alloydb-basics
Manages clusters, instances, and backups for AlloyDB for PostgreSQL, and integrates with AlloyDB Model Context Protocol (MCP) tools for automated database operations. Use when creating, configuring, or administering AlloyDB databases. Do NOT use for general PostgreSQL instances (e.g. Cloud SQL) or o
- 0
- Installs
- —
- Rating
- —
- Success rate
- 6
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 d588434deec603af… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
AlloyDB Basics
AlloyDB for PostgreSQL is a managed, PostgreSQL-compatible database service designed for enterprise-grade performance and availability. It utilizes a disaggregated compute and storage architecture to scale resources independently. It also provides AlloyDB AI, a collection of features that includes AI-powered search (vector, hybrid search, and AI functions), natural language capabilities, conversational analytics, and inference features like forecasting and model endpoint management to help developers build AI apps faster.
Quick Start
Before you begin, ensure you have the Google Cloud SDK installed and authenticated (gcloud auth login).
-
Enable the AlloyDB API:
gcloud services enable alloydb.googleapis.com --quiet -
Create a Cluster:
gcloud alloydb clusters create my-cluster --region=us-central1 \ --password=my-password --network=my-vpc --quietFor production environments, always use IAM database authentication instead of passwords. If configuration constraint requires passwords, store them securely using Secret Manager.
-
Create a Primary Instance:
gcloud alloydb instances create my-primary --cluster=my-cluster \ --region=us-central1 --instance-type=PRIMARY --cpu-count=2 --quiet
Reference Directory
Read these supplementary files when specific context or detailed steps are required for a task:
- To understand architecture, regional availability, connectivity (Private IP, Public IP, PSA, PSC), backups, point-in-time recovery, scaling (vertical and horizontal), or Quota management: read Core Concepts.
- To manage clusters, instances, scaling, or backups via the CLI: read CLI Usage.
- To configure AlloyDB remote MCP tools: read MCP Usage.
- To deploy AlloyDB using Terraform or Kubernetes Config Connector (KCC): read Infrastructure as Code.
- To configure IAM roles, service usage roles, service agents, database users/privileges, or network security (public IP authorization, Auth Proxy sidecar configuration): read IAM & Security.
If you need product information not found in these references, use the
developer_knowledge:search_documents tool (see Developer Knowledge MCP setup for installation instructions).
Directives for Agents
Agents MUST adhere to the following directives when answering queries related to AlloyDB:
- Provide Multiple Methods: When explaining how to perform administrative
tasks (like backups, scaling, or database user creation), always provide
both the Google Cloud Console steps and the
gcloudCLI commands if both are available in the reference documents. - Prioritize Private IP: Recommend Private IP (especially PSC) over Public IP for connections to ensure traffic remains within the Google Cloud network and reduces exposure.
- Require Serverless Connectors: Verify and state that Serverless VPC Access or Direct VPC Egress is required when connecting from Cloud Run to Private IP.
- Enforce Connectors: Always direct users to configure the AlloyDB Auth Proxy (running as a sidecar or locally) or language connectors rather than direct TCP connections.
- Block Open Public Access: If Public IP is configured, warn against and
reject designs with
0.0.0.0/0in Authorized Networks as this exposes the database to the entire internet. - Default to IAM Database Authentication: Suggest IAM database
authentication and the
alloydbiamuserdatabase role instead of static database passwords. - Enforce Least Privilege Connection: When explaining connection roles,
explicitly state that
roles/alloydb.clientshould be used to adhere to the principle of least privilege, and warn against using broader roles likeroles/alloydb.adminfor connections. - Mention All Creation Methods: When describing how to create IAM database
users, explicitly state that they can be created using the Google Cloud
Console, the
gcloudCLI, and the AlloyDB API. - Explain Private IP Options: When explaining Private IP connectivity, always explicitly mention and describe both Private Services Access (PSA) and Private Service Connect (PSC) as the supported methods, recommending PSC for new deployments.
- Compare Direct Connections: Explicitly explain that direct connections (connecting directly to the private IP without connectors) are possible but discouraged, and compare their security (lack of IAM/mTLS) to secure methods like the AlloyDB Auth Proxy or language connectors.
- Enforce SQL Alone Warning: When explaining IAM user creation, you MUST explicitly state that "IAM database users cannot be created using standard SQL alone" and must be registered via the control plane first.
