Google Associate Cloud EngineerDeploying and implementing a cloud solutionEasy
An application deployed on Compute Engine VMs needs to securely connect to a Cloud SQL instance without exposing the database to the public internet. Which networking configuration should be used?
- AUse a Cloud VPN connection between the Compute Engine VPC and the Cloud SQL instance.
- BAssign a public IP address to the Cloud SQL instance and configure firewall rules.
- CConfigure Private IP for the Cloud SQL instance and ensure the Compute Engine VMs are in the same VPC network.
- DEstablish a Shared VPC between the Compute Engine project and the Cloud SQL project.
Show answer & explanationAnswer & explanation
Correct answer: C. Configure Private IP for the Cloud SQL instance and ensure the Compute Engine VMs are in the same VPC network.
Configuring Private IP for Cloud SQL allows instances to connect using internal IP addresses within a Virtual Private Cloud (VPC) network, providing secure communication without exposing the database to the public internet. VMs in the same VPC can access it directly.
Why the other options are wrong
- A. Cloud VPN is typically for connecting on-premises networks to Google Cloud, not for services within the same cloud VPC.
- B. Assigning a public IP exposes the database to the internet, which violates the security requirement.
- D. Shared VPC allows resources from different projects to share a common VPC, but it doesn't inherently create the private connection for Cloud SQL; Private IP is still needed.
Cloud SQL Private IP
Cloud SQL instances can be configured with a private IP address, allowing them to connect to Compute Engine VMs, GKE clusters, and other services within the same VPC network without needing public IP addresses.
- Uses internal IP addresses.
- Enhances security by avoiding public exposure.
- Requires VPC Peering for cross-project/network access.
- Ensures low-latency, high-bandwidth connection.
Memory trick: Private IP keeps SQL's secrets safe inside the VPC fence.