对于 CloudSQL,您需要在您的 VPC 中分配一个 Google Managed Service 范围,然后在 PrivateNetwork 属性中使用 VPC Self Link 配置 SQL 实例。有关 GCP 私有服务的更多信息,请参阅GCP VPC 配置私有服务访问以及有关在CloudSQL 配置私有 IP 中将它们与 CloudSQL 一起使用的信息。
您可以在https://github.com/raelga/gcp-dm-templates中找到部署这两种配置的模板。
网络
{% if properties["google-managed-services-range"] %}
- name: google-managed-services-{{ NETWORK }}
type: compute.v1.globalAddresses
properties:
name: google-managed-services-{{ NETWORK }}
address: {{ properties["google-managed-services-range"].split("/")[0] }}
prefixLength: {{ properties["google-managed-services-range"].split("/")[1] }}
addressType: INTERNAL
purpose: VPC_PEERING
network: $(ref.{{ NETWORK }}.selfLink)
description: >
Address range reserved for Google Managed Services.
https://cloud.google.com/vpc/docs/configure-private-services-access
{% endif %}
https://github.com/raelga/gcp-dm-templates/blob/master/compute/vpc-network.jinja
SQL 实例
以及带有专用网络部分的 CloudSQL 模板:
resources:
- name: {{ name }}
type: sqladmin.v1beta4.instance
properties:
backendType: {{ properties['backendType'] }}
...
{# Connectivity #}
ipConfiguration:
ipv4Enabled: {{ properties['publicIp'] }}
{% if properties['authorizedNetworks'] %}
authorizedNetworks:
{% for authorizedNetwork in properties['authorizedNetworks'] %}
- name: {{ authorizedNetwork.name }}
cidrBlock: {{ authorizedNetwork.cidrBlock }}
{% endfor %}
{% endif %}
{% if properties['privateIp'] %}
privateNetwork: {{ "projects/{}/global/networks/{}".format(
env['project'], properties['privateNetwork']
) }}
{% endif %}
https://github.com/raelga/gcp-dm-templates/blob/master/sql/master-instance.jinja
以及用于创建私有 CloudSQL 实例的模板示例:
网络
imports:
- path: ../../../templates/compute/vpc-network.jinja
resources:
- name: vpc-network
type: ../../../templates/compute/vpc-network.jinja
properties:
subnets:
- name: compute
range: 10.60.0.0/23
google-managed-services-range: 10.60.240.0/20
https://github.com/raelga/gcp.rael.io/blob/master/dm/deployments/rshared/compute/network.yaml
CloudSQL 实例
imports:
- path: ../../../templates/sql/master-instance.jinja
resources:
- name: sites-mysql
type: ../../../templates/sql/master-instance.jinja
properties:
tier: db-f1-micro
publicIp: false
privateIp: true
privateNetwork: rshared-net
outputs:
- name: connectionName
value: $(ref.sites-mysql.connectionName)
- name: ipAddress
value: $(ref.sites-mysql.ipAddresses[0].ipAddress)
https://github.com/raelga/gcp.rael.io/blob/master/dm/deployments/rshared/sql/sites-mysql-cloudsql.yaml