You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP调用Google SQL Admin API无法添加授权IP问题求助

Why Your Google Cloud SQL IP Authorization Code Isn't Working

Let's break down the issues in your code and fix them step by step:

1. You're Not Actually Submitting the Update to the API

The biggest problem here is that after modifying the instance settings locally, you never send those changes to Google's servers. Calling $sql->instances->get(...) fetches a local copy of the instance data, and modifying that object doesn't automatically sync back to the cloud. You need to explicitly call the update method to apply your changes.

2. You're Replacing (Not Adding) Authorized Networks

Your code sets authorizedNetworks to [$newAuthNetwork], which will overwrite all existing allowed IPs instead of adding a new one. If you want to keep existing entries and add a new one, you need to append the new entry to the existing list.

3. Redundant/Unnecessary Code

You create a Google_Service_SQLAdmin_Settings object ($sqlAdmin) that you never use, and you set authorizedNetworks twice on $authNetworks which is redundant.


Fixed Code Example

$client = new Google_Client();
$client->setAuthConfig('../config/service-account.json');
$client->setApplicationName(env("APP_NAME"));
$projectName = env("GOOGLE_PROJECT_NAME");
$instanceName = env("SQL_INSTANCE_NAME");
$scopes = [
    "https://www.googleapis.com/auth/sqlservice.admin",
    "https://www.googleapis.com/auth/compute",
];
$client->addScope($scopes);
$sql = new Google_Service_SQLAdmin($client);

// Fetch the current instance and its settings
$instance = $sql->instances->get($projectName, $instanceName);
$instanceSettings = $instance->getSettings();
$ipConfiguration = $instanceSettings->getIpConfiguration();

// Get existing authorized networks (or initialize empty array if none)
$existingAuthNetworks = $ipConfiguration->getAuthorizedNetworks() ?? [];

// Create new ACL entry
$newAuthNetwork = new Google_Service_SQLAdmin_AclEntry($client);
$newAuthNetwork->setName("tmp_ip_connection");
$newAuthNetwork->setKind("sql#aclEntry");
$ipv4 = file_get_contents('https://api.ipify.org');
$newAuthNetwork->setValue($ipv4);

// Append new entry to existing list (instead of replacing)
$existingAuthNetworks[] = $newAuthNetwork;
$ipConfiguration->setAuthorizedNetworks($existingAuthNetworks);

// Update the instance settings locally
$instanceSettings->setIpConfiguration($ipConfiguration);
$instance->setSettings($instanceSettings);

// THIS IS THE KEY STEP YOU WERE MISSING: Submit the update to Google's API
$sql->instances->update($projectName, $instanceName, $instance);

// Verify the change
$updatedInstance = $sql->instances->get($projectName, $instanceName);
print_r($updatedInstance->getSettings()->getIpConfiguration()->getAuthorizedNetworks());

Key Changes Explained

  • Added $sql->instances->update(...) to send the modified instance data back to the API. This is the critical missing piece in your original code.
  • Modified the logic to append the new IP to existing authorized networks instead of replacing them (you can remove this part if you intend to replace all IPs, but that's usually not desired).
  • Removed redundant objects and cleaned up the flow to make it clearer.

Also, double-check that your service account has the Cloud SQL Admin role (or sufficient permissions) to modify instance settings. Even if you can fetch the instance data, missing write permissions would prevent updates from being applied.

内容的提问来源于stack exchange,提问作者Luis Gonzalez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:32:08