PostgreSQL login-failure throttling is disabled

Throttling repeated failed logins helps reduce password-guessing attempts against PostgreSQL.

Description

Azure PostgreSQL connection throttling temporarily limits connections from an IP address after too many invalid-password login failures. Without it, one safeguard against repeated authentication attempts is absent. It is not a general concurrent-connection limit or protection against every denial-of-service attack.

Potential impact

  • Password guessing and repeated failed requests may continue without this limit.
  • Excessive authentication requests can increase operational load and investigation work.

Remediation

  • Set the supported Flexible Server parameter connection_throttle.enable to on.
  • Restrict network access and monitor authentication failures. Manage ordinary connection counts separately through pooling and capacity settings.
  • Fix clients repeatedly using incorrect passwords and check the effect on legitimate users sharing an IP address.

Examples

The first example uses the legacy Single Server parameter; Single Server retired on March 28, 2025. The second uses an existing Flexible Server and azure.azcollection 3.18.0 or later.

Before

yaml
- name: PostgreSQL 설정 변경
  azure.azcollection.azure_rm_postgresqlconfiguration:
    resource_group: myResourceGroup
    server_name: myServer
    name: connection_throttling
    value: "off"

The legacy limit on failed logins is disabled. This value does not specify a general maximum number of concurrent connections.

After

yaml
- name: PostgreSQL 설정 변경
  azure.azcollection.azure_rm_postgresqlflexibleconfiguration:
    resource_group: myResourceGroup
    server_name: myServer
    name: connection_throttle.enable
    value: "on"

Per-IP login-failure throttling is enabled for Flexible Server. Check support in the PostgreSQL version in use and verify legitimate connections too.

References