Conéctate a Cloud SQL para Postgres con los permisos de IAM y Go
Organiza tus páginas con colecciones
Guarda y categoriza el contenido según tus preferencias.
Conéctate a Cloud SQL para Postgres con los permisos de IAM y Go a fin de controlar quién o qué puede conectarse a tus instancias de Cloud SQL.
Explora más
Para obtener documentación en la que se incluye esta muestra de código, consulta lo siguiente:
Muestra de código
Salvo que se indique lo contrario, el contenido de esta página está sujeto a la licencia Atribución 4.0 de Creative Commons, y los ejemplos de código están sujetos a la licencia Apache 2.0. Para obtener más información, consulta las políticas del sitio de Google Developers. Java es una marca registrada de Oracle o sus afiliados.
[[["Fácil de comprender","easyToUnderstand","thumb-up"],["Resolvió mi problema","solvedMyProblem","thumb-up"],["Otro","otherUp","thumb-up"]],[["Difícil de entender","hardToUnderstand","thumb-down"],["Información o código de muestra incorrectos","incorrectInformationOrSampleCode","thumb-down"],["Faltan la información o los ejemplos que necesito","missingTheInformationSamplesINeed","thumb-down"],["Problema de traducción","translationIssue","thumb-down"],["Otro","otherDown","thumb-down"]],[],[],[],null,["# Connect to Cloud SQL for Postgres using Go and IAM permissions to control who/what can connect to your Cloud SQL instances.\n\nExplore further\n---------------\n\n\nFor detailed documentation that includes this code sample, see the following:\n\n- [Log in using IAM database authentication](/sql/docs/postgres/iam-logins)\n\nCode sample\n-----------\n\n### Go\n\n\nTo authenticate to Cloud SQL for PostgreSQL, set up Application Default Credentials.\nFor more information, see\n\n[Set up authentication for a local development environment](/docs/authentication/set-up-adc-local-dev-environment).\n\n import (\n \t\"context\"\n \t\"database/sql\"\n \t\"fmt\"\n \t\"log\"\n \t\"net\"\n \t\"os\"\n\n \t\"cloud.google.com/go/cloudsqlconn\"\n \t\"github.com/jackc/pgx/v5\"\n \t\"github.com/jackc/pgx/v5/stdlib\"\n )\n\n func connectWithConnectorIAMAuthN() (*sql.DB, error) {\n \tmustGetenv := func(k string) string {\n \t\tv := os.Getenv(k)\n \t\tif v == \"\" {\n \t\t\tlog.Fatalf(\"Warning: %s environment variable not set.\", k)\n \t\t}\n \t\treturn v\n \t}\n \t// Note: Saving credentials in environment variables is convenient, but not\n \t// secure - consider a more secure solution such as\n \t// Cloud Secret Manager (https://cloud.google.com/secret-manager) to help\n \t// keep secrets safe.\n \tvar (\n \t\tdbUser = mustGetenv(\"DB_IAM_USER\") // e.g. 'service-account-name@project-id.iam'\n \t\tdbName = mustGetenv(\"DB_NAME\") // e.g. 'my-database'\n \t\tinstanceConnectionName = mustGetenv(\"INSTANCE_CONNECTION_NAME\") // e.g. 'project:region:instance'\n \t\tusePrivate = os.Getenv(\"PRIVATE_IP\")\n \t)\n\n \t// WithLazyRefresh() Option is used to perform refresh\n \t// when needed, rather than on a scheduled interval.\n \t// This is recommended for serverless environments to\n \t// avoid background refreshes from throttling CPU.\n \td, err := cloudsqlconn.https://cloud.google.com/go/docs/reference/cloud.google.com/go/cloudsqlconn/latest/index.html#cloud_google_com_go_cloudsqlconn_Dialer_NewDialer(\n \t\tcontext.Background(),\n \t\tcloudsqlconn.https://cloud.google.com/go/docs/reference/cloud.google.com/go/cloudsqlconn/latest/index.html#cloud_google_com_go_cloudsqlconn_Option_WithIAMAuthN(),\n \t\tcloudsqlconn.https://cloud.google.com/go/docs/reference/cloud.google.com/go/cloudsqlconn/latest/index.html#cloud_google_com_go_cloudsqlconn_Option_WithLazyRefresh(),\n \t)\n \tif err != nil {\n \t\treturn nil, fmt.Errorf(\"cloudsqlconn.NewDialer: %w\", err)\n \t}\n \tvar opts []cloudsqlconn.https://cloud.google.com/go/docs/reference/cloud.google.com/go/cloudsqlconn/latest/index.html#cloud_google_com_go_cloudsqlconn_DialOption\n \tif usePrivate != \"\" {\n \t\topts = append(opts, cloudsqlconn.https://cloud.google.com/go/docs/reference/cloud.google.com/go/cloudsqlconn/latest/index.html#cloud_google_com_go_cloudsqlconn_DialOption_WithPrivateIP())\n \t}\n\n \tdsn := fmt.Sprintf(\"user=%s database=%s\", dbUser, dbName)\n \tconfig, err := pgx.ParseConfig(dsn)\n \tif err != nil {\n \t\treturn nil, err\n \t}\n\n \tconfig.DialFunc = func(ctx context.Context, network, instance string) (net.Conn, error) {\n \t\treturn d.https://cloud.google.com/go/docs/reference/cloud.google.com/go/cloudsqlconn/latest/index.html#cloud_google_com_go_cloudsqlconn_Dialer_Dial(ctx, instanceConnectionName, opts...)\n \t}\n \tdbURI := stdlib.RegisterConnConfig(config)\n \tdbPool, err := sql.Open(\"pgx\", dbURI)\n \tif err != nil {\n \t\treturn nil, fmt.Errorf(\"sql.Open: %w\", err)\n \t}\n \treturn dbPool, nil\n }\n\nWhat's next\n-----------\n\n\nTo search and filter code samples for other Google Cloud products, see the\n[Google Cloud sample browser](/docs/samples?product=cloud_sql_postgres)."]]