Cloud SQL contained database authentication is enabled

Contained database authentication allows access to be managed within the database. Review whether it is needed and who can manage database users.

Description

SQL Server contained database authentication allows a database to authenticate users without relying solely on instance logins. It still requires authentication, but database users with permissions such as ALTER ANY USER can grant access to other users. Access reviews therefore need to cover those delegated permissions.

Disable contained database authentication in Cloud SQL when it is unnecessary. If it is needed, manage both instance logins and contained database users.

Potential impact

  • Excessive user-management permissions can grant database access to accounts that should not have it.
  • Reviews limited to instance logins can overlook contained database users and their access.

Remediation

  • Check how existing users and applications authenticate. If the feature is unnecessary, set contained database authentication to the string off. If it remains enabled, restrict permissions such as ALTER ANY USER to users who need them.
  • Change existing instances through the Cloud SQL console or supported administration tooling/API. The SQL instance module in google.cloud 1.14.0 cannot update existing objects, so editing its playbook alone cannot apply the change. Preserve other required flags when replacing the flag list.
  • Verify that required application connections still work and access by unauthorized users is denied.

Examples

These historical examples use SQLSERVER_13_1, which is not a currently documented Cloud SQL version identifier. For deployment, use a supported version and settings for your environment, and quote flag strings such as "on" or "off".

First configuration

yaml
- name: sql_instance
  google.cloud.gcp_sql_instance:
    auth_kind: serviceaccount
    database_version: SQLSERVER_13_1
    name: "{{ resource_name }}-2"
    project: test_project
    region: us-central1
    service_account_file: /tmp/auth.pem
    settings:
      database_flags:
      - name: contained database authentication
        value: on
      tier: db-n1-standard-1
    state: present

This configuration enables contained database authentication. Database users and the permissions to manage them require appropriate controls.

Comparison configuration

yaml
- name: sql_instance
  google.cloud.gcp_sql_instance:
    auth_kind: serviceaccount
    database_version: SQLSERVER_13_1
    name: '{{ resource_name }}-2'
    project: test_project
    region: us-central1
    service_account_file: /tmp/auth.pem
    settings:
      database_flags:
      - name: contained database authentication
        value: off
      tier: db-n1-standard-1
    state: present

Disable the flag when the feature is unnecessary. First confirm that existing connections do not depend on contained database authentication.

References