如何为GKE中运行的Payara Server Full Pod配置与CloudSQL的JDBC连接
Hey there! Let's walk through how to set up your JDBC connection between Payara Server Full on GKE and Cloud SQL. I've done this a few times, so here's a step-by-step breakdown that should get you sorted:
Cloud SQL offers two main ways to connect from GKE—Cloud SQL Auth Proxy (the recommended secure option, no IP whitelisting needed) or direct private IP connection. We'll start with the proxy since it's simpler to implement for most cases.
You'll run the proxy alongside your Payara container in the same Pod to route traffic securely to Cloud SQL. Update your Deployment manifest with these changes:
- Add the proxy container using the official image:
gcr.io/cloudsql-docker/gce-proxy:1.33.0(check GCP's docs for the latest version if needed) - The proxy command should look like this (adjust port for MySQL/PostgreSQL):
Replace/cloud_sql_proxy -instances=YOUR_PROJECT_ID:REGION:INSTANCE_NAME=tcp:5432 -credential_file=/secrets/cloudsql/credentials.jsonYOUR_PROJECT_ID,REGION,INSTANCE_NAMEwith your actual values—use port 3306 for MySQL instead of 5432. - Create a Kubernetes Secret to store your Cloud SQL service account key (generate the key in GCP Console > IAM > Service Accounts, then run:
kubectl create secret generic cloudsql-instance-credentials --from-file=credentials.json=/path/to/your/downloaded-key.json). Mount this secret to the proxy container so it can access the credentials file.
With the proxy handling traffic, now set up the JDBC pool in Payara. You can use the Admin Console or edit domain.xml directly—both options work.
Option A: Use Payara Admin Console
- First, access the console securely (for testing, use port-forwarding:
kubectl port-forward <your-payara-pod-name> 4848:4848) - Navigate to Resources > JDBC > JDBC Connection Pools and click New:
- Pool Name: Pick a descriptive name (e.g.,
CloudSQLPool) - Resource Type: Select
javax.sql.DataSource(standard for most apps) - Database Driver Vendor: Choose your database (PostgreSQL/MySQL/etc.)
- Pool Name: Pick a descriptive name (e.g.,
- On the next page, fill in connection details:
- Host:
localhost(since the proxy runs in the same Pod, it listens on localhost) - Port: 5432 (PostgreSQL) or 3306 (MySQL)
- Database Name: Your Cloud SQL database name
- User Name/Password: Your Cloud SQL database credentials
- Host:
- Add driver-specific properties under Additional Properties (e.g.,
sslmode=requirefor PostgreSQL to enforce encrypted connections) - Click Ping to test the connection—if it succeeds, you're ready to move on!
- Create a JDBC Resource (Resources > JDBC > JDBC Resources) linked to this pool, using the JNDI name your app expects (e.g.,
jdbc/MyApplicationDB)
Option B: Edit domain.xml Directly
For automation or config-as-code workflows, add these snippets to your Payara domain.xml inside the <resources> section:
PostgreSQL Example
<jdbc-connection-pool name="CloudSQLPool" res-type="javax.sql.DataSource" datasource-classname="org.postgresql.ds.PGSimpleDataSource"> <property name="serverName" value="localhost"/> <property name="portNumber" value="5432"/> <property name="databaseName" value="YOUR_DB_NAME"/> <property name="user" value="YOUR_DB_USER"/> <property name="password" value="YOUR_DB_PASSWORD"/> <property name="sslmode" value="require"/> </jdbc-connection-pool> <jdbc-resource pool-name="CloudSQLPool" jndi-name="jdbc/MyApplicationDB"/>
MySQL Example
<jdbc-connection-pool name="CloudSQLPool" res-type="javax.sql.DataSource" datasource-classname="com.mysql.cj.jdbc.MysqlDataSource"> <property name="serverName" value="localhost"/> <property name="portNumber" value="3306"/> <property name="databaseName" value="YOUR_DB_NAME"/> <property name="user" value="YOUR_DB_USER"/> <property name="password" value="YOUR_DB_PASSWORD"/> <property name="useSSL" value="true"/> <property name="requireSSL" value="true"/> </jdbc-connection-pool> <jdbc-resource pool-name="CloudSQLPool" jndi-name="jdbc/MyApplicationDB"/>
Note: Payara Full includes PostgreSQL and MySQL drivers by default, but double-check that the driver JAR exists in glassfish/domains/domain1/lib if you run into issues.
Ensure your application uses the correct JNDI name to look up the DataSource. For example, in a Java EE app:
@Resource(lookup = "jdbc/MyApplicationDB") private DataSource appDataSource;
Test your app to confirm it can connect and execute database operations successfully.
- Avoid hardcoding credentials: Instead of putting passwords in
domain.xml, use Payara's Secure Vault or inject credentials from Kubernetes Secrets as environment variables. Reference them in the JDBC pool with syntax like${ENV=DB_PASSWORD}. - Restrict service account permissions: The service account used for the proxy only needs the
Cloud SQL Clientrole—no extra permissions. - Use private IP for production: For lower latency in production, switch to Cloud SQL's private IP by configuring VPC peering between your GKE cluster's VPC and Cloud SQL's VPC.
内容的提问来源于stack exchange,提问作者David Leonardo Andrade Bolaños

