Install Releem for MySQL on GCP Cloud SQL
Connect the Releem Agent to Cloud SQL for MySQL.
Prerequisites
Review MySQL permissions, including query visibility for the examples below. Place the Agent where it can reach the Cloud SQL instance through the approved private network or connector. Enable Performance Schema and the slow query log for the related database and query data:
performance_schema=ON
slow_query_log=ON
Give the Agent access to Cloud SQL
Attach a service account to the Compute Engine VM. Grant it Cloud SQL Viewer (roles/cloudsql.viewer) on the project containing the Cloud SQL instance. This role includes cloudsql.instances.get for instance discovery and monitoring.timeSeries.list for system metrics—the read operations used by the Agent. Enable the Cloud SQL Admin API and Cloud Monitoring API in that project.
To make Releem's Apply action available, also grant the VM service account cloudsql.instances.update in that project through a custom role. The Agent uses Cloud SQL instances.patch, viewer alone cannot submit that change.
Give the VM the cloud-platform access scope, then use its IAM roles to limit access. The same service account and scope are needed when the Agent runs in Docker on that VM.
Automatic installation
Install the Agent on a Compute Engine VM that can reach Cloud SQL. A starting VM size is 2 vCPUs, 4 GB of memory, and a 10 GB balanced persistent disk; adjust it for your workload. Open a private root shell and run this command. Replace the bracketed placeholders with your values.
RELEEM_INSTANCE_TYPE="gcp/cloudsql" RELEEM_GCP_PROJECT_ID="[PROJECT_ID]" RELEEM_GCP_REGION="[REGION]" RELEEM_GCP_CLOUDSQL_INSTANCE="[INSTANCE_ID]" RELEEM_MYSQL_PASSWORD='[MONITORING_PASSWORD]' RELEEM_MYSQL_LOGIN='releem' RELEEM_DB_MEMORY_LIMIT=0 RELEEM_API_KEY='[RELEEM_API_KEY]' RELEEM_CRON_ENABLE=1 RELEEM_QUERY_OPTIMIZATION=true bash -c "$(curl -L https://releem.s3.amazonaws.com/v2/install.sh)"
Manual installation
To run the Agent in a container on the Compute Engine VM, choose Docker or Docker Compose. Replace every bracketed value.
Docker
docker run -d --name releem-agent \
-e RELEEM_API_KEY="[RELEEM_API_KEY]" \
-e RELEEM_HOSTNAME="[SERVER_NAME]" \
-e DB_USER="releem" \
-e DB_PASSWORD="[MONITORING_PASSWORD]" \
-e INSTANCE_TYPE="gcp/cloudsql" \
-e RELEEM_GCP_PROJECT_ID="[PROJECT_ID]" \
-e RELEEM_GCP_REGION="[REGION]" \
-e RELEEM_GCP_CLOUDSQL_INSTANCE="[INSTANCE_ID]" \
-e RELEEM_QUERY_OPTIMIZATION="true" \
--restart unless-stopped \
releem/releem-agent:[VERSION_FROM_DOCKER_HUB]
Check the container log with docker logs --tail=100 releem-agent.
Docker Compose
Create compose.yaml:
services:
releem-agent:
image: "releem/releem-agent:[VERSION_FROM_DOCKER_HUB]"
environment:
RELEEM_API_KEY: "[RELEEM_API_KEY]"
RELEEM_HOSTNAME: "[SERVER_NAME]"
DB_USER: "releem"
DB_PASSWORD: "[MONITORING_PASSWORD]"
INSTANCE_TYPE: "gcp/cloudsql"
RELEEM_GCP_PROJECT_ID: "[PROJECT_ID]"
RELEEM_GCP_REGION: "[REGION]"
RELEEM_GCP_CLOUDSQL_INSTANCE: "[INSTANCE_ID]"
RELEEM_QUERY_OPTIMIZATION: "true"
restart: unless-stopped
docker compose up -d
docker compose logs --tail=100 releem-agent
Keep a Compose file containing credentials out of version control.
To monitor another Cloud SQL instance from the same VM, duplicate the Compose service. Give the second service and container unique names, then set its own RELEEM_HOSTNAME, project, Region, instance ID, and database credentials. Start both services with docker compose up -d; each Agent should appear as a separate server in the Dashboard.
Installer parameters
RELEEM_GCP_PROJECT_IDis the Google Cloud project ID.RELEEM_GCP_REGIONis the Cloud SQL Region.RELEEM_GCP_CLOUDSQL_INSTANCEis the instance ID or connection name.RELEEM_MYSQL_LOGINandRELEEM_MYSQL_PASSWORDconfigure the database connection.RELEEM_CRON_ENABLE=1enables daily Agent updates on the VM. Set it to0if you do not want scheduled updates.RELEEM_QUERY_OPTIMIZATION=trueenables query collection after you grant the query permissions. Remove it from the chosen installation example for baseline monitoring only.
Expected result
After you complete a supported installation method, the Dashboard should show Agent Status: Connected and current metrics or a current data timestamp.
Verify the installation
Confirm both the Agent connection and current metrics in the Dashboard. If either is missing, check the Agent logs.
Troubleshooting
Cloud API access denied
If the Agent logs Failed to get Cloud SQL instance details, check its VM service account, project ID, Cloud SQL Admin API, and cloudsql.instances.get permission. If it logs Failed to collect GCP metrics, check the Cloud Monitoring API and monitoring.timeSeries.list permission. Also confirm that the VM access scope allows the APIs. Restart the Agent after correcting its access.
The Dashboard has no latency data
Check that Performance Schema is active on the running Cloud SQL instance and that the Agent can read the statement-digest data. Run database queries, then check the Latency graph again.
Error 1045 (28000): Access denied
Confirm the database user, password, and host from which the Agent connects. Compare the account's effective grants with MySQL Required Permissions. Update the Agent's protected credentials if needed, then restart the Agent.
Connect: connection timed out
For a private-IP connection, check that the VM has access to the Cloud SQL VPC and that firewall rules allow the database connection. If you use the Cloud SQL Auth Proxy, confirm that the proxy is running, points to the correct instance and IP path, and that its identity has the Cloud SQL Client role.
For other failures, use Troubleshoot the Releem Agent and review the Agent logs.