PostgreSQL connection logging is disabled

Use Cloud SQL for PostgreSQL connection logs to examine account access history.

Description

log_connections records connection attempts and successful authentication and authorization. Disabling it reduces evidence for investigating account connections and unusual access patterns.

Potential impact

Investigating account misuse or application connection problems can become harder.

Remediation

Set log_connections to the string on in settings.database_flