GoogleCloudPlatform / GoogleCloudPlatform/deploymentmanager-samples

CloudSQL Import - Replace the need to share the dump file publicly

Open
#458 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Jinja
Stars
951
Forks
700
PR merge metrics
No merged PRs in 30d

Description

Hello,

First, thanks for those samples, it helps me a lot everyday ! 😄

In the Import CloudSQL sample, one of the prerequisites is to publicly share the SQL Dump. I think that this could be a bad practice and leads to security flaws ( https://github.com/GoogleCloudPlatform/deploymentmanager-samples/tree/master/examples/v2/cloudsql_import#prerequsites ).

Maybe, we can change the orchestration of the DM script this way :
* Create the Cloud SQL Instance
* Create the GCS bucket & add the dump in it (from SourceRepo for example)
* Add the CloudSQL service account with role `Storage Object Viewer` permission to the GCS bucket
* Make the actual import

I can do the actual PR if you want so 😃

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.