This document describes how to create a data store that connects to AlloyDB for PostgreSQL data. You can link this data store to a Gemini Enterprise app to allow the agents to analyze your data.
To connect to AlloyDB for PostgreSQL data using a Gemini Enterprise data store, you can use one of the following modes:
Federated query (recommended) [Preview]: Connect to AlloyDB for PostgreSQL data in place without incurring egress costs for copying and moving the data. Federated query sends your query directly to AlloyDB for PostgreSQL across all clusters, databases, and tables that your identity has Identity and Access Management (IAM) permission to access, which is more efficient for analytical queries. When you use federated query mode, Knowledge Catalog is automatically enabled on the Assistant tab of your Gemini Enterprise app to give the agent tools to search for data that the user has access to and look up context.
Data ingestion: Copy data from a specific AlloyDB for PostgreSQL table to the Gemini Enterprise data store. Data must be manually refreshed to reflect changes in the AlloyDB for PostgreSQL table. This mode incurs egress costs for moving data to a new location, and existing IAM permissions aren't replicated into the data store.
Before you begin
To create an AlloyDB for PostgreSQL data store in Gemini Enterprise,
you must have the
Gemini Enterprise Admin
(roles/discoveryengine.agentspaceAdmin) or
Discovery Engine Admin
(roles/discoveryengine.admin) role. For more information, see
Grant permissions to admins.
If your project is protected by a VPC Service Controls perimeter or has organization policy enforcement enabled, ensure that your organization policy allows the connector:
- Add
alloydbto theallowedDataSourcesparameter in thediscoveryengine.managed.allowedDataSourcesmanaged constraint (Restrict allowed data sources for data connectors). For more information, see Overview of managed policy constraints and Configure allowed data sources.
In addition, configure the required AlloyDB for PostgreSQL IAM permissions for the connector mode that you plan to use:
Federated query
To connect to AlloyDB for PostgreSQL using federated query mode, grant the following IAM roles in the Google Cloud project that contains your AlloyDB for PostgreSQL cluster to users who query or perform actions through the connector:
- Cluster and database access:
- Cloud AlloyDB Viewer (
roles/alloydb.viewer) and Cloud AlloyDB Client (roles/alloydb.client) (or Cloud AlloyDB Database User (roles/alloydb.databaseUser) with IAM database authentication) for read-only queries and tools. - Cloud AlloyDB Admin (
roles/alloydb.admin) if write or cluster management actions (such as creating clusters, instances, or backups, or executing SQL writes) are enabled.
- Cloud AlloyDB Viewer (
- MCP tool access:
- MCP Tool User (
roles/mcp.toolUser) permission in the Google Cloud project where the AlloyDB for PostgreSQL cluster lives to invoke MCP tools.
- MCP Tool User (
Data ingestion
To ingest data from a source Google Cloud project that's
different from the Google Cloud project that contains the Gemini Enterprise data
store that you're creating, grant the
Cloud AlloyDB Admin (roles/alloydb.admin)
role on the source AlloyDB for PostgreSQL project to the
service-PROJECT_NUMBER@gcp-sa-discoveryengine.iam.gserviceaccount.com
service account (where PROJECT_NUMBER is the project number of the
Google Cloud project that contains the Gemini Enterprise data store).
Create a AlloyDB for PostgreSQL data store
To create a data store that connects data from AlloyDB for PostgreSQL to Gemini Enterprise, follow these steps:
In the Google Cloud console, go to the Gemini Enterprise page.
Go to the Data stores page.
Click Create data store.
On the Source page, choose a data source for your data store. Search for "AlloyDB for PostgreSQL" in the Select a data source search field, or find AlloyDB for PostgreSQL in the list of First-party data sources. Select Add data source.
On the Data page, select the connector mode for how to connect to your data. Select from the following tabs for further instructions based on the mode that you have chosen.
Federated query
Data ingestion
- Select Data ingestion.
- Specify details about the data that you want to import. Under Import data from your AlloyDB for PostgreSQL table, specify the following information:
- Project ID: The Google Cloud project that contains the AlloyDB for PostgreSQL table. This is a required field.
- Location ID: The AlloyDB for PostgreSQL location ID that contains the data you want to import. This is a required field.
- Cluster ID: The AlloyDB for PostgreSQL cluster ID that contains the data you want to import. This is a required field.
- Database ID: The AlloyDB for PostgreSQL database ID that contains the data you want to import. This is a required field.
- Table ID: The AlloyDB for PostgreSQL table ID that contains the data you want to import. This is a required field.
- Click Continue.
On the Configuration page, configure your data store settings.
- Location of your data connector: Choose a region for where to store the metadata of your data store. You cannot change the location after the data store is created. For important information about multi-regions, see Gemini Enterprise locations.
- Your data connector name: In the Data connector name field, enter a name for your data connector. You cannot change the name after the data connector is created. Entering a name generates a unique ID for your data connector. Optionally, in the Tag (optional) field, enter a tag for your data connector, which serves as a stable identifier for the connector across all versions.
- Sensitive data protection policy: Select a
sensitive data protection policy
for your data store. The format should follow:
projects/{project}/locations/{location}/contentPolicies/{policy}. You can edit this setting later.
Click Create.
Now you're ready to attach your data store to a Gemini Enterprise app. In federated query mode, queries incur AlloyDB for PostgreSQL usage costs when users run queries through the attached app; in data ingestion mode, importing data incurs AlloyDB for PostgreSQL and Gemini Enterprise indexing costs even before the data store is attached to an app. To learn more about these charges, see Gemini Enterprise pricing.
Next steps
To attach your data store to an app, create an app and select your data store following the steps on Create a Gemini Enterprise app.
Learn how Knowledge Catalog works with Data Cloud connectors (automatically enabled when you use federated query mode) to help the agent search for data that the user has access to and look up organizational context.
To build a high-accuracy, scoped agent with verified queries, see Publish an AlloyDB for PostgreSQL data agent to Gemini Enterprise.