Cloud SQL runs managed MySQL, PostgreSQL, and SQL Server. Reaching the data is either a network problem (a public IP with a wide authorized-network range, or the SQL Auth Proxy opened from a host you hold) or a credential problem (built-in DB users whose passwords sit in metadata, Secret Manager, or app config, and IAM database authentication where your principal is granted a DB role).
Finding and reaching instances#
gcloud sql instances list
gcloud sql instances describe <inst> \
--format='value(ipAddresses,settings.ipConfiguration.authorizedNetworks)'
# a public IP + 0.0.0.0/0 authorized network is directly reachable
Connecting#
# built-in user over a reachable IP
mysql -h <public-ip> -u root -p
# or tunnel through the SQL Auth Proxy with your gcloud creds
cloud-sql-proxy <project>:<region>:<inst> &
psql "host=127.0.0.1 dbname=postgres user=postgres"
# IAM database authentication: mint a token as your principal
gcloud sql generate-login-token
Exploitation notes#
cloudsql.instances.connectplus the proxy reaches a private-IP instance without a password when IAM DB auth is enabled for your principal.- Built-in user passwords are frequently reused from Secret Manager or an instance's metadata; harvest there first.
- A database export (
gcloud sql export sql) to a bucket you control dumps the whole database offline when you holdcloudsql.instances.export.
Tools#
- gcloud (
sql instances list/describe,sql export sql). - cloud-sql-proxy: authenticated tunnel to an instance.
- native clients (
mysql,psql,sqlcmd).