Agent skill

Cloud Run Job Cloudsql Setup

by divinevideo in divinevideo/divine-mobile

Set up Cloud Run Jobs with CloudSQL connection. An agent skill from divinevideo/divine-mobile.

MPL-2.0Auto-check passedDatabases

Install Cloud Run Job Cloudsql Setup

skills CLI
$ npx skills add divinevideo/divine-mobile --skill cloud-run-job-cloudsql-setup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install divinevideo/divine-mobile cloud-run-job-cloudsql-setup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/cloud-run-job-cloudsql-setup .claude/skills/cloud-run-job-cloudsql-setup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloud-run-job-cloudsql-setup
GitHub stars
265
Token cost
~1.4k tokens
SKILL.md length
317 words
Files
1
Skills in repo
103
Repo updated
First seen
Licence
MPL-2.0

At a glance

Set up Cloud Run Jobs with CloudSQL connection. An agent skill from divinevideo/divine-mobile.

  • Works in 5 steps: Create the Job with Correct Flags → Configure Socket Path in App → Grant Required IAM Permissions → …
  • Deploying long-running batch jobs that need database access
  • SKILL.md covers Problem, Context / Trigger Conditions, Solution and Verification, plus 3 more sections
  • Calls gcloud; needs POSTGRES_PASSWORD

What it does

Cloud Run Job Cloudsql Setup is an agent skill from divinevideo/divine-mobile. Set up Cloud Run Jobs with CloudSQL connection. Use when: (1) Deploying long-running batch jobs that need database access, (2) Errors like "Cloud SQL Proxy not found" in container, (3) "password authentication failed" despite correct credentials, (4) Job creation fails with permission errors. Covers socket path configuration, IAM permissions, and common gotchas.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases, covering Background jobs and SQL. It works with Cloud Run, SQL and PostgreSQL. The licence is MPL-2.0.

When your agent uses it

  • Deploying long-running batch jobs that need database access
  • Errors like Cloud SQL Proxy not found in container
  • Password authentication failed despite correct credentials
  • Job creation fails with permission errors

Example prompts

  • “Cloud SQL Proxy not found”
  • “password authentication failed”
  • “/cloud-run-job-cloudsql-setup”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Create the Job with Correct Flags
  2. Configure Socket Path in App
  3. Grant Required IAM Permissions
  4. Don't Auto-Start Proxy in Container
  5. Create Secrets Without Newlines

What it can do on your machine

Read from SKILL.md and the folder at commit 8d5fbf2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • POSTGRES_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloud Run Job Cloudsql Setup loads about 1.4k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 317 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from divinevideo/divine-mobile at commit 8d5fbf2, republished under its MPL-2.0 licence (© divinevideo). 317 words, ~1,370 tokens.

Download SKILL.mdSave it as .claude/skills/cloud-run-job-cloudsql-setup/SKILL.md (or your agent's skills folder).
name
cloud-run-job-cloudsql-setup
description
Set up Cloud Run Jobs with CloudSQL connection. Use when: (1) Deploying long-running batch jobs that need database access, (2) Errors like "Cloud SQL Proxy not found" in container, (3) "password authentication failed" despite correct credentials, (4) Job creation fails with permission errors. Covers socket path configuration, IAM permissions, and common gotchas.
author
Claude Code
version
1.0.0
date
2026-01-31

Cloud Run Job with CloudSQL Setup

Problem

Setting up Cloud Run Jobs to connect to CloudSQL involves multiple non-obvious steps and gotchas that cause confusing errors. The main issues are:

  1. Wrong gcloud flags for CloudSQL connection
  2. Incorrect socket path configuration
  3. Missing IAM permissions
  4. App code trying to start proxy when Cloud Run already provides it

Context / Trigger Conditions

  • Error: "unrecognized arguments: --add-cloudsql-instances" (wrong flag name)
  • Error: "Cloud SQL Proxy not found" (app trying to start proxy in container)
  • Error: "password authentication failed" (socket path misconfigured or newline in secret)
  • Error: "Permission denied on secret" (missing secretAccessor role)
  • Error: "does not have permission to access namespaces" (missing cloudsql.client role)

Solution

1. Create the Job with Correct Flags
bash
gcloud run jobs create my-job \
  --region=us-central1 \
  --image=gcr.io/PROJECT/IMAGE:latest \
  --set-cloudsql-instances=PROJECT:REGION:INSTANCE \  # NOT --add-cloudsql-instances
  --set-env-vars="POSTGRES_SOCKET_PATH=/cloudsql/PROJECT:REGION:INSTANCE,POSTGRES_DATABASE=mydb,POSTGRES_USER=myuser" \
  --set-secrets="POSTGRES_PASSWORD=my-secret:latest"

Key: Use --set-cloudsql-instances NOT --add-cloudsql-instances

2. Configure Socket Path in App

For Node.js with pg library:

typescript
// Use socketPath for unix socket, not host
if (config.socketPath) {
  pool = new Pool({
    host: config.socketPath,  // e.g., "/cloudsql/project:region:instance"
    database: config.database,
    user: config.user,
    password: config.password,
  });
}

