Connect to Cloud SQL

This document describes how to create a data store that connects to Cloud SQL data. You can link this data store to a Gemini Enterprise app to allow the agents to analyze your data.

To connect to Cloud SQL data using a Gemini Enterprise data store, you can use one of the following modes:

  • Federated query (recommended) [Preview]: Connect to Cloud SQL data in place without incurring egress costs for copying and moving the data. Federated query sends your query directly to Cloud SQL across all instances, databases, and tables that your identity has Identity and Access Management (IAM) permission to access, which is more efficient for analytical queries. When you use federated query mode, Knowledge Catalog is automatically enabled on the Assistant tab of your Gemini Enterprise app to give the agent tools to search for data that the user has access to and look up context.

  • Data ingestion: Copy data from a specific Cloud SQL table to the Gemini Enterprise data store. Data must be manually refreshed to reflect changes in the Cloud SQL table. This mode incurs egress costs for moving data to a new location, and existing IAM permissions aren't replicated into the data store.

Before you begin

To create a Cloud SQL data store in Gemini Enterprise, you must have the Gemini Enterprise Admin (roles/discoveryengine.agentspaceAdmin) or Discovery Engine Admin (roles/discoveryengine.admin) role. For more information, see Grant permissions to admins.

If your project is protected by a VPC Service Controls perimeter or has organization policy enforcement enabled, ensure that your organization policy allows the connector:

In addition, complete the prerequisites and configure the required Cloud SQL IAM permissions for the connector mode that you plan to use:

Federated query

To connect to Cloud SQL using federated query mode, complete the following prerequisites in the Google Cloud project that contains your Cloud SQL instance:

  1. Enable the Data API on your Cloud SQL instance:

    gcloud sql instances patch <var>INSTANCE_NAME</var> \
        --project=<var>PROJECT_ID</var> \
        --data-api-access=ALLOW_DATA_API
    
  2. Grant IAM permissions: Grant the following IAM roles in the Google Cloud project that contains your Cloud SQL instance to users who query or perform actions through the connector:

Data ingestion

To ingest data from Cloud SQL, configure the following IAM permissions:

  • Staging bucket access: When ingesting data from Cloud SQL, data is first staged to a Cloud Storage bucket. Grant the Storage Admin (roles/storage.admin) role on the intermediate Cloud Storage bucket to your Cloud SQL instance's service account (for example, p9876-abcd33f@gcp-sa-cloud-sql.).
  • Cross-project Cloud SQL access: If you are importing data from a source Google Cloud project that's different from the Google Cloud project that contains the Gemini Enterprise data store that you're creating, grant the Cloud SQL Viewer (roles/cloudsql.viewer) role on the source Cloud SQL project to the service-PROJECT_NUMBER@gcp-sa-discoveryengine. service account (where PROJECT_NUMBER is the project number of the Google Cloud project that contains the Gemini Enterprise data store).

Create a Cloud SQL data store

To create a data store that connects data from Cloud SQL to Gemini Enterprise, follow these steps:

  1. In the Google Cloud console, go to the Gemini Enterprise page.

    Gemini Enterprise

  2. Go to the Data stores page.

  3. Click Create data store.

  4. On the Source page, choose a data source for your data store. Search for "Cloud SQL" in the Select a data source search field, or find Cloud SQL in the list of First-party data sources. Select Add data source.

  5. On the Data page, select the connector mode for how to connect to your data. Select from the following tabs for further instructions based on the mode that you have chosen.

    Federated query

    1. Select Federated query (recommended). Click Continue.
    2. On the Actions page, select the Cloud SQL actions that you want to enable for your data store. You can edit these settings later. Click Continue.

    Data ingestion

    1. Select Data ingestion.
    2. Specify details about the data that you want to import. Under Import data from your Cloud SQL table, specify the following information:
      • Project ID: The Google Cloud project that contains the Cloud SQL table. This is a required field.
      • Instance ID: The Cloud SQL instance ID that contains the data you want to import. This is a required field.
      • Database ID: The Cloud SQL database ID that contains the data you want to import. This is a required field.
      • Table ID: The Cloud SQL table ID that contains the data you want to import. This is a required field.
      • Enter the Google Cloud Storage bucket location for the data. This field is required. Optionally, select Enable serverless export to use Cloud SQL serverless export. Enabling serverless export will incur additional cost. See Cloud SQL serverless export pricing.
    3. Click Continue.
  6. On the Configuration page, configure your data store settings.

    • Location of your data connector: Choose a region for where to store the metadata of your data store. You cannot change the location after the data store is created. For important information about multi-regions, see Gemini Enterprise locations.
    • Your data connector name: In the Data connector name field, enter a name for your data connector. You cannot change the name after the data connector is created. Entering a name generates a unique ID for your data connector. Optionally, in the Tag (optional) field, enter a tag for your data connector, which serves as a stable identifier for the connector across all versions.
    • Sensitive data protection policy: Select a sensitive data protection policy for your data store. The format should follow: projects/{project}/locations/{location}/contentPolicies/{policy}. You can edit this setting later.
  7. Click Create.

Now you're ready to attach your data store to a Gemini Enterprise app. In federated query mode, queries incur Cloud SQL usage costs when users run queries through the attached app; in data ingestion mode, importing data incurs Cloud SQL, Cloud Storage, and Gemini Enterprise indexing costs even before the data store is attached to an app. To learn more about these charges, see Gemini Enterprise pricing.

Next steps