Alloydb Basics

作者 google55b4e13eba6d無授權條款21K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Manages clusters, instances, and backups for AlloyDB for PostgreSQL, and integrates with AlloyDB Model Context Protocol (MCP) tools for automated database operations. Use when creating, configuring, or administering AlloyDB databases. Do NOT use for general PostgreSQL instances (e.g. Cloud SQL) or other GCP databases.

精選僅含說明DevOps & Cloud
AI 產生的概覽

指導 AlloyDB for PostgreSQL 叢集、執行個體、備份、連線與 IAM 安全的管理。

功能
此技能為 AlloyDB for PostgreSQL 的管理提供參考指引,涵蓋叢集與執行個體建立、備份、擴縮、連線方式以及 IAM 安全。它會指向數個補充參考檔案,涉及 CLI 用法、核心概念、基礎架構即程式碼、MCP 工具設定以及 IAM 與安全。它也規定代理在說明這些主題時應遵循的指示,例如優先採用私有 IP 和 IAM 資料庫驗證。其產出是說明性指引與指令範例,而非檔案或程式碼成品。
適用情境
適用於建立、設定或管理 AlloyDB for PostgreSQL 資料庫時,包括叢集、執行個體、備份和連線。不適用於一般 PostgreSQL 執行個體(例如 Cloud SQL)或其他 Google Cloud 資料庫。
執行需求
需要安裝並完成驗證的 Google Cloud SDK(gcloud),以及 AlloyDB API 的存取權。部分引用內容涉及 Terraform、Kubernetes Config Connector、AlloyDB Auth Proxy、語言連接器和 AlloyDB MCP 工具。此技能不附帶指令碼,僅為說明與參考文件。

AlloyDB Basics

AlloyDB for PostgreSQL is a managed, PostgreSQL-compatible database service designed for enterprise-grade performance and availability. It utilizes a disaggregated compute and storage architecture to scale resources independently. It also provides AlloyDB AI, a collection of features that includes AI-powered search (vector, hybrid search, and AI functions), natural language capabilities, conversational analytics, and inference features like forecasting and model endpoint management to help developers build AI apps faster.

Quick Start

Before you begin, ensure you have the Google Cloud SDK installed and authenticated (gcloud auth login).

  1. Enable the AlloyDB API:

    bash
    gcloud services enable alloydb.googleapis.com --quiet
  2. Create a Cluster:

    bash
    gcloud alloydb clusters create my-cluster --region=us-central1 \    --password=my-password --network=my-vpc --quiet

    For production environments, always use IAM database authentication instead of passwords. If configuration constraint requires passwords, store them securely using Secret Manager.

  3. Create a Primary Instance:

    bash
    gcloud alloydb instances create my-primary --cluster=my-cluster \    --region=us-central1 --instance-type=PRIMARY --cpu-count=2 --quiet

Reference Directory

Read these supplementary files when specific context or detailed steps are required for a task:

  • To understand architecture, regional availability, connectivity (Private IP, Public IP, PSA, PSC), backups, point-in-time recovery, scaling (vertical and horizontal), or Quota management: read Core Concepts [blocked].
  • To manage clusters, instances, scaling, or backups via the CLI: read CLI Usage [blocked].
  • To configure AlloyDB remote MCP tools: read MCP Usage [blocked].
  • To deploy AlloyDB using Terraform or Kubernetes Config Connector (KCC): read Infrastructure as Code [blocked].
  • To configure IAM roles, service usage roles, service agents, database users/privileges, or network security (public IP authorization, Auth Proxy sidecar configuration): read IAM & Security [blocked].

If you need product information not found in these references, use the developer_knowledge:search_documents tool (see Developer Knowledge MCP setup for installation instructions).