Environment variable: POSTGRES_SOCKET_PATH=/cloudsql/PROJECT:REGION:INSTANCE

3. Grant Required IAM Permissions
bash
# Secret access
gcloud secrets add-iam-policy-binding my-secret \
  --member="serviceAccount:PROJECT_NUMBER-compute@developer.gserviceaccount.com" \
  --role="roles/secretmanager.secretAccessor"

# CloudSQL connection
gcloud projects add-iam-policy-binding PROJECT_ID \
  --member="serviceAccount:PROJECT_NUMBER-compute@developer.gserviceaccount.com" \
  --role="roles/cloudsql.client"
4. Don't Auto-Start Proxy in Container

Cloud Run automatically provides the CloudSQL proxy socket. If your app has logic to start the proxy, skip it when a socket path is configured:

typescript
// Skip proxy start if socketPath provided (Cloud Run handles it)
if (!config.socketPath && config.host === "localhost") {
  await ensureCloudSqlProxy();  // Only for local development
}
5. Create Secrets Without Newlines
bash
# WRONG - adds trailing newline
gcloud secrets create my-secret --data-file=- <<< "password"

# CORRECT - no trailing newline
echo -n "password" | gcloud secrets create my-secret --data-file=-

Verification

bash
# Check job config
gcloud run jobs describe my-job --region=us-central1

# Execute and check logs
gcloud run jobs execute my-job --region=us-central1
gcloud run jobs logs read my-job --region=us-central1 --limit=50

Example: Complete Setup

bash
# 1. Create secrets (no newlines!)
echo -n "dbpassword123" | gcloud secrets create db-password --data-file=-

# 2. Grant permissions
gcloud secrets add-iam-policy-binding db-password \
  --member="serviceAccount:123456789-compute@developer.gserviceaccount.com" \
  --role="roles/secretmanager.secretAccessor"

# 3. Create job
gcloud run jobs create my-processor \
  --region=us-central1 \
  --image=gcr.io/my-project/processor:latest \
  --memory=4Gi \
  --cpu=2 \
  --task-timeout=86400s \
  --max-retries=3 \
  --set-cloudsql-instances=my-project:us-central1:my-instance \
  --set-env-vars="POSTGRES_SOCKET_PATH=/cloudsql/my-project:us-central1:my-instance,POSTGRES_DATABASE=mydb,POSTGRES_USER=myuser" \
  --set-secrets="POSTGRES_PASSWORD=db-password:latest"

# 4. Execute
gcloud run jobs execute my-processor --region=us-central1

Notes

  • Cloud Run Job timeout max is 86400s (24 hours)
  • The socket path format is /cloudsql/PROJECT:REGION:INSTANCE
  • Socket appears as a Unix socket at that path when container starts
  • No need for Cloud SQL Proxy binary in your container
  • Cloud Build service account needs different permissions than the compute service account
  • PostgreSQL password reset gotcha: When resetting Cloud SQL PostgreSQL passwords, do NOT use --host='%'. That flag is MySQL-specific and creates a separate user entry in PostgreSQL, causing intermittent password auth failures (some jobs connect, others don't, despite identical DATABASE_URL). Use: gcloud sql users set-password USERNAME --instance=INSTANCE --password=PASSWORD (no --host flag)
  • Password changes may take a minute to propagate through Cloud SQL Auth Proxy sidecars. If auth fails immediately after a reset, redeploy the job to force a fresh proxy connection

References

© divinevideo, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/cloud-run-job-cloudsql-setup of divinevideo/divine-mobile.

Open the folder on GitHubat commit 8d5fbf2

Compare with similar skills

Cloud Run Job Cloudsql Setup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloud Run Job Cloudsql Setup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloud Run Job Cloudsql Setup this skilldivinevideo/divine-mobile265—~1.4kAutomated safety check: PassMPL-2.0
SQL Database Support for pRESTprest/prest4.6k—~1.6kAutomated safety check: PassMIT
NpgsqlrestNpgsqlRest/NpgsqlRest132—~7kAutomated safety check: NotesMIT
Ops Telemetry Queryboundless-xyz/boundless193—~3.8kAutomated safety check: PassApache-2.0
Dsqlawslabs/agent-plugins912—~6.9kAutomated safety check: PassApache-2.0
Redshift Guideaws/agent-toolkit-for-aws2.8k—~2.6kAutomated safety check: PassApache-2.0

Similar skills

  • Guides classifying, gap-analyzing and scaffolding support for a new SQL database in pREST, from Postgres-compatible variants to entirely new dialects.

    4.6k GitHub stars~1.6k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Npgsqlrest

    NpgsqlRest/NpgsqlRest

    Build and modify REST APIs with NpgsqlRest — exposing PostgreSQL as HTTP endpoints from two sources (database functions/procedures/tables/views, and plain .sql files), driven by SQL comment…

    132 GitHub stars~7k tokensUpdated 4 days ago
    DatabasesAuto-check: notes
  • Ops Telemetry Query

    boundless-xyz/boundless

    Internal — for Boundless team members only. An agent skill from boundless-xyz/boundless.

