You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP中如何通过实例IAM用户访问数据库?所需权限及相关提示解析

Accessing GCP Databases with an IAM User + Required Permissions

Hey there! Let's walk through exactly how to use your GCP IAM user to access a Cloud SQL database (the most common managed DB in GCP), plus the permissions you need to set up. If you're working with a different GCP database like Spanner, the core IAM concepts apply, but the connection steps might vary a bit.

Step 1: Enable IAM Authentication on Your Cloud SQL Instance

First, you need to turn on IAM database auth for your instance—this is a prerequisite for using IAM users to connect:

  • Head to the GCP Console, navigate to your Cloud SQL instance.
  • Go to the Connections tab, then select the IAM authentication section.
  • Check the box for Enable IAM database authentication and save your settings. Note: You might need to restart the instance for this change to take effect.

Step 2: Create an IAM-Bound Database User

Next, you need to link your existing IAM user to a database user account in Cloud SQL:

Option 1: Using the GCP Console

  • Go to your Cloud SQL instance's Users tab.
  • Click Add user account, select the IAM user type.
  • Enter the email address associated with your IAM user, then save.

Option 2: Using the gcloud CLI

Run this command, replacing placeholders with your details:

gcloud sql users create YOUR_IAM_USER_EMAIL --instance=YOUR_INSTANCE_NAME --type=iam

Step 3: Connect to the Database with Your IAM User

You'll need a client that supports IAM authentication, or use the Cloud SQL Auth Proxy (the most secure method):

  1. Download and start the proxy:

    ./cloud-sql-proxy YOUR_INSTANCE_CONNECTION_NAME
    

    (Your instance connection name looks like project-id:region:instance-name)

  2. Generate a temporary access token (valid for 1 hour):

    gcloud auth print-access-token
    
  3. Connect using your database client (e.g., psql for PostgreSQL):

    psql "host=127.0.0.1 port=5432 user=YOUR_IAM_USER_EMAIL dbname=YOUR_DB_NAME password=$(gcloud auth print-access-token)"
    

    For MySQL, the command is similar—just use the mysql client instead.

Using a Direct Client Connection

If your client supports automatic IAM token retrieval (some GCP-integrated tools do), you can connect directly by using the IAM user's email as the username and letting the client handle the token.


Required Permissions to Configure

As the warning mentioned, IAM users start with no database privileges—you need to set up two layers of permissions:

1. GCP IAM Roles (Instance-Level Access)

These control whether the IAM user can even connect to the Cloud SQL instance:

  • Cloud SQL Client (roles/cloudsql.client): This is the minimum required role—it grants permission to connect to the instance.
  • If you need the user to manage database users or instance settings, you can assign Cloud SQL Editor (roles/cloudsql.editor), but stick to cloudsql.client for read-only/limited access.
  • For strict least-privilege, create a custom IAM role with just the cloudsql.instances.connect permission.

2. Database-Level Privileges

Once the user can connect to the instance, you need to grant them permissions inside the database itself. Log into the database using a superuser account (like root for MySQL or postgres for PostgreSQL) and run these commands:

For PostgreSQL:

-- Grant read/write access to all tables in a schema
GRANT SELECT, INSERT, UPDATE, DELETE ON ALL TABLES IN SCHEMA public TO "YOUR_IAM_USER_EMAIL";

-- Grant permission to create tables/objects in the schema (if needed)
GRANT CREATE ON SCHEMA public TO "YOUR_IAM_USER_EMAIL";

For MySQL:

-- Grant read/write access to a specific database
GRANT SELECT, INSERT, UPDATE, DELETE ON `your_database_name`.* TO 'YOUR_IAM_USER_EMAIL';

-- Grant create table permissions (if needed)
GRANT CREATE ON `your_database_name`.* TO 'YOUR_IAM_USER_EMAIL';

-- Refresh privileges to apply changes
FLUSH PRIVILEGES;

Quick Notes

  • Access tokens expire after 1 hour—you'll need to regenerate them with gcloud auth print-access-token when that happens.
  • Make sure the Cloud SQL API (cloudsql.googleapis.com) is enabled in your GCP project.
  • If you're using a VPC, ensure your network has access to the Cloud SQL instance, or use the Auth Proxy to bypass network restrictions.

内容的提问来源于stack exchange,提问作者Jan Seijerlin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 01:22:42