Class IpConfiguration (0.1.1)

IpConfiguration(mapping=None, *, ignore_unknown_fields=False, **kwargs)

Attributes

Name Description
ipv4_enabled google.protobuf.wrappers_pb2.BoolValue
Whether the instance is assigned a public IP address or not.
private_network str
The resource link for the VPC network from which the Cloud SQL instance is accessible for private IP. For example, /projects/myProject/global/networks/default. This setting can be updated, but it cannot be removed after it is set.
require_ssl google.protobuf.wrappers_pb2.BoolValue
Use ssl_mode instead. Whether SSL/TLS connections over IP are enforced. If set to false, then allow both non-SSL/non-TLS and SSL/TLS connections. For SSL/TLS connections, the client certificate won't be verified. If set to true, then only allow connections encrypted with SSL/TLS and with valid client certificates. If you want to enforce SSL/TLS without enforcing the requirement for valid client certificates, then use the ssl_mode flag instead of the require_ssl flag.
authorized_networks MutableSequence[google.cloud.sqladmin_v1.types.AclEntry]
The list of external networks that are allowed to connect to the instance using the IP. In 'CIDR' notation, also known as 'slash' notation (for example: 157.197.200.0/24).
allocated_ip_range str
The name of the allocated ip range for the private ip Cloud SQL instance. For example: "google-managed-services-default". If set, the instance ip will be created in the allocated range. The range name must comply with `RFC 1035
enable_private_path_for_google_cloud_services google.protobuf.wrappers_pb2.BoolValue
Controls connectivity to private IP instances from Google services, such as BigQuery.
ssl_mode google.cloud.sqladmin_v1.types.IpConfiguration.SslMode
Specify how SSL/TLS is enforced in database connections. If you must use the require_ssl flag for backward compatibility, then only the following value pairs are valid: For PostgreSQL and MySQL: - ssl_mode=ALLOW_UNENCRYPTED_AND_ENCRYPTED and require_ssl=false - ssl_mode=ENCRYPTED_ONLY and require_ssl=false - ssl_mode=TRUSTED_CLIENT_CERTIFICATE_REQUIRED and require_ssl=true For SQL Server: - ssl_mode=ALLOW_UNENCRYPTED_AND_ENCRYPTED and require_ssl=false - ssl_mode=ENCRYPTED_ONLY and require_ssl=true The value of ssl_mode has priority over the value of require_ssl. For example, for the pair ssl_mode=ENCRYPTED_ONLY and require_ssl=false, ssl_mode=ENCRYPTED_ONLY means accept only SSL connections, while require_ssl=false means accept both non-SSL and SSL connections. In this case, MySQL and PostgreSQL databases respect ssl_mode and accepts only SSL connections.
psc_config google.cloud.sqladmin_v1.types.PscConfig
PSC settings for this instance. This field is a member of oneof_ _psc_config.
server_ca_mode google.cloud.sqladmin_v1.types.IpConfiguration.CaMode
Specify what type of CA is used for the server certificate. This field is a member of oneof_ _server_ca_mode.
custom_subject_alternative_names MutableSequence[str]
Optional. Custom Subject Alternative Name(SAN)s for a Cloud SQL instance.
server_ca_pool str
Optional. The resource name of the server CA pool for an instance with CUSTOMER_MANAGED_CAS_CA as the server_ca_mode. Format: projects/{PROJECT}/locations/{REGION}/caPools/{CA_POOL_ID} This field is a member of oneof_ _server_ca_pool.
server_certificate_rotation_mode google.cloud.sqladmin_v1.types.IpConfiguration.ServerCertificateRotationMode
Optional. Controls the automatic server certificate rotation feature. This feature is disabled by default. When enabled, the server certificate will be automatically rotated during Cloud SQL scheduled maintenance or self-service maintenance updates up to six months before it expires. This setting can only be set if server_ca_mode is either GOOGLE_MANAGED_CAS_CA or CUSTOMER_MANAGED_CAS_CA. This field is a member of oneof_ _server_certificate_rotation_mode.

Classes

CaMode

CaMode(value)

Various Certificate Authority (CA) modes for certificate signing.

ServerCertificateRotationMode

ServerCertificateRotationMode(value)

Settings for automatic server certificate rotation.

SslMode

SslMode(value)

The SSL options for database connections.

    When this value is used, the legacy `require_ssl` flag
    must be false or cleared to avoid a conflict between the
    values of the two flags.
ENCRYPTED_ONLY (2):
    Only allow connections encrypted with SSL/TLS. For SSL
    connections to MySQL and PostgreSQL, the client certificate
    isn't verified.

    When this value is used, the legacy `require_ssl` flag
    must be false or cleared to avoid a conflict between the
    values of the two flags.
TRUSTED_CLIENT_CERTIFICATE_REQUIRED (3):
    Only allow connections encrypted with SSL/TLS and with valid
    client certificates.

    When this value is used, the legacy `require_ssl` flag
    must be true or cleared to avoid the conflict between values
    of two flags. PostgreSQL clients or users that connect using
    IAM database authentication must use either the `Cloud SQL
    Auth
    Proxy <https://cloud.google.com/sql/docs/postgres/connect-auth-proxy>`__
    or `Cloud SQL
    Connectors <https://cloud.google.com/sql/docs/postgres/connect-connectors>`__
    to enforce client identity verification.

    Only applicable to MySQL and PostgreSQL. Not applicable to
    SQL Server.