Description
SQL Server contained database authentication allows a database to authenticate users without relying solely on instance logins. It still requires authentication, but database users with permissions such as ALTER ANY USER can grant access to other users. Access reviews therefore need to cover those delegated permissions.
Disable contained database authentication in Cloud SQL when it is unnecessary. If it is needed, manage both instance logins and contained database users.
Potential impact
- Excessive user-management permissions can grant database access to accounts that should not have it.
- Reviews limited to instance logins can overlook contained database users and their access.
Remediation
- Check how existing users and applications authenticate. If the feature is unnecessary, set
contained database authenticationto the stringoff. If it remains enabled, restrict permissions such asALTER ANY USERto users who need them. - Change existing instances through the Cloud SQL console or supported administration tooling/API. The SQL instance module in
google.cloud1.14.0 cannot update existing objects, so editing its playbook alone cannot apply the change. Preserve other required flags when replacing the flag list. - Verify that required application connections still work and access by unauthorized users is denied.
Examples
These historical examples use SQLSERVER_13_1, which is not a currently documented Cloud SQL version identifier. For deployment, use a supported version and settings for your environment, and quote flag strings such as "on" or "off".
First configuration
- name: sql_instance
google.cloud.gcp_sql_instance:
auth_kind: serviceaccount
database_version: SQLSERVER_13_1
name: "{{ resource_name }}-2"
project: test_project
region: us-central1
service_account_file: /tmp/auth.pem
settings:
database_flags:
- name: contained database authentication
value: on
tier: db-n1-standard-1
state: present
This configuration enables contained database authentication. Database users and the permissions to manage them require appropriate controls.
Comparison configuration
- name: sql_instance
google.cloud.gcp_sql_instance:
auth_kind: serviceaccount
database_version: SQLSERVER_13_1
name: '{{ resource_name }}-2'
project: test_project
region: us-central1
service_account_file: /tmp/auth.pem
settings:
database_flags:
- name: contained database authentication
value: off
tier: db-n1-standard-1
state: present
Disable the flag when the feature is unnecessary. First confirm that existing connections do not depend on contained database authentication.