Cross-database ownership chaining is enabled in Cloud SQL

Cross-database ownership chaining affects permission checks on objects in other databases. Review existing dependencies and remove unnecessary chains.

Description

SQL Server ownership chaining can skip permission checks on a referenced object when it has the same owner as the referring object and the relevant conditions are met. If that chain crosses databases, it can permit access beyond the intended database boundary.

Cloud SQL has deprecated cross db ownership chaining for all SQL Server versions and no longer allows it to be newly set to on. Where it is already enabled, review application dependencies and remove the flag or change it to off.

Potential impact

  • Ownership chaining combined with excessive database permissions can allow unintended access across databases or privilege escalation.
  • Disabling a chain without accounting for dependent operations can break application workflows across databases.

Remediation

  • Identify operations that need access across databases and review the associated account and object permissions. Remove the existing cross db ownership chaining flag or set it to the string off.
  • Grant only the access those operations need. Consider certificate-signed stored procedures as recommended by Cloud SQL, and verify that required operations still work while unauthorized access is denied.
  • Change existing instances through the Cloud SQL console or supported administration tooling/API. The SQL instance module in google.cloud 1.14.0 cannot update existing objects. Preserve other required flags when replacing the flag list.

Examples

These historical examples use SQLSERVER_13_1, which is not a currently documented Cloud SQL version identifier. The first example's on value also cannot be newly configured. Use a supported version and quoted flag strings such as "off" in an actual configuration.

First configuration

yaml
- name: sql_instance
  google.cloud.gcp_sql_instance:
    auth_kind: serviceaccount
    database_version: SQLSERVER_13_1
    name: "{{ resource_name }}-2"
    project: test_project
    region: us-central1
    service_account_file: /tmp/auth.pem
    settings:
      database_flags:
      - name: cross db ownership chaining
        value: on
      tier: db-n1-standard-1
    state: present

This historical configuration enables cross-database ownership chaining. If an existing instance uses it, review permissions across databases and application dependencies.

Comparison configuration

yaml
- name: sql_instance
  google.cloud.gcp_sql_instance:
    auth_kind: serviceaccount
    database_version: SQLSERVER_13_1
    name: '{{ resource_name }}-2'
    project: test_project
    region: us-central1
    service_account_file: /tmp/auth.pem
    settings:
      database_flags:
      - name: cross db ownership chaining
        value: off
      tier: db-n1-standard-1
    state: present

This configuration disables the flag. Provide the required access across databases separately and verify that normal operations continue to work.

References