Using Cloud SQL

This page shows how to connect to a Cloud SQL for MySQL Second Generation instance from an App Engine application in the flexible environment, and how to read and write to Cloud SQL. Cloud SQL is a SQL database that lives in Google's cloud.

To learn more about Cloud SQL, see the Cloud SQL documentation. For information on Cloud SQL pricing and limits, see the Cloud SQL Pricing page. App Engine applications are also subject to the App Engine quotas.

Before you begin

  1. Create or select a GCP project in the GCP Console and then ensure that project includes an App Engine application and billing is enabled:
    Go to App Engine

    The Dashboard opens if an App Engine application already exists in your project and billing is enabled. Otherwise, follow the prompts for choosing a region and enabling billing.

  2. Enable the Cloud SQL API.

    Enable the API

  3. To deploy your app with the gcloud tool, you must download, install, and initialize the Google Cloud SDK:
    Download the SDK

Creating an instance and setting the password

To create and configure a Cloud SQL instance:

  1. Create a Cloud SQL Second Generation instance.
  2. If you haven't already, set the password for the default user on your Cloud SQL instance:
    gcloud sql users set-password root % --instance [INSTANCE_NAME] --password [PASSWORD]
    
  3. Record the connection name for the instance:
    gcloud sql instances describe [INSTANCE_NAME]
    

    For example:

    connectionName: project1:us-central1:instance1
    

    You can also find this value in the Instance details page of the Google Cloud Platform Console.

Granting access to App Engine

If your App Engine application and Cloud SQL instance are in different Google Cloud Platform projects, you must use a service account to allow your App Engine application access to Cloud SQL.

This service account represents your App Engine application and is created by default when you create a Google Cloud Platform project.

  1. If your App Engine application is in the same project as your Cloud SQL instance, you can skip this section and go to Setting up your local environment. Otherwise, proceed to the next step.
  2. Identify the service account associated with your App Engine application. The default App Engine service account is named [PROJECT-ID]@appspot.gserviceaccount.com.

    You can verify the App Engine service account on the IAM Permissions page. Ensure that you select the project for your App Engine application, not your Cloud SQL instance.

    Go to the IAM Permissions page

  3. Go to the IAM & Admin Projects page in the Google Cloud Platform Console.

    Go to the IAM & Admin Projects page

  4. Select the project that contains the Cloud SQL instance.
  5. Search for the service account name.
  6. If the service account is already there with the Cloud SQL Client or Editor role, you can proceed to Setting up your local environment.
  7. Otherwise, add the service account by clicking Add.
  8. In the Add members dialog, provide the name of the service account and select Cloud SQL > Cloud SQL Client for the role.

    Alternatively, you can use the primitive Editor role by selecting Project > Editor, but the Editor role includes permissions across Google Cloud Platform.

    If you do not see these roles, your Google Cloud Platform user might not have the resourcemanager.projects.setIamPolicy permission. You can check your permissions by going to the IAM page in the Google Cloud Platform Console and searching for your user id.

  9. Click Add.

    You should now see the service account listed with the specified role.

Setting up your local environment

Once deployed, your application uses the Cloud SQL Proxy that is built in to the App Engine flexible environment to communicate with your Cloud SQL instance. However, to test your application locally, you must install and use a local copy of the Cloud SQL Proxy in your development environment.

To perform basic administrative tasks on your Cloud SQL instance, you can use the administration client for your database or the GCP Console.

  1. Install the Cloud SQL proxy:

    Linux 64-bit

    1. Download the proxy:
      wget https://dl.google.com/cloudsql/cloud_sql_proxy.linux.amd64 -O cloud_sql_proxy
      
    2. Make the proxy executable:
      chmod +x cloud_sql_proxy
      

    Linux 32-bit

    1. Download the proxy:
      wget https://dl.google.com/cloudsql/cloud_sql_proxy.linux.386 -O cloud_sql_proxy
      
    2. Make the proxy executable:
      chmod +x cloud_sql_proxy
      

    OS X 64-bit

    1. Download the proxy:
      curl -o cloud_sql_proxy https://dl.google.com/cloudsql/cloud_sql_proxy.darwin.amd64
      
    2. Make the proxy executable:
      chmod +x cloud_sql_proxy
      

    OS X 32-bit

    1. Download the proxy:
      curl -o cloud_sql_proxy https://dl.google.com/cloudsql/cloud_sql_proxy.darwin.386
      
    2. Make the proxy executable:
      chmod +x cloud_sql_proxy
      

    Windows 64-bit

    Right-click https://dl.google.com/cloudsql/cloud_sql_proxy_x64.exe and select "Save link as..." to download the proxy, renaming it to cloud_sql_proxy.exe.

    Windows 32-bit

    Right-click https://dl.google.com/cloudsql/cloud_sql_proxy_x86.exe and select "Save link as..." to download the proxy, renaming it to cloud_sql_proxy.exe.
    If your operating system is not included here, you can also compile the proxy from source.

  2. Run the proxy:

    Depending on your language and environment, you can start the proxy using either TCP sockets or Unix sockets.

    TCP sockets

    1. Copy your instance connection name from the Instance details page.
    2. If you are using a service account to authenticate the proxy, note the location on your client machine of the private key file that was created when you created the service account.
    3. Start the proxy.

