如何解决本地/Cloud Shell/App Engine无法连接Compute Engine上MySQL服务器的问题?
Hey there, let's work through this connection issue together—since other Compute Engine VMs can connect to your MySQL server, we know the database itself is healthy. The problem is almost definitely tied to network access rules or MySQL configuration settings that are blocking external connections. Here's a step-by-step breakdown to fix it:
Firewall blocks are the #1 reason external connections fail. MySQL uses port 3306 by default, so we need to make sure this port is open to your local machine, Cloud Shell, and App Engine:
- Head to the GCP Console, navigate to VPC Network > Firewall
- Look for an existing rule that allows traffic on port 3306. If there isn't one, create a new rule:
- Name it something like
allow-mysql-external-access - Set Targets to either "All instances in the network" (or specifically your MySQL VM if you want tighter security)
- For Source IP ranges, add:
- Your local machine's public IP (find this with
curl ifconfig.mein your local terminal) - Cloud Shell's IP range:
35.235.240.0/20 - App Engine's IP ranges (you can look these up for your region, or use
0.0.0.0/0temporarily for testing—just remember to narrow it down later!)
- Your local machine's public IP (find this with
- Under Protocols and ports, select
tcp:3306 - Save the rule and wait a minute for it to take effect
- Name it something like
If your MySQL server is only listening on the local loopback (127.0.0.1) or internal GCE IP, external connections can't reach it:
- SSH into your MySQL GCE VM
- Open the MySQL config file (location varies by OS—common paths are
/etc/mysql/mysql.conf.d/mysqld.cnfor/etc/my.cnf) - Find the line starting with
bind-addressand change it to:
(Or comment out the line entirely—some default configs bind to all interfaces if this line is missing)bind-address = 0.0.0.0 - Restart MySQL to apply changes:
sudo systemctl restart mysql - Verify the binding worked with:
You should seesudo netstat -plntu | grep mysqld0.0.0.0:3306or:::3306in the output (this means it's listening on all IPs)
Even if the network is open, your MySQL user might be restricted to only connect from internal GCE IPs:
- From a GCE VM that can already connect, log into MySQL:
mysql -u your_username -p - Run this query to see which hosts your user is allowed to connect from:
SELECT user, host FROM mysql.user; - If your user's
hostislocalhostor a specific internal IP, update it to allow external connections:-- Allow connections from any IP (less secure, good for testing) GRANT ALL PRIVILEGES ON *.* TO 'your_username'@'%' IDENTIFIED BY 'your_password'; -- Or allow only your local IP (more secure) -- GRANT ALL PRIVILEGES ON *.* TO 'your_username'@'your-local-public-ip' IDENTIFIED BY 'your_password'; FLUSH PRIVILEGES;
Cloud Shell has a specific IP range, so double-check these:
- In Cloud Shell, test if you can reach the VM's public IP with:
If this fails, your firewall rule doesn't include Cloud Shell's IP rangeping your-mysql-vm-public-ip - Test the port directly with telnet:
If you get a "Connection refused" error, go back to steps 1 and 2—either the firewall is blocking it, or MySQL isn't binding to the public IPtelnet your-mysql-vm-public-ip 3306
App Engine has different network behavior depending on your environment:
- Standard Environment: By default, it's not part of your VPC. You have two options:
- Use Serverless VPC Access to connect your App Engine service to your GCE VPC (this lets you use the MySQL VM's internal IP)
- Allow App Engine's public IP ranges in your firewall rule, and use the MySQL VM's public IP in your app's connection string
- Flexible Environment: It's connected to your VPC by default, but make sure your firewall allows traffic from the App Engine Flexible IP ranges, or your MySQL user allows connections from the app's internal IP
Once you've made changes, test incrementally:
- First, use telnet from your local machine to confirm port 3306 is open:
If you see a MySQL welcome message, the network is working—now try MySQL Workbench/mysql-clienttelnet your-mysql-vm-public-ip 3306 - In Cloud Shell, run the MySQL client command:
mysql -h your-mysql-vm-public-ip -u your_username -p - For App Engine, add a quick test snippet (example in Python):
import mysql.connector try: conn = mysql.connector.connect( host="your-mysql-vm-public-ip", user="your_username", password="your_password" ) print("Successfully connected to MySQL!") conn.close() except Exception as e: print(f"Connection failed: {str(e)}")
内容的提问来源于stack exchange,提问作者gajam

