Skip to content

How to use the cloud-sql-auth proxy with Private Service Connect from developer machines #2158

Description

@espenmeidell

Question

Hi, according to the docs [1] the cloud-sql-auth proxy requires the private DNS zone to contain a record mapping the instance DNS to the service attachment IP. This works great from within the VPC, but not from laptops connected to the VPC via a VPN.

The command I'm running:

cloud-sql-proxy --auto-iam-authn --psc PROJECT:REGION:REDACTED

Results in errors like this:


2024/03/25 11:06:09 [REDACTED] failed to connect to instance: Dial error: failed to dial (connection name = "PROJECT:REGION:REDACTED"): dial tcp: lookup XXXXXXXX.YYYYYYYYY.REGION.sql.goog.: no such host

To solve this I can add an entry in my local hosts file mapping XXXXXXXX.YYYYYYYYY.REGION.sql.goog to the IP address of the forwarding rule (private, but accessible via my VPN). This works, but the developer ergonomics isn't great.

Is there a plan to make this simpler, or is there something obvious I'm missing? I really want to be able to use the auth proxy so I don't have to manage certificates etc.

Let me know if you need any more information, thanks!

  1. https://cloud.google.com/sql/docs/postgres/configure-private-service-connect#connect-cloud-sql-auth-proxy

Code

No response

Additional Details

No response

Metadata

Metadata

Assignees

Labels

priority: p2Moderately-important priority. Fix may not be included in next release.type: feature request‘Nice-to-have’ improvement, new feature or different behavior or design.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions