloud SQL instance and Compute Engine instance to a new Google Cloud Project.

You can create firewall rule based on the service account. Let say that your port is 3306 (MySQL standard port). You can do that:

  • Create a firewall rule:
    • Source -> All VM in the network
    • Target -> IP of your database
    • Egress
    • Deny
    • priority 10000
    • port 3306
    • Protocol TCP
  • Create a firewall rules per VM that you want to authorize
    • Source -> Service Account of the VM
    • Target -> IP of your database
    • Egress
    • Allow
    • priority 1000
    • port 3306
    • Protocol TCP

Like that you block all by default, and you authorize only explicitly the VM with the specified service account to reach your database IP

Related