- Enforce Roles and Privileges Terminology: When explaining database object access, you MUST explicitly state that "standard PostgreSQL roles and privileges" apply, using both terms.
- Explain Backup Lifecycle: When explaining backups, always explicitly state that discrete backups exist independently of the source cluster and remain active even if the source cluster is deleted.
- Recommend Connectors for Public IP: Explicitly state that secure connection methods (AlloyDB Auth Proxy, Language Connectors) are especially recommended for connections over Public IP.
- Mention Autoscaling: When explaining read pool scaling, always explicitly mention the option of using read pool autoscaling and state that it is in Preview.
Supporting Links
Files
6- SKILL.md
8ea72d9ee16.8 KB - references/cli-usage.md
5606cb58cc3.5 KB - references/core-concepts.md
82014d53755.4 KB - references/iac-usage.md
ba367fb7a63.3 KB - references/iam-security.md
b6386e215a4.2 KB - references/mcp-usage.md
59ce6e35341.2 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from google/skills8
Configures best-practice alerting policies for AI agents using OpenTelemetry (OTel) metrics, generating output as Terraform (.tf) configuration files. Use when analyzing, writing, or deploying alerting policies to monitor agent latency, error rates, token usage, and quality metrics. Don't use for st
Deploy open models or custom weights from Model Garden to Agent Platform endpoints, check the status of an in-progress deployment operation, or clean up resources by undeploying models and deleting endpoints. Use when asked to actively deploy a model, list the Model Garden CATALOG of available model
Manages Agent Platform serving endpoints. Use when you need to create, list, describe, update, or delete serving endpoints for model deployment on Agent Platform. Also use when troubleshooting endpoint permission, quota, or resource busy errors. Don't use for deploying models to endpoints or for run
Measures and improves the quality of AI models and agents on Google Cloud using the Eval Quality Flywheel methodology. Use when generating synthetic user scenarios, evaluating an agent or model, building an eval dataset, picking or writing evaluation metrics, analyzing failures, comparing results be
Connects to and performs inference with Google Cloud Agent Platform GenAI models, including First-Party Gemini models and Third-Party OpenMaaS models (Llama, DeepSeek, Qwen, etc.). Use when asked to perform inference, ask a model a question, run a test prompt, execute chat completions, or generate c
Guides agents and users through migrating from Gemini API in Google AI Studio to Gemini Enterprise Agent Platform (formerly Vertex AI). Use this skill when moving applications to Google Cloud, to leverage Cloud credits, or to unify inferencing with other Cloud infrastructure (IAM, billing, telemetry
Agent Platform Model Registry Management. Use when you need to upload, list, describe, update, or delete machine learning models (and their versions) in the Agent Platform Model Registry. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform models.
Manages and orchestrates prompts in Agent Platform. Use when you need to create, list, retrieve, version, or delete managed prompts in Agent Platform. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform prompts.
Related database skillsscan passed
Prisma ORM patterns for TypeScript backends — schema design, query optimization, transactions, pagination, and critical traps like updateMany returning count not records, $transaction timeouts, migrate dev resetting the DB, @updatedAt skipped on bulk writes, and serverless connection exhaustion. Use
Use when the user wants to provision infrastructure or third-party services using Stripe Projects. Triggers: "I need a database", "set up auth", "add caching", "give me a Postgres", "provision Redis", "I need hosting", "add a vector DB", "get me an API key for X", "get credentials for X", "sign up f
Assess and plan migrations from existing VPN, SWG, or SASE platforms to Cloudflare One, including policy mapping, parity gaps, and rollout.
Manages deprecation and migration. Use when removing old systems, APIs, or features. Use when migrating users from one implementation to another. Use when migrating a database schema in production, such as renaming or dropping a column without downtime (expand/contract). Use when deciding whether to
Builds and deploys Firebase SQL Connect (aka Firebase Data Connect) backends with PostgreSQL securely. Use when designing schemas with tables and relations, writing authorized queries and mutations, configuring real-time data updates, or generating type-safe SDKs. Use when you need a relational data
Amazon Redshift is NOT PostgreSQL — corrects PostgreSQL-derived LLM mistakes; covers Redshift-specific SQL, DDL, COPY/UNLOAD, system views, metadata discovery, and operational patterns. Applies ONLY when the task is about Redshift itself (cluster, Serverless workgroup, or Redshift SQL). Pushes back