A Cloud Run service in one project must connect to a Cloud SQL instance in another project. The Cloud Run service account has the Cloud SQL Client role on the Cloud SQL project but connection fails. Follow Google best practices to fix it. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable the Cloud SQL Admin API in both projects..
Why this is the answer
Enabling the Cloud SQL Admin API in both projects is crucial for cross-project Cloud SQL connectivity. Even with the Cloud SQL Client role, the Cloud Run service needs the API to be active in its own project to discover and establish a connection to the Cloud SQL instance in the other project. The Cloud SQL Admin API must also be enabled in the Cloud SQL instance's project for the instance to be manageable and discoverable. Adding the cloudsql.instances.connect permission is redundant because the Cloud SQL Client role already includes this permission. Requesting additional API quota for the Cloud SQL Auth Proxy is unlikely to resolve a connection failure unless specific quota limits are being hit, which isn't indicated. Migrating the Cloud SQL instance to the same project would resolve the issue but isn't always feasible or a best practice for managing resources across projects.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed