Skip to content

GCP.SQL reference

Source: src/GCP/SQL/Backup.ts

An on-demand Cloud SQL backup (projects/{project}/backups/{backup}).

The create API assigns the backup id. Alchemy stamps ownership into description so list / pnpm nuke:gcp can find leaked rows. Changing instance or location replaces the backup. Description, ttlDays, and expiryTime are create-time for on-demand backups; FINAL backups can update description and expiration in place.

On-demand backup of a Cloud SQL instance

const instance = yield* GCP.SQL.Instance("AppDb", {
tier: "db-f1-micro",
backupEnabled: true,
});
const backup = yield* GCP.SQL.Backup("Nightly", {
instance: instance.instanceName,
});

Description, location, and TTL

const backup = yield* GCP.SQL.Backup("Nightly", {
instance: instance.instanceName,
location: "us",
description: "pre-release",
ttlDays: 7,
});

Source: src/GCP/SQL/BackupRun.ts

An on-demand Cloud SQL backup run (projects/{project}/instances/{instance}/backupRuns/{id}).

Insert assigns the run id. Alchemy stamps ownership into description so list / pnpm nuke:gcp can find leaked rows. Changing instance or location replaces the run. Description is create-only — backup runs have no update API.

On-demand backup of a Cloud SQL instance

const instance = yield* GCP.SQL.Instance("AppDb", {
tier: "db-f1-micro",
backupEnabled: true,
});
const backup = yield* GCP.SQL.BackupRun("Nightly", {
instance: instance.instanceName,
});

Description and location

const backup = yield* GCP.SQL.BackupRun("Nightly", {
instance: instance.instanceName,
location: "us",
description: "pre-release",
});

Source: src/GCP/SQL/Connect.ts

Runtime binding that connects a Cloud Run service to a Cloud SQL instance over the Cloud SQL Unix socket — no public IP allow-list, no VPC.

Binding it at init grants roles/cloudsql.client on the project under an IAM Condition naming only this instance, mounts the instance as the service’s cloudsql volume (the socket appears at /cloudsql/{connectionName}), and grants roles/secretmanager.secretAccessor on the password secret. The returned Effect reads the password and resolves a ConnectionInfo on each execution; no socket is opened. Provide ConnectHttp. Cloud Run services only.

const connect = yield* GCP.SQL.Connect(instance, {
database,
user,
passwordSecret,
});
const db = yield* Drizzle.Postgres(
connect.pipe(Effect.map((info) => info.url)),
);
// …provided with Effect.provide(GCP.SQL.ConnectHttp)

Source: src/GCP/SQL/ConnectHttp.ts Kind: Layer · Provides: GCP.SQL.Connect

HTTP implementation of Connect: reads the password through GCP.SecretManager.ReadSecret and connects over the Cloud Run cloudsql socket volume.

Source: src/GCP/SQL/Database.ts

A logical database inside a Cloud SQL instance.

Cloud SQL databases have no labels field. list enumerates non-system databases on alchemy-labeled instances so pnpm nuke:gcp can find leaked rows without dropping mysql / postgres / template1.

Changing instance or databaseName replaces the database. charset and collation update in place where the engine allows.

Generated name on a Cloud SQL instance

const instance = yield* GCP.SQL.Instance("AppDb", {
tier: "db-f1-micro",
backupEnabled: false,
});
const database = yield* GCP.SQL.Database("App", {
instance: instance.instanceName,
});

Explicit name, charset, and collation

const database = yield* GCP.SQL.Database("App", {
instance: instance.instanceName,
databaseName: "app_production",
charset: "utf8mb4",
collation: "utf8mb4_unicode_ci",
});

Source: src/GCP/SQL/ExecuteSql.ts

Runtime binding for Cloud SQL instances.executeSql.

Bind this operation to an Instance in a Function/Action init phase. Provide ExecuteSqlHttp. The instance must allow the Execute SQL API (dataApiAccess: true).

