gcp-cloud-sql
gcp-cloud-sql is an engineering AI skill with a core value of Provision Cloud SQL and Spanner databases. It
helps developers solve real-world problems in the engineering domain, boosting
efficiency, automating repetitive tasks, and optimizing workflows.
Provision Cloud SQL and Spanner databases. Configure high availability, backups, and security. Use when deploying managed databases on GCP.
Quick Facts
mkdir -p ./skills/gcp-cloud-sql && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/gcp-cloud-sql/SKILL.md -o ./skills/gcp-cloud-sql/SKILL.md Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).
Skill Content
# GCP Cloud SQL
Deploy and manage fully managed relational databases (PostgreSQL, MySQL, SQL Server) on Google Cloud.
When to Use
- Running production relational databases without managing replication, patching, or backups
- Migrating on-premises PostgreSQL or MySQL workloads to a managed service
- Applications requiring ACID transactions, relational schemas, and SQL query support
- Workloads that need automated high availability with regional failover
Prerequisites
- Google Cloud SDK (`gcloud`) installed and authenticated
- Cloud SQL Admin API and Service Networking API enabled
- IAM role `roles/cloudsql.admin` for full management
gcloud services enable sqladmin.googleapis.com servicenetworking.googleapis.comInstance Tiers Reference
| Tier | vCPUs | Memory | Use Case |
|------|-------|--------|----------|
| db-f1-micro | Shared | 0.6 GB | Dev/test only |
| db-g1-small | Shared | 1.7 GB | Low-traffic staging |
| db-custom-2-8192 | 2 | 8 GB | Small production |
| db-custom-4-16384 | 4 | 16 GB | Medium production |
| db-custom-8-32768 | 8 | 32 GB | High-traffic production |
Create a PostgreSQL Instance
gcloud sql instances create prod-db \
--database-version=POSTGRES_16 \
--tier=db-custom-4-16384 \
--region=us-central1 \
--availability-type=REGIONAL \
--storage-type=SSD --storage-size=100GB --storage-auto-increase \
--backup-start-time=02:00 --enable-point-in-time-recovery \
--retained-backups-count=14 \
--maintenance-window-day=SUN --maintenance-window-hour=4 \
--database-flags=max_connections=200,log_min_duration_statement=1000 \
--root-password=$(openssl rand -base64 24) \
--labels=env=production,team=backend
gcloud sql databases create myapp --instance=prod-db --charset=UTF8
gcloud sql users create appuser --instance=prod-db \
--password=$(openssl rand -base64 24)Create a MySQL Instance
gcloud sql instances create mysql-prod \
--database-version=MYSQL_8_0 \
--tier=db-custom-4-16384 --region=us-central1 \
--availability-type=REGIONAL \
--storage-type=SSD --storage-size=100GB --storage-auto-increase \
--backup-start-time=02:00 --enable-bin-log --retained-backups-count=14 \
--database-flags=slow_query_log=on,long_query_time=2,max_connections=500 \
--root-password=$(openssl rand -base64 24)Private IP Configuration
# Allocate IP range and create private connection
gcloud compute addresses create google-managed-services \
--global --purpose=VPC_PEERING --prefix-length=16 --network=my-vpc
gcloud services vpc-peerings connect \
--service=servicenetworking.googleapis.com \
--ranges=google-managed-services --network=my-vpc
# Create instance with private IP only
gcloud sql instances create private-db \
--database-version=POSTGRES_16 --tier=db-custom-2-8192 \
--region=us-central1 \
--network=projects/${PROJECT_ID}/global/networks/my-vpc \
--no-assign-ip --availability-type=REGIONAL \
--storage-type=SSD --storage-size=50GB --storage-auto-increaseRead Replicas
# Same-region replica
gcloud sql instances create prod-db-replica-1 \
--master-instance-name=prod-db --tier=db-custom-4-16384 \
--region=us-central1 --availability-type=ZONAL
# Cross-region replica for DR
gcloud sql instances create prod-db-replica-eu \
--master-instance-name=prod-db --tier=db-custom-4-16384 \
--region=europe-west1 --availability-type=ZONAL
# Promote a replica to standalone (disaster recovery)
gcloud sql instances promote-replica prod-db-replica-euBackups and Restore
gcloud sql backups create --instance=prod-db --description="pre-migration"
gcloud sql backups list --instance=prod-db
# Point-in-time recovery
gcloud sql instances clone prod-db prod-db-pitr \
--point-in-time="2026-03-23T10:00:00Z"
# Export / import
gcloud sql export sql prod-db gs://my-bucket/export.sql.gz --database=myapp
gcloud sql import sql prod-db gs://my-bucket/export.sql.gz --database=myappCloud SQL Auth
🎯 Best For
- Security auditors
- DevSecOps teams
- Compliance officers
- Claude users
- AI users
💡 Use Cases
- Auditing dependencies for known CVEs
- Scanning API endpoints for auth gaps
- Using gcp-cloud-sql in daily workflow
- Automating repetitive engineering tasks
📖 How to Use This Skill
- 1
Install the Skill
Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.
- 2
Load into Your AI Assistant
Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.
- 3
Apply gcp-cloud-sql to Your Work
Provide context for your task — paste source material, describe your audience, or share existing work to guide the AI.
- 4
Review and Refine
Edit the AI output for accuracy, tone, and completeness. Add human insight where the AI lacks context.
❓ Frequently Asked Questions
Can this replace a dedicated SAST tool?
AI-based security review is complementary to SAST tools. Use it as a first-pass filter, not a replacement.
How do I install gcp-cloud-sql?
Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/gcp-cloud-sql/SKILL.md, ready to use.
Can I customize this skill for my team?
Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.
⚠️ Common Mistakes to Avoid
Only scanning surface-level issues
Deep security review requires understanding your app architecture, not just regex patterns.
Not reading the full skill
Skills contain important context and edge cases beyond the quick start.