GCP中如何通过实例IAM用户访问数据库?所需权限及相关提示解析
Hey there! Let's walk through exactly how to use your GCP IAM user to access a Cloud SQL database (the most common managed DB in GCP), plus the permissions you need to set up. If you're working with a different GCP database like Spanner, the core IAM concepts apply, but the connection steps might vary a bit.
Step 1: Enable IAM Authentication on Your Cloud SQL Instance
First, you need to turn on IAM database auth for your instance—this is a prerequisite for using IAM users to connect:
- Head to the GCP Console, navigate to your Cloud SQL instance.
- Go to the Connections tab, then select the IAM authentication section.
- Check the box for Enable IAM database authentication and save your settings. Note: You might need to restart the instance for this change to take effect.
Step 2: Create an IAM-Bound Database User
Next, you need to link your existing IAM user to a database user account in Cloud SQL:
Option 1: Using the GCP Console
- Go to your Cloud SQL instance's Users tab.
- Click Add user account, select the IAM user type.
- Enter the email address associated with your IAM user, then save.
Option 2: Using the gcloud CLI
Run this command, replacing placeholders with your details:
gcloud sql users create YOUR_IAM_USER_EMAIL --instance=YOUR_INSTANCE_NAME --type=iam
Step 3: Connect to the Database with Your IAM User
You'll need a client that supports IAM authentication, or use the Cloud SQL Auth Proxy (the most secure method):
Using Cloud SQL Auth Proxy (Recommended)
Download and start the proxy:
./cloud-sql-proxy YOUR_INSTANCE_CONNECTION_NAME(Your instance connection name looks like
project-id:region:instance-name)Generate a temporary access token (valid for 1 hour):
gcloud auth print-access-tokenConnect using your database client (e.g., psql for PostgreSQL):
psql "host=127.0.0.1 port=5432 user=YOUR_IAM_USER_EMAIL dbname=YOUR_DB_NAME password=$(gcloud auth print-access-token)"For MySQL, the command is similar—just use the
mysqlclient instead.
Using a Direct Client Connection
If your client supports automatic IAM token retrieval (some GCP-integrated tools do), you can connect directly by using the IAM user's email as the username and letting the client handle the token.
Required Permissions to Configure
As the warning mentioned, IAM users start with no database privileges—you need to set up two layers of permissions:
1. GCP IAM Roles (Instance-Level Access)
These control whether the IAM user can even connect to the Cloud SQL instance:
- Cloud SQL Client (
roles/cloudsql.client): This is the minimum required role—it grants permission to connect to the instance. - If you need the user to manage database users or instance settings, you can assign Cloud SQL Editor (
roles/cloudsql.editor), but stick tocloudsql.clientfor read-only/limited access. - For strict least-privilege, create a custom IAM role with just the
cloudsql.instances.connectpermission.
2. Database-Level Privileges
Once the user can connect to the instance, you need to grant them permissions inside the database itself. Log into the database using a superuser account (like root for MySQL or postgres for PostgreSQL) and run these commands:
For PostgreSQL:
-- Grant read/write access to all tables in a schema GRANT SELECT, INSERT, UPDATE, DELETE ON ALL TABLES IN SCHEMA public TO "YOUR_IAM_USER_EMAIL"; -- Grant permission to create tables/objects in the schema (if needed) GRANT CREATE ON SCHEMA public TO "YOUR_IAM_USER_EMAIL";
For MySQL:
-- Grant read/write access to a specific database GRANT SELECT, INSERT, UPDATE, DELETE ON `your_database_name`.* TO 'YOUR_IAM_USER_EMAIL'; -- Grant create table permissions (if needed) GRANT CREATE ON `your_database_name`.* TO 'YOUR_IAM_USER_EMAIL'; -- Refresh privileges to apply changes FLUSH PRIVILEGES;
Quick Notes
- Access tokens expire after 1 hour—you'll need to regenerate them with
gcloud auth print-access-tokenwhen that happens. - Make sure the Cloud SQL API (
cloudsql.googleapis.com) is enabled in your GCP project. - If you're using a VPC, ensure your network has access to the Cloud SQL instance, or use the Auth Proxy to bypass network restrictions.
内容的提问来源于stack exchange,提问作者Jan Seijerlin