Directives for Agents

Agents MUST adhere to the following directives when answering queries related to AlloyDB:

  • Provide Multiple Methods: When explaining how to perform administrative tasks (like backups, scaling, or database user creation), always provide both the Google Cloud Console steps and the gcloud CLI commands if both are available in the reference documents.
  • Prioritize Private IP: Recommend Private IP (especially PSC) over Public IP for connections to ensure traffic remains within the Google Cloud network and reduces exposure.
  • Require Serverless Connectors: Verify and state that Serverless VPC Access or Direct VPC Egress is required when connecting from Cloud Run to Private IP.
  • Enforce Connectors: Always direct users to configure the AlloyDB Auth Proxy (running as a sidecar or locally) or language connectors rather than direct TCP connections.
  • Block Open Public Access: If Public IP is configured, warn against and reject designs with 0.0.0.0/0 in Authorized Networks as this exposes the database to the entire internet.
  • Default to IAM Database Authentication: Suggest IAM database authentication and the alloydbiamuser database role instead of static database passwords.
  • Enforce Least Privilege Connection: When explaining connection roles, explicitly state that roles/alloydb.client should be used to adhere to the principle of least privilege, and warn against using broader roles like roles/alloydb.admin for connections.
  • Mention All Creation Methods: When describing how to create IAM database users, explicitly state that they can be created using the Google Cloud Console, the gcloud CLI, and the AlloyDB API.
  • Explain Private IP Options: When explaining Private IP connectivity, always explicitly mention and describe both Private Services Access (PSA) and Private Service Connect (PSC) as the supported methods, recommending PSC for new deployments.
  • Compare Direct Connections: Explicitly explain that direct connections (connecting directly to the private IP without connectors) are possible but discouraged, and compare their security (lack of IAM/mTLS) to secure methods like the AlloyDB Auth Proxy or language connectors.
  • Enforce SQL Alone Warning: When explaining IAM user creation, you MUST explicitly state that "IAM database users cannot be created using standard SQL alone" and must be registered via the control plane first.
  • Enforce Roles and Privileges Terminology: When explaining database object access, you MUST explicitly state that "standard PostgreSQL roles and privileges" apply, using both terms.
  • Explain Backup Lifecycle: When explaining backups, always explicitly state that discrete backups exist independently of the source cluster and remain active even if the source cluster is deleted.
  • Recommend Connectors for Public IP: Explicitly state that secure connection methods (AlloyDB Auth Proxy, Language Connectors) are especially recommended for connections over Public IP.
  • Mention Autoscaling: When explaining read pool scaling, always explicitly mention the option of using read pool autoscaling and state that it is in Preview.

Supporting Links

來源與署名

來源:google/skills位於skills/cloud/alloydb-basics提交55b4e13

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 google/skills 的技能

Dpop Adoption

google

精選

指導為 Google OAuth 平台實作 OAuth 2.0 DPoP(RFC 9449)傳送方約束的更新權杖。

Security21K今天更新

Finding Google Skills

google

精選

Google platform decision and setup guidance, loaded on demand from Google's skill catalog. Use when a developer is choosing or setting up part of their stack, such as where to run a service, a database, storage, messaging, authentication, analytics, ads, or AI model serving, and a Google product is a reasonable candidate - whether or not a vendor is named - or when a request names a Google product or API. Brings in the matching Google skill so the answer can weigh Google options, their trade-offs, and when they are not the right fit. Skip when the stack is already settled on another provider and no Google product is named, or the task involves no platform choice.

待分類21K今天更新

Spanner Basics

google

精選

指導 Google Cloud Spanner 的執行個體與資料庫管理、結構定義設計、查詢與效能診斷。

Data & Analytics21K今天更新

Secops Triage

google

精選

引導 SOC 分析師對 Google SecOps 安全警示進行分診,從調查到結案或升級。

Security21K今天更新

Secops Investigate

google

精選

指導 SOC 分析師在 Google SecOps 中使用 UDM 查詢與時間軸進行深入的安全事件與實體調查。

Security21K今天更新

Secops Hunt

google

精選

指導在 Google SecOps 中使用 UDM 查詢、IoC 回溯、普遍性與異常分析進行主動威脅狩獵。

Security21K今天更新