Memory hook: Reachability, identity, privileges: three gates.
Must remember
- Private connectivity removes a public path but does not grant database permission. Plan VPC routing, DNS, private services access or Private Service Connect according to the chosen database.
- Cloud SQL/AlloyDB connectors and auth proxies simplify supported authenticated TLS connections. They do not magically create a missing private network route or remove engine-level authorization.
- IAM controls cloud resource operations and supported IAM database authentication; database users/roles control SQL privileges. Separate administration, application access and migration identities.
- Pool connections to avoid exhausting database limits during application autoscaling. Set bounded pool sizes, connection lifetimes, timeouts and retry behavior; multiply per-instance pools by maximum instance count.
- Use TLS in transit and appropriate managed/CMEK encryption at rest. Plan key permissions, rotation and availability before restricting keys; secret rotation must coordinate clients and database credentials.
- Audit sensitive access and changes at the relevant cloud and engine layers. Log enough to investigate without exposing query parameters or credentials unnecessarily.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Many short-lived application instances | Bounded connection pooling and a database connection budget. |
| Application can reach the host but SELECT fails | Inspect database authentication and object privileges. |
Traps
- Cloud IAM administrator access does not imply every SQL data privilege.
- An auth proxy is not a general-purpose VPN.
Active recall
1. Why calculate total pool size?
Hundreds of application instances can each open a pool and overwhelm the database.
2. What protects data in transit?
TLS with proper identity/certificate validation.
3. How diagnose a private connection timeout?
Check DNS, routing, firewall/service connectivity and target availability before SQL grants.
4. Why use separate migration credentials?
Migration often needs elevated temporary privileges that applications should not keep.
5. What happens if a required CMEK becomes unusable?
The dependent database operations or data access can fail.