# Cloud SQL SSL/TLS Configuration for Encrypted Connections: Two Methods Explained

> Master Cloud SQL SSL/TLS configuration. Learn two methods for encrypted connections: mutual TLS certificates and the Cloud SQL Auth Proxy. Secure your database today.

- Repository: [Google/skills](https://github.com/google/skills)
- Tags: how-to-guide
- Published: 2026-06-09

---

**Google Cloud SQL enforces SSL/TLS by default and supports encrypted connections via mutual TLS certificates or the Cloud SQL Auth Proxy, which automatically handles TLS without requiring client certificates.**

Google Cloud SQL provides built-in encryption for database connections, ensuring that data in transit remains secure. According to the `google/skills` repository, Cloud SQL SSL/TLS configuration for encrypted connections can be implemented through either manually managed client certificates or the Cloud SQL Auth Proxy, which automates TLS termination through IAM authentication. Understanding both approaches helps you choose the right balance between security and operational simplicity for your workloads.

## Two Methods for Cloud SQL SSL/TLS Encryption

Google Cloud SQL offers two complementary ways to establish encrypted connections.

### Mutual TLS with Client Certificates

**SSL/TLS certificates** enable mutual TLS for direct IP-based connections. Cloud SQL automatically provides server-side certificates, and you generate client certificates using the `gcloud sql ssl client-certs create` command. The client presents its certificate during connection, and the server validates it.

This method suits legacy workloads, on-premise applications, or environments where the Cloud SQL Auth Proxy cannot be deployed. However, it requires you to manage certificate rotation and distribution.

### Cloud SQL Auth Proxy

The **Cloud SQL Auth Proxy** authenticates via IAM and encrypts traffic end-to-end without requiring SSL certificates. As documented in [`skills/cloud/cloud-sql-basics/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/cloud-sql-basics/SKILL.md), the proxy automatically establishes a TLS tunnel to your Cloud SQL instance.

This is the recommended approach for most modern workloads, including GKE, Cloud Run, and Cloud Functions, because it removes the need to manage certificates and authorized networks.

## How to Configure Cloud SQL SSL/TLS for Encrypted Connections

Both methods require that the instance has **SSL/TLS enabled**—which is on by default—and that appropriate IAM roles such as `roles/cloudsql.client` or `roles/cloudsql.admin` are granted, as detailed in [`skills/cloud/cloud-sql-basics/references/iam-security.md`](https://github.com/google/skills/blob/main/skills/cloud/cloud-sql-basics/references/iam-security.md).

Follow these steps to configure encrypted connectivity.

### 1. Enable the Cloud SQL Admin API

Enable the API for your project before managing certificates or connectivity.

```bash
gcloud services enable sqladmin.googleapis.com --quiet

```

### 2. Generate a Client Certificate

Create a client certificate and private key for your instance. Keep these files secret.

```bash
gcloud sql ssl client-certs create \
    --instance=INSTANCE_NAME \
    --certificate=client-cert.pem \
    --private-key=client-key.pem

```

### 3. Download the Server CA Certificate

If your client requires server identity verification, download the public CA certificate.

```bash
gcloud sql ssl server-ca-certs list \
    --instance=INSTANCE_NAME \
    --format="value(cert)" > server-ca.pem

```

### 4. Connect Using the Client Certificate

Use the PEM files to establish a verified connection.

**PostgreSQL (`psql`):**

```bash
psql "host=PUBLIC_IP \
      port=5432 \
      dbname=DATABASE_NAME \
      user=postgres \
      sslmode=verify-full \
      sslrootcert=server-ca.pem \
      sslcert=client-cert.pem \
      sslkey=client-key.pem"

```

**MySQL (`mysql`):**

```bash
mysql \
    --host=PUBLIC_IP \
    --user=mysql_user \
    --ssl-mode=VERIFY_IDENTITY \
    --ssl-ca=server-ca.pem \
    --ssl-cert=client-cert.pem \
    --ssl-key=client-key.pem

```

### 5. Restrict Public Access (Optional)

Add a second layer of protection by configuring *Authorized Networks* to allow only specific IP ranges.

