You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Cloud SQL PostgreSQL缺失同项目App Engine授权的替代配置咨询

Optimal Network Authorization for App Engine Flex to Access Cloud SQL PostgreSQL

Great question—this is a super common pain point when working with Cloud SQL and App Engine Flex, since those dynamic temporary IPs make restrictive firewall rules feel impossible. Skip the insecure 0.0.0.0/0 rule; here are the most secure, practical solutions I’ve implemented:

This is my go-to because it avoids IP whitelisting entirely and uses IAM for access control. The proxy runs alongside your App Engine Flex app, handles the secure connection to Cloud SQL, and lets your app connect to localhost instead of the public SQL endpoint.

To set this up:

  • Add the proxy installation and startup command to your Dockerfile (for custom runtime Flex apps) or configure it in your app.yaml (for standard Flex runtimes). For example, in a Python app's app.yaml:
    runtime: python
    env: flex
    entrypoint: bash -c "wget https://dl.google.com/cloudsql/cloud_sql_proxy.linux.amd64 -O cloud_sql_proxy && chmod +x cloud_sql_proxy && ./cloud_sql_proxy -instances=PROJECT_ID:REGION:INSTANCE_NAME=tcp:5432 & gunicorn -b :$PORT main:app"
    
  • Grant your App Engine service account the Cloud SQL Client IAM role (or a custom role with necessary permissions) to access the Cloud SQL instance.

Pros: No IP management needed, secure IAM-based access, works with all App Engine Flex runtimes.
Cons: Adds a tiny overhead to app startup, but it’s negligible for most workloads.

2. Whitelist App Engine Flex Outbound IP Ranges

Google publishes the outbound IP ranges for App Engine Flex per region. You can retrieve these ranges and add them to Cloud SQL’s authorized networks.

How to do this:

  • Use the gcloud CLI to get your app’s outbound IPs:
    gcloud app describe | grep -A 10 "featureSettings"
    
  • Copy the outboundIpAddresses list, convert them to CIDR format (e.g., 192.168.1.0/24 for a subnet range), and add each to your Cloud SQL instance’s authorized networks.
  • Set up a periodic script (using Cloud Scheduler + Cloud Functions) to refresh these IPs automatically, since Google occasionally updates the ranges.

Pros: No extra components running with your app.
Cons: Requires maintenance to keep IP ranges up-to-date, and the ranges can be broad (though still way more secure than 0.0.0.0/0).

3. Connect via Serverless VPC Access (Highest Security)

If maximum security is your priority, connect your App Engine Flex app to a VPC using Serverless VPC Access, then use Cloud SQL’s private IP. This keeps all traffic within Google’s private network, with no public IP exposure at all.

Steps:

  1. Create a Serverless VPC Access connector in your project, linked to your VPC subnet.
  2. Update your app.yaml to use the connector:
    runtime: python
    env: flex
    vpc_access_connector:
      name: "projects/PROJECT_ID/locations/REGION/connectors/CONNECTOR_NAME"
    
  3. Enable private IP for your Cloud SQL instance, and ensure the VPC subnet is authorized to access it via Cloud SQL’s private network settings.

Pros: Zero public network exposure, most secure option, ideal for sensitive workloads.
Cons: Requires VPC setup and configuration, which adds a bit more complexity upfront.

Final Recommendation

Prioritize these solutions in this order:

  • Serverless VPC Access if security is your top concern and you’re comfortable with VPC setup.
  • Cloud SQL Auth Proxy for a balance of security and ease of implementation.
  • IP Range Whitelisting only if the first two aren’t feasible for your setup.

内容的提问来源于stack exchange,提问作者Vijay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 07:08:48