July 2018
Intermediate to advanced
506 pages
16h 2m
English
Let's set up an SSL connection with our hello-cloud-sql instance. Before starting, disable all non-SSL traffic for our instance with the following command:
gcloud sql instances patch hello-cloud-sql --require-ssl
Once non-SSL traffic has been disabled, we can create a client certificate for our instance. Client certificates can be created manually, by downloading the server's CA certificate, or automatically, using the built-in functionality in the gcloud CLI. If manually creating the client certificate, the server's certificate can be downloaded from the Cloud Console, or by running the following command:
gcloud sql instances describe hello-cloud-sql \ --format="value(serverCaCert.cert)" > server-ca.pem
The ...