### 6. Deploy the Cloud SQL Auth Proxy (Recommended)

For new services, the Auth Proxy handles TLS automatically and eliminates client certificate management.

```bash
./cloud-sql-proxy \
    --instances=PROJECT:REGION:my-instance=tcp:5432 \
    --credential-file=/path/to/service-account.json

```

Then connect locally without SSL flags.

```bash
psql "host=127.0.0.1 port=5432 user=postgres dbname=mydb"

```

## Why Use SSL/TLS for Cloud SQL?

Encrypting connections to Cloud SQL provides three critical security benefits.

- **Data-in-motion encryption** guarantees that traffic cannot be intercepted between the client and your Cloud SQL instance.
- **Mutual authentication** ensures that only clients with a valid certificate can connect, providing strong identity verification.
- **Compliance** helps meet regulatory requirements that mandate TLS for all database connections.

## When to Prefer the Auth Proxy Over Raw SSL

Choose the Cloud SQL Auth Proxy instead of manual SSL/TLS certificates when you want:

- **IAM-based authentication** instead of managing static passwords and certificates.
- **No public IP exposure** by using Private IP or the proxy tunnel.
- **Automatic certificate rotation**, since the proxy refreshes TLS certificates behind the scenes.

As noted in [`skills/cloud/cloud-sql-basics/references/client-library-usage.md`](https://github.com/google/skills/blob/main/skills/cloud/cloud-sql-basics/references/client-library-usage.md), many client libraries for Python, Java, Node.js, and Go also provide secure connections without requiring you to manage SSL certs directly.

## Source Files in the google/skills Repository

The following files in the `google/skills` repository provide additional context and implementation guidance.

- **[`skills/cloud/cloud-sql-basics/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/cloud-sql-basics/SKILL.md)** — Overview of Cloud SQL, quick-start commands, and connectivity references.
- **[`skills/cloud/cloud-sql-basics/references/iam-security.md`](https://github.com/google/skills/blob/main/skills/cloud/cloud-sql-basics/references/iam-security.md)** — IAM roles, secure connectivity options, and SSL/TLS certificate management.
- **[`skills/cloud/cloud-sql-basics/references/client-library-usage.md`](https://github.com/google/skills/blob/main/skills/cloud/cloud-sql-basics/references/client-library-usage.md)** — Secure connections using official client libraries.
- **[`skills/cloud/cloud-sql-basics/references/core-concepts.md`](https://github.com/google/skills/blob/main/skills/cloud/cloud-sql-basics/references/core-concepts.md)** — Instance architecture and built-in encryption at rest and in flight.

## Summary

- **Cloud SQL SSL/TLS configuration for encrypted connections** supports two primary methods: mutual TLS with client certificates and the Cloud SQL Auth Proxy.
- Mutual TLS requires generating client certificates with `gcloud sql ssl client-certs create` and configuring clients like `psql` or `mysql` to use them.
- The **Cloud SQL Auth Proxy** is the recommended approach for most workloads because it automatically encrypts traffic via IAM without manual certificate management.
- SSL/TLS is enabled by default on Cloud SQL instances, but you must grant appropriate IAM roles and optionally restrict authorized networks for defense in depth.

## Frequently Asked Questions

### Is SSL/TLS enabled by default in Cloud SQL?

Yes. Cloud SQL instances have SSL/TLS enabled by default. You do not need to manually enable encryption for data in transit, though you must still configure either client certificates or the Cloud SQL Auth Proxy to connect securely depending on your architecture.

### What is the difference between the Cloud SQL Auth Proxy and SSL client certificates?

**SSL client certificates** require you to generate, distribute, and rotate PEM files manually for mutual TLS connections over public IP. The **Cloud SQL Auth Proxy** authenticates via IAM and automatically establishes a TLS tunnel without client certificates, making it ideal for containerized and serverless workloads.

### How do I generate a client certificate for Cloud SQL?

Use the `gcloud sql ssl client-certs create` command with the `--instance`, `--certificate`, and `--private-key` flags. This generates a PEM-encoded client certificate and private key that you must store securely and reference in your database client.

### Do I need to manage server CA certificates when using the Cloud SQL Auth Proxy?

No. When using the Cloud SQL Auth Proxy, you do not need to download server CA certificates or configure SSL modes in your client. The proxy handles TLS certificate validation and rotation automatically.