Grants roles/cloudsql.instanceUser (cloudsql.instances.executeSql, get, login) on the project under an IAM Condition naming only this instance.

const executeSql = yield* GCP.SQL.ExecuteSql(db);
const result = yield* executeSql({
body: {
sqlStatement: "SELECT 1",
database: "mysql",
user: "root",
},
});

Source: src/GCP/SQL/ExecuteSqlHttp.ts Kind: Layer · Provides: GCP.SQL.ExecuteSql

HTTP implementation of ExecuteSql.

Source: src/GCP/SQL/GetInstance.ts

Runtime binding for Cloud SQL instances.get.

Bind this operation to an Instance in a Function/Action init phase. Provide GetInstanceHttp.

Grants roles/cloudsql.viewer on the project under an IAM Condition naming only this instance (Cloud SQL has no instance-level IAM policy).

const getInstance = yield* GCP.SQL.GetInstance(db);
const live = yield* getInstance();

Source: src/GCP/SQL/GetInstanceHttp.ts Kind: Layer · Provides: GCP.SQL.GetInstance

HTTP implementation of GetInstance.

Source: src/GCP/SQL/GetUser.ts

Runtime binding for Cloud SQL users.get.

Bind this operation to a User in a Function/Action init phase. Provide GetUserHttp.

Grants roles/cloudsql.viewer on the project, unconditioned: Cloud SQL has no instance-level IAM policy, cloudsql.users.get is not matched by an IAM Condition on the instance name, and no narrower predefined role carries it.

const getUser = yield* GCP.SQL.GetUser(appUser);
const live = yield* getUser();

Source: src/GCP/SQL/GetUserHttp.ts Kind: Layer · Provides: GCP.SQL.GetUser

HTTP implementation of GetUser.

Source: src/GCP/SQL/Instance.ts

A Cloud SQL database instance.

Changing instanceName, region, or databaseVersion replaces the instance. Provisioning typically takes several minutes (often 5–15).

Generated name, MySQL 8.0 shared-core

const db = yield* GCP.SQL.Instance("AppDb", {});

Explicit name, labels, and backups off

const db = yield* GCP.SQL.Instance("AppDb", {
instanceName: "app-db",
region: "us-central1",
databaseVersion: "MYSQL_8_0",
tier: "db-f1-micro",
labels: { env: "prod" },
backupEnabled: false,
deletionProtectionEnabled: false,
});
const db = yield* GCP.SQL.Instance("AppDb", {
databaseVersion: "POSTGRES_15",
rootPassword: "change-me",
tier: "db-f1-micro",
});

Source: src/GCP/SQL/SslCert.ts

A Cloud SQL client SSL certificate.

Insert returns the private key once; it is stored on the resource and cannot be recovered from the API later. Certificates have no labels field. list enumerates certs on alchemy-labeled instances so pnpm nuke:gcp can find leaked rows. Changing instance or commonName replaces the certificate. The new certificate is not usable until the instance is restarted.

Generated common name on a Cloud SQL instance

const instance = yield* GCP.SQL.Instance("AppDb", {
tier: "db-f1-micro",
backupEnabled: false,
});
const cert = yield* GCP.SQL.SslCert("Client", {
instance: instance.instanceName,
});

Explicit common name

const cert = yield* GCP.SQL.SslCert("Client", {
instance: instance.instanceName,
commonName: "app-client",
});

Source: src/GCP/SQL/User.ts

A database user on a Cloud SQL instance.

Cloud SQL users have no labels field. list enumerates non-system users on alchemy-labeled instances so pnpm nuke:gcp can find leaked rows without dropping root / postgres / cloudsqladmin.

Changing instance, userName, host, or type replaces the user. password, databaseRoles, and passwordPolicy update in place.

Generated name on a Cloud SQL instance

const instance = yield* GCP.SQL.Instance("AppDb", {
tier: "db-f1-micro",
backupEnabled: false,
});
const appUser = yield* GCP.SQL.User("AppUser", {
instance: instance.instanceName,
password: "change-me",
});

Explicit MySQL user and host

const appUser = yield* GCP.SQL.User("AppUser", {
instance: instance.instanceName,
userName: "app",
host: "%",
password: "change-me",
type: "BUILT_IN",
});
const iamUser = yield* GCP.SQL.User("IamUser", {
instance: instance.instanceName,
userName: "alice@example.com",
type: "CLOUD_IAM_USER",
});