IpConfiguration(mapping=None, *, ignore_unknown_fields=False, **kwargs)IP Management configuration.
.. _oneof: https://proto-plus-python.readthedocs.io/en/stable/fields.html#oneofs-mutually-exclusive-fields
Attributes |
|
|---|---|
| Name | Description |
ipv4_enabled |
google.protobuf.wrappers_pb2.BoolValue
Whether the instance is assigned a public IP address or not. |
private_network |
str
The resource link for the VPC network from which the Cloud SQL instance is accessible for private IP. For example, /projects/myProject/global/networks/default. This
setting can be updated, but it cannot be removed after it is
set.
|
require_ssl |
google.protobuf.wrappers_pb2.BoolValue
Use ssl_mode instead.
Whether SSL/TLS connections over IP are enforced. If set to
false, then allow both non-SSL/non-TLS and SSL/TLS
connections. For SSL/TLS connections, the client certificate
won't be verified. If set to true, then only allow
connections encrypted with SSL/TLS and with valid client
certificates. If you want to enforce SSL/TLS without
enforcing the requirement for valid client certificates,
then use the ssl_mode flag instead of the legacy
require_ssl flag.
|
authorized_networks |
MutableSequence[google.cloud.sqladmin_v1beta4.types.AclEntry]
The list of external networks that are allowed to connect to the instance using the IP. In 'CIDR' notation, also known as 'slash' notation (for example: 157.197.200.0/24).
|
allocated_ip_range |
str
The name of the allocated ip range for the private ip Cloud SQL instance. For example: "google-managed-services-default". If set, the instance ip will be created in the allocated range. The range name must comply with `RFC 1035 |
enable_private_path_for_google_cloud_services |
google.protobuf.wrappers_pb2.BoolValue
Controls connectivity to private IP instances from Google services, such as BigQuery. |
ssl_mode |
google.cloud.sqladmin_v1beta4.types.IpConfiguration.SslMode
Specify how SSL/TLS is enforced in database connections. If you must use the require_ssl flag for backward
compatibility, then only the following value pairs are
valid:
For PostgreSQL and MySQL:
- ssl_mode=ALLOW_UNENCRYPTED_AND_ENCRYPTED and
require_ssl=false
- ssl_mode=ENCRYPTED_ONLY and require_ssl=false
- ssl_mode=TRUSTED_CLIENT_CERTIFICATE_REQUIRED and
require_ssl=true
For SQL Server:
- ssl_mode=ALLOW_UNENCRYPTED_AND_ENCRYPTED and
require_ssl=false
- ssl_mode=ENCRYPTED_ONLY and require_ssl=true
The value of ssl_mode has priority over the value of
require_ssl.
For example, for the pair ssl_mode=ENCRYPTED_ONLY and
require_ssl=false, ssl_mode=ENCRYPTED_ONLY means
accept only SSL connections, while require_ssl=false
means accept both non-SSL and SSL connections. In this case,
MySQL and PostgreSQL databases respect ssl_mode and
accepts only SSL connections.
|
psc_config |
google.cloud.sqladmin_v1beta4.types.PscConfig
PSC settings for this instance. This field is a member of oneof_ _psc_config.
|
server_ca_mode |
google.cloud.sqladmin_v1beta4.types.IpConfiguration.CaMode
Specify what type of CA is used for the server certificate. This field is a member of oneof_ _server_ca_mode.
|
custom_subject_alternative_names |
MutableSequence[str]
Optional. Custom Subject Alternative Name(SAN)s for a Cloud SQL instance. |
server_ca_pool |
str
Optional. The resource name of the server CA pool for an instance with CUSTOMER_MANAGED_CAS_CA as the
server_ca_mode. Format:
projects/{PROJECT}/locations/{REGION}/caPools/{CA_POOL_ID}
This field is a member of oneof_ _server_ca_pool.
|
server_certificate_rotation_mode |
google.cloud.sqladmin_v1beta4.types.IpConfiguration.ServerCertificateRotationMode
Optional. Controls the automatic server certificate rotation feature. This feature is disabled by default. When enabled, the server certificate will be automatically rotated during Cloud SQL scheduled maintenance or self-service maintenance updates up to six months before it expires. This setting can only be set if server_ca_mode is either GOOGLE_MANAGED_CAS_CA or CUSTOMER_MANAGED_CAS_CA. This field is a member of oneof_ _server_certificate_rotation_mode.
|
Classes
CaMode
CaMode(value)Various Certificate Authority (CA) modes for certificate signing.
ServerCertificateRotationMode
ServerCertificateRotationMode(value)Settings for automatic server certificate rotation.
SslMode
SslMode(value)The SSL options for database connections.
When this value is used, the legacy `require_ssl` flag
must be false or cleared to avoid a conflict between the
values of the two flags.
ENCRYPTED_ONLY (2):
Only allow connections encrypted with SSL/TLS. For SSL
connections to MySQL and PostgreSQL, the client certificate
isn't verified.
When this value is used, the legacy `require_ssl` flag
must be false or cleared to avoid a conflict between the
values of the two flags.
TRUSTED_CLIENT_CERTIFICATE_REQUIRED (3):
Only allow connections encrypted with SSL/TLS and with valid
client certificates.
When this value is used, the legacy `require_ssl` flag
must be true or cleared to avoid the conflict between values
of two flags. PostgreSQL clients or users that connect using
IAM database authentication must use either the `Cloud SQL
Auth
Proxy <https://cloud.google.com/sql/docs/postgres/connect-auth-proxy>`__
or `Cloud SQL
Connectors <https://cloud.google.com/sql/docs/postgres/connect-connectors>`__
to enforce client identity verification.
Only applicable to MySQL and PostgreSQL. Not applicable to
SQL Server.