TLS enforcement is disabled for Azure PostgreSQL

Require TLS for Azure PostgreSQL connections and verify the server certificate.

Description

Disabling TLS enforcement on Azure PostgreSQL can allow unencrypted connections. The former Single Server service used enforce_ssl, while the current Flexible Server service uses require_secure_transport.

Potential impact

Database requests and responses sent in plaintext can be exposed or modified on the network.

Remediation

Keep require_secure_transport set to on on Flexible Server and configure clients to use TLS with server-certificate verification.

Examples

The initial excerpt is a historical setting for the retired Single Server service. The revised excerpt updates a parameter on an existing Flexible Server named testserver; server and data migration must be handled separately.

Before

yaml
- name: PostgreSQL 서버 생성
  azure.azcollection.azure_rm_postgresqlserver:
    resource_group: myResourceGroup
    name: testserver
    location: eastus
    storage_mb: 5120
    enforce_ssl: no
    admin_username: cloudsa
    admin_password: "{{ postgresql_admin_password }}"
  no_log: true

After

yaml
- name: PostgreSQL TLS 설정
  azure.azcollection.azure_rm_postgresqlflexibleconfiguration:
    resource_group: myResourceGroup
    server_name: testserver
    name: require_secure_transport
    value: "on"

References