google/alloydb-basics
>- Manages clusters, instances, and backups for AlloyDB for PostgreSQL, and integrates with AlloyDB Model Context Protocol (MCP) tools for automated database operations. Use when creating, configuring, or administering AlloyDB databases. Do NOT use for general PostgreSQL instances (e.g. Cloud SQL) or other GCP databases.
npx skills add https://github.com/google/skills --skill alloydb-basics
AlloyDB for PostgreSQL is a managed, PostgreSQL-compatible database service
designed for enterprise-grade performance and availability. It utilizes a
disaggregated compute and storage architecture to scale resources independently.
It also provides AlloyDB AI, a collection of features that includes AI-powered
search (vector, hybrid search, and AI functions), natural language capabilities,
conversational analytics, and inference features like forecasting and model
endpoint management to help developers build AI apps faster.
Before you begin, ensure you have the Google Cloud SDK installed and authenticated (gcloud auth login).
gcloud services enable alloydb.googleapis.com --quiet
gcloud alloydb clusters create my-cluster --region=us-central1 \
--password=my-password --network=my-vpc --quiet
*For production environments, always use IAM database authentication instead
of passwords. If configuration constraint requires passwords, store them
securely using Secret Manager.*
gcloud alloydb instances create my-primary --cluster=my-cluster \
--region=us-central1 --instance-type=PRIMARY --cpu-count=2 --quiet
Read these supplementary files when specific context or detailed steps are
required for a task:
Public IP, PSA, PSC), backups, point-in-time recovery, scaling (vertical and
horizontal), or Quota management: read
Core Concepts.
CLI Usage.
MCP Usage.
Infrastructure as Code.
users/privileges, or network security (public IP authorization, Auth Proxy
sidecar configuration): read IAM & Security.
*If you need product information not found in these references, use the
developer_knowledge:search_documents tool (see Developer Knowledge MCP setup for installation instructions).*
Agents MUST adhere to the following directives when answering queries related to
AlloyDB:
tasks (like backups, scaling, or database user creation), always provide
both the Google Cloud Console steps and the gcloud CLI commands if both
are available in the reference documents.
IP for connections to ensure traffic remains within the Google Cloud network
and reduces exposure.
Access or Direct VPC Egress is required when connecting from Cloud Run to
Private IP.
Proxy (running as a sidecar or locally) or language connectors rather than
direct TCP connections.
reject designs with 0.0.0.0/0 in Authorized Networks as this exposes the
database to the entire internet.
authentication and the alloydbiamuser database role instead of static
database passwords.
explicitly state that roles/alloydb.client should be used to adhere to the
principle of least privilege, and warn against using broader roles like
roles/alloydb.admin for connections.
users, explicitly state that they can be created using the Google Cloud
Console, the gcloud CLI, and the AlloyDB API.
always explicitly mention and describe both **Private Services Access
(PSA) and Private Service Connect (PSC)** as the supported methods,
recommending PSC for new deployments.
(connecting directly to the private IP without connectors) are possible but
discouraged, and compare their security (lack of IAM/mTLS) to secure methods
like the AlloyDB Auth Proxy or language connectors.
explicitly state that "IAM database users cannot be created using standard
SQL alone" and must be registered via the control plane first.
object access, you MUST explicitly state that "standard PostgreSQL roles and
privileges" apply, using both terms.
state that discrete backups exist independently of the source cluster and
remain active even if the source cluster is deleted.
connection methods (AlloyDB Auth Proxy, Language Connectors) are
especially recommended for connections over Public IP.
explicitly mention the option of using read pool autoscaling and state
that it is in Preview.
Take google/alloydb-basics from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.