      Some possible proxy invocation strings:

      • Using Cloud SDK authentication:
        ./cloud_sql_proxy -instances=<INSTANCE_CONNECTION_NAME>=tcp:3306
        
        The specified port must not already be in use, for example, by a local database server.
      • Using a service account and explicit instance specification (recommended for production environments):
        ./cloud_sql_proxy -instances=<INSTANCE_CONNECTION_NAME>=tcp:3306 \
                          -credential_file=<PATH_TO_KEY_FILE> &
        

      For more information about proxy options, see Options for authenticating the proxy and Options for specifying instances.

    Unix sockets

    1. If you are using explicit instance specification, copy your instance connection name from the Instance details page.
    2. Create the directory where the proxy sockets will live:
      sudo mkdir /cloudsql; sudo chmod 777 /cloudsql
    3. If you are using a service account to authenticate the proxy, note the location on your client machine of the private key file that was created when you created the service account.
    4. Open a new terminal window and start the proxy.

      Some possible proxy invocation strings:

      • Using a service account and explicit instance specification (recommended for production environments):
        ./cloud_sql_proxy -dir=/cloudsql -instances=<INSTANCE_CONNECTION_NAME> \
                          -credential_file=<PATH_TO_KEY_FILE> &
      • Using Cloud SDK authentication and automatic instance discovery:
        ./cloud_sql_proxy -dir=/cloudsql &

      It is best to start the proxy in its own terminal so you can monitor its output without it mixing with the output from other programs.

      For more information about proxy options, see Options for authenticating the proxy and Options for specifying instances.

  3. To use the administration client, you can install a local copy and connect either by using the proxy or IP Addresses.

    For more information, see Connecting MySQL Client Using the Cloud SQL Proxy and Connecting MySQL Client Using IP Addresses.

Setting up the Cloud SQL instance

The following instructions use the gcloud command-line tool to set up the instance. You can also use the administration client on your local machine or the administration client built into Cloud Shell.

Note: The sample code below creates the databases needed in the sample, but for more information, see Creating and Managing Databases.
  1. Create a user:
    gcloud sql users create [USER_NAME] [HOST] --instance=[INSTANCE_NAME] --password=[PASSWORD]
    

Setting connection strings and adding a library

  1. Set up the local environment to support connections for local testing.

    For example, for the provided code sample:

    export MYSQL_USER=[YOUR_USER]
    export MYSQL_PASSWORD=[YOUR_PASSWORD]
    export MYSQL_DATABASE=[YOUR_DATABASE]
    export MYSQL_SOCKET_PATH=/cloudsql/[YOUR_INSTANCE_CONNECTION_NAME]
    

  2. To allow your app to connect to your Cloud SQL instance when the app is deployed, add the user, password, database, and instance connection name variables from Cloud SQL to the related environment variables in the app.yaml file:

    env_variables:
      MYSQL_USER: [YOUR_USER]
      MYSQL_PASSWORD: [YOUR_PASSWORD]
      MYSQL_DATABASE: [YOUR_DATABASE]
      MYSQL_SOCKET_PATH: /cloudsql/[YOUR_INSTANCE_CONNECTION_NAME]
  3. Add the beta_settings section to your app.yaml, using your Cloud SQL instance connection name.

    beta_settings:
      cloud_sql_instances: [YOUR_INSTANCE_CONNECTION_NAME]

  4. Add a Ruby MySQL client library to your application's Gemfile. For example, the provided code sample uses Sequel with Mysql2 as the driver:

    source "https://rubygems.org"
    
    gem "mysql2"
    gem "sequel"

  5. Install your application dependencies:

    bundle install
    

    For more information on Bundler, see Using Ruby Libraries.

Running the sample code

The sample of app.rb below uses the Sinatra framework to create a visitor log in a Cloud SQL instance. It also uses Sequel, which handles connection pooling and querying.

Before you run the sample, create the tables you need and ensure that the database is properly configured:

bundle exec ruby create_tables.rb

The following sample writes visit information to Cloud SQL and then reads and returns the last ten visits:

require "digest/sha2"
require "sinatra"
require "sequel"

DB = Sequel.mysql2 user:     ENV["MYSQL_USER"],
                   password: ENV["MYSQL_PASSWORD"],
                   database: ENV["MYSQL_DATABASE"],
                   socket:   ENV["MYSQL_SOCKET_PATH"]

get "/" do
  # Store a hash of the visitor's ip address
  visitor_ip = Digest::SHA256.hexdigest request.ip

  # Save visit in database
  DB[:visits].insert user_ip: visitor_ip, timestamp: Time.now

  # Retrieve the latest 10 visit records from the database
  visits = DB[:visits].limit(10).order Sequel.desc(:timestamp)

  response.write "Last 10 visits:\n"

  visits.each do |visit|
    response.write "Time: #{visit[:timestamp]} Addr: #{visit[:user_ip]}\n"
  end

  content_type "text/plain"
  status 200
end

Testing and deploying

  1. To test your application locally:

    bundle exec ruby app.rb
    

  2. After local testing, deploy your app to App Engine:

    gcloud app deploy
    
  3. To launch your browser and view the app at http://[YOUR_PROJECT_ID].appspot.com, run the following command:

    gcloud app browse
    

Send feedback about...

App Engine flexible environment for Ruby docs