Repository navigation
Permission denied when trying to query mysql with unix socket and credential file. #1403
Description
Activity
- addedtype: bugError or flaw in code with unintended results or allowing sub-optimal usage patterns.Error or flaw in code with unintended results or allowing sub-optimal usage patterns.
on Sep 12, 2022 - addedpriority: p1Important issue which blocks shipping the next release. Will be fixed prior to next release.Important issue which blocks shipping the next release. Will be fixed prior to next release.
on Sep 12, 2022 Let me see if I can reproduce this and report back.
- addedtype: questionRequest for information or clarification.Request for information or clarification.and removedtype: bugError or flaw in code with unintended results or allowing sub-optimal usage patterns.Error or flaw in code with unintended results or allowing sub-optimal usage patterns.
on Sep 12, 2022 In addition to our automated test (source), I tried to connect to my MySQL instance with application default credentials and with a credential file:
# in one shell with application default credentials $ cloud-sql-proxy -u /cloudsql/ project:region:instance # in another shell $ mysql --version mysql Ver 15.1 Distrib 10.6.9-MariaDB, for debian-linux-gnu (x86_64) using EditLine wrapper $ mysql -S /cloudsql/project:region:instance --user=test-user test-db --passwordand
# in one shell with application default credentials $ cloud-sql-proxy -u /cloudsql/ project:region:instance -c /my/secret/key.json # in another shell $ mysql -S /cloudsql/project:region:instance --user=test-user test-db --passwordIn both cases the connection worked. So, could you double check that your instance name is correct?
@enocom Yeah the instance name is correct, we used the same configuration to reproduce this issue, we just changed the version of cloud-sql-proxy and the start command:
# For version v1.31.2: cloud-sql-proxy -dir=/cloud-sql/ -instances=PROJECT_NAME:us-central1:INSTANCE_NAME -credential_file=/cloud-sql-service-account # For version 2.0.0-preview.1: cloud-sql-proxy -u /cloud-sql/ -c /cloud-sql-service-account PROJECT_NAME:us-central1:INSTANCE_NAMEWhat client are you using to query MySQL?
@enocom We use supervisor for the startup processes, the main application process was started with a different user than the cloud-sql-proxy, the previous version creates the socket with write access permission for groups and others, the latest version doesn't do this:
For version v1.31.2: 3280871 0 srwxrwxrwx 1 root root 0 Sep 12 21:47 PROJECT_NAME:us-central1:INSTANCE_NAME # For version 2.0.0-preview.1: 1449959 0 srwxr-xr-x 1 root root 0 Sep 12 20:49 PROJECT_NAME:us-central1:INSTANCE_NAMEYep that’s the problem. OK. I’ll fix it. Thanks for helping debug.
- addedtype: bugError or flaw in code with unintended results or allowing sub-optimal usage patterns.Error or flaw in code with unintended results or allowing sub-optimal usage patterns.and removedtype: questionRequest for information or clarification.Request for information or clarification.
on Sep 12, 2022 - added a commit that references this issue
on Sep 13, 2022 - added a commit that references this issue
on Sep 13, 2022
We upgrading to the last version of the cloud-sql-proxy, but we can't get it to work right, when we trying to query to mysql instance get the [SQLSTATE[HY000] [2002] Permission denied] error.
Bug Description
We use the latest version of cloud-sql-proxy installed like this:
for start the instance we use credential file, we also create a user with 'cloudsqlproxy~%' hostname to allow connect to the instance.
We have a successfully start like this:
But when the application tries to query mysql for any information using the unix socket, we get a error:
We tried with oldest cloud-sql-proxy versions and this problem doesn't happens, like:
Environment
./cloud-sql-proxy --version): cloud-sql-proxy version 2.0.0-preview.1