    193 GitHub stars~3.8k tokensUpdated 1 mo ago
    DatabasesAuto-check passed
  • Dsql

    awslabs/agent-plugins

    Official

    Build with Aurora DSQL — manage schemas, execute queries, handle migrations, diagnose query plans, diagnose cluster performance, load data, and develop applications with a serverless, distributed…

    912 GitHub stars~6.9k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Redshift Guide

    aws/agent-toolkit-for-aws

    Official

    Amazon Redshift is NOT PostgreSQL — corrects PostgreSQL-derived LLM mistakes; covers Redshift-specific SQL, DDL, COPY/UNLOAD, system views, metadata discovery, and operational patterns.

    2.8k GitHub stars~2.6k tokensUpdated today
    DatabasesAuto-check passed
  • GCP Essentials

    ericrisco/rsc-harness

    A skill your agent uses when running a small product on core Google Cloud via the gcloud CLI: a project, Cloud Run deploys, a locked-down Cloud Storage bucket, managed Cloud SQL, and least-privilege…

    156 GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed

More from divinevideo/divine-mobile

All 103 skills in this repo
  • Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y".

    265 GitHub stars~931 tokensUpdated today
    Auto-check passed
  • Art Direct

    divinevideo/divine-mobile

    Art direction for any content — reads text, PDF, Word, HTML, PPT, then proposes 2-3 creative directions with photography style, mood, and visual language.

    265 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Async Await Null Race Condition

    divinevideo/divine-mobile

    Fix "Null check operator used on a null value" errors when an object is set to null during an async await.

    265 GitHub stars~881 tokensUpdated today
    Auto-check passed
  • AWS V4 Signing Custom Headers Gcs

    divinevideo/divine-mobile

    Add custom metadata headers (x-amz-meta-) to AWS v4 signed requests for GCS S3-compatible API.

    265 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Bash Herestring Newline Secrets

    divinevideo/divine-mobile

    Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings.

    265 GitHub stars~791 tokensUpdated today
    Auto-check passed
  • Fix silent video/media processing failures caused by URL extraction code that filters on file extensions (.mp4, .webm, .webp).

    265 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Questions about Cloud Run Job Cloudsql Setup

What does Cloud Run Job Cloudsql Setup do?

Set up Cloud Run Jobs with CloudSQL connection. An agent skill from divinevideo/divine-mobile. Cloud Run Job Cloudsql Setup is an agent skill from divinevideo/divine-mobile. Set up Cloud Run Jobs with CloudSQL connection.

When should I use Cloud Run Job Cloudsql Setup?

Cloud Run Job Cloudsql Setup fits situations like: deploying long-running batch jobs that need database access; errors like Cloud SQL Proxy not found in container; password authentication failed despite correct credentials; job creation fails with permission errors.

How do I install Cloud Run Job Cloudsql Setup in Claude Code?

Run `npx skills add divinevideo/divine-mobile --skill cloud-run-job-cloudsql-setup -a claude-code`. Or copy the skill folder (.agents/skills/cloud-run-job-cloudsql-setup in divinevideo/divine-mobile) into .claude/skills/cloud-run-job-cloudsql-setup in your project. Claude Code loads it when a task matches its description.

How do I install Cloud Run Job Cloudsql Setup in Codex?

Run `npx skills add divinevideo/divine-mobile --skill cloud-run-job-cloudsql-setup -a codex`. Or copy the skill folder (.agents/skills/cloud-run-job-cloudsql-setup in divinevideo/divine-mobile) into .agents/skills/cloud-run-job-cloudsql-setup in your project. Codex loads it when a task matches its description.

Can I use Cloud Run Job Cloudsql Setup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add divinevideo/divine-mobile --skill cloud-run-job-cloudsql-setup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-run-job-cloudsql-setup, .gemini/skills/cloud-run-job-cloudsql-setup, .github/skills/cloud-run-job-cloudsql-setup and .opencode/skills/cloud-run-job-cloudsql-setup in your project.

What does Cloud Run Job Cloudsql Setup need to run?

Going by SKILL.md and its folder, Cloud Run Job Cloudsql Setup needs the command-line tools its instructions call (gcloud) and credentials named POSTGRES_PASSWORD. Our summary lists: Node.js.

Does Cloud Run Job Cloudsql Setup access the network?

SKILL.md names 1 domain. As links in the text: cloud.google.com. This is read from the text; nothing was executed.

Is Cloud Run Job Cloudsql Setup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloud Run Job Cloudsql Setup use?

Cloud Run Job Cloudsql Setup is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloud Run Job Cloudsql Setup use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cloud Run Job Cloudsql Setup?

Skills that share tags, products or a category with Cloud Run Job Cloudsql Setup: SQL Database Support for pREST (prest/prest, 4.6k stars), Npgsqlrest (NpgsqlRest/NpgsqlRest, 132 stars), Ops Telemetry Query (boundless-xyz/boundless, 193 stars) and Dsql (awslabs/agent-plugins, 912 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloud Run Job Cloudsql Setup?

divinevideo (a GitHub organization) maintains it in divinevideo/divine-mobile, which has 265 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 7, 2026.

Source: divinevideo/divine-mobile on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.