Following is the list of identified permissions (existing service account) required for supporting GCP Cloud SQL:

Prerequisite for using an existing VPC:

Additionally, the user account must have the Compute Network Admin role and secretmanager.secretAccessor role.