Cloud SQL SSL/TLS Configuration for Encrypted Connections: Two Methods Explained

Google Cloud SQL enforces SSL/TLS by default and supports encrypted connections via mutual TLS certificates or the Cloud SQL Auth Proxy, which automatically handles TLS without requiring client certificates.

Google Cloud SQL provides built-in encryption for database connections, ensuring that data in transit remains secure. According to the google/skills repository, Cloud SQL SSL/TLS configuration for encrypted connections can be implemented through either manually managed client certificates or the Cloud SQL Auth Proxy, which automates TLS termination through IAM authentication. Understanding both approaches helps you choose the right balance between security and operational simplicity for your workloads.

Two Methods for Cloud SQL SSL/TLS Encryption

Google Cloud SQL offers two complementary ways to establish encrypted connections.

Mutual TLS with Client Certificates

SSL/TLS certificates enable mutual TLS for direct IP-based connections. Cloud SQL automatically provides server-side certificates, and you generate client certificates using the gcloud sql ssl client-certs create command. The client presents its certificate during connection, and the server validates it.

This method suits legacy workloads, on-premise applications, or environments where the Cloud SQL Auth Proxy cannot be deployed. However, it requires you to manage certificate rotation and distribution.

Cloud SQL Auth Proxy

The Cloud SQL Auth Proxy authenticates via IAM and encrypts traffic end-to-end without requiring SSL certificates. As documented in skills/cloud/cloud-sql-basics/SKILL.md, the proxy automatically establishes a TLS tunnel to your Cloud SQL instance.

This is the recommended approach for most modern workloads, including GKE, Cloud Run, and Cloud Functions, because it removes the need to manage certificates and authorized networks.

How to Configure Cloud SQL SSL/TLS for Encrypted Connections

Both methods require that the instance has SSL/TLS enabled—which is on by default—and that appropriate IAM roles such as roles/cloudsql.client or roles/cloudsql.admin are granted, as detailed in skills/cloud/cloud-sql-basics/references/iam-security.md.

Follow these steps to configure encrypted connectivity.

1. Enable the Cloud SQL Admin API

Enable the API for your project before managing certificates or connectivity.

gcloud services enable sqladmin.googleapis.com --quiet

2. Generate a Client Certificate

Create a client certificate and private key for your instance. Keep these files secret.

gcloud sql ssl client-certs create \
    --instance=INSTANCE_NAME \
    --certificate=client-cert.pem \
    --private-key=client-key.pem

3. Download the Server CA Certificate

If your client requires server identity verification, download the public CA certificate.

gcloud sql ssl server-ca-certs list \
    --instance=INSTANCE_NAME \
    --format="value(cert)" > server-ca.pem

4. Connect Using the Client Certificate

Use the PEM files to establish a verified connection.

PostgreSQL (psql):

psql "host=PUBLIC_IP \
      port=5432 \
      dbname=DATABASE_NAME \
      user=postgres \
      sslmode=verify-full \
      sslrootcert=server-ca.pem \
      sslcert=client-cert.pem \
      sslkey=client-key.pem"

MySQL (mysql):

mysql \
    --host=PUBLIC_IP \
    --user=mysql_user \
    --ssl-mode=VERIFY_IDENTITY \
    --ssl-ca=server-ca.pem \
    --ssl-cert=client-cert.pem \
    --ssl-key=client-key.pem

5. Restrict Public Access (Optional)

Add a second layer of protection by configuring Authorized Networks to allow only specific IP ranges.

For new services, the Auth Proxy handles TLS automatically and eliminates client certificate management.

./cloud-sql-proxy \
    --instances=PROJECT:REGION:my-instance=tcp:5432 \
    --credential-file=/path/to/service-account.json

Then connect locally without SSL flags.

psql "host=127.0.0.1 port=5432 user=postgres dbname=mydb"

Why Use SSL/TLS for Cloud SQL?

Encrypting connections to Cloud SQL provides three critical security benefits.

  • Data-in-motion encryption guarantees that traffic cannot be intercepted between the client and your Cloud SQL instance.
  • Mutual authentication ensures that only clients with a valid certificate can connect, providing strong identity verification.
  • Compliance helps meet regulatory requirements that mandate TLS for all database connections.

When to Prefer the Auth Proxy Over Raw SSL

Choose the Cloud SQL Auth Proxy instead of manual SSL/TLS certificates when you want:

  • IAM-based authentication instead of managing static passwords and certificates.
  • No public IP exposure by using Private IP or the proxy tunnel.
  • Automatic certificate rotation, since the proxy refreshes TLS certificates behind the scenes.

As noted in skills/cloud/cloud-sql-basics/references/client-library-usage.md, many client libraries for Python, Java, Node.js, and Go also provide secure connections without requiring you to manage SSL certs directly.

Source Files in the google/skills Repository

The following files in the google/skills repository provide additional context and implementation guidance.

Summary

  • Cloud SQL SSL/TLS configuration for encrypted connections supports two primary methods: mutual TLS with client certificates and the Cloud SQL Auth Proxy.
  • Mutual TLS requires generating client certificates with gcloud sql ssl client-certs create and configuring clients like psql or mysql to use them.
  • The Cloud SQL Auth Proxy is the recommended approach for most workloads because it automatically encrypts traffic via IAM without manual certificate management.
  • SSL/TLS is enabled by default on Cloud SQL instances, but you must grant appropriate IAM roles and optionally restrict authorized networks for defense in depth.

Frequently Asked Questions

Is SSL/TLS enabled by default in Cloud SQL?

Yes. Cloud SQL instances have SSL/TLS enabled by default. You do not need to manually enable encryption for data in transit, though you must still configure either client certificates or the Cloud SQL Auth Proxy to connect securely depending on your architecture.

What is the difference between the Cloud SQL Auth Proxy and SSL client certificates?

SSL client certificates require you to generate, distribute, and rotate PEM files manually for mutual TLS connections over public IP. The Cloud SQL Auth Proxy authenticates via IAM and automatically establishes a TLS tunnel without client certificates, making it ideal for containerized and serverless workloads.

How do I generate a client certificate for Cloud SQL?

Use the gcloud sql ssl client-certs create command with the --instance, --certificate, and --private-key flags. This generates a PEM-encoded client certificate and private key that you must store securely and reference in your database client.

Do I need to manage server CA certificates when using the Cloud SQL Auth Proxy?

No. When using the Cloud SQL Auth Proxy, you do not need to download server CA certificates or configure SSL modes in your client. The proxy handles TLS certificate validation and rotation automatically.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →