Question
Hi, according to the docs [1] the cloud-sql-auth proxy requires the private DNS zone to contain a record mapping the instance DNS to the service attachment IP. This works great from within the VPC, but not from laptops connected to the VPC via a VPN.
The command I'm running:
cloud-sql-proxy --auto-iam-authn --psc PROJECT:REGION:REDACTED
Results in errors like this:
2024/03/25 11:06:09 [REDACTED] failed to connect to instance: Dial error: failed to dial (connection name = "PROJECT:REGION:REDACTED"): dial tcp: lookup XXXXXXXX.YYYYYYYYY.REGION.sql.goog.: no such host
To solve this I can add an entry in my local hosts file mapping XXXXXXXX.YYYYYYYYY.REGION.sql.goog to the IP address of the forwarding rule (private, but accessible via my VPN). This works, but the developer ergonomics isn't great.
Is there a plan to make this simpler, or is there something obvious I'm missing? I really want to be able to use the auth proxy so I don't have to manage certificates etc.
Let me know if you need any more information, thanks!
- https://cloud.google.com/sql/docs/postgres/configure-private-service-connect#connect-cloud-sql-auth-proxy
Code
No response
Additional Details
No response
Question
Hi, according to the docs [1] the cloud-sql-auth proxy requires the private DNS zone to contain a record mapping the instance DNS to the service attachment IP. This works great from within the VPC, but not from laptops connected to the VPC via a VPN.
The command I'm running:
Results in errors like this:
To solve this I can add an entry in my local hosts file mapping
XXXXXXXX.YYYYYYYYY.REGION.sql.googto the IP address of the forwarding rule (private, but accessible via my VPN). This works, but the developer ergonomics isn't great.Is there a plan to make this simpler, or is there something obvious I'm missing? I really want to be able to use the auth proxy so I don't have to manage certificates etc.
Let me know if you need any more information, thanks!
Code
No response
Additional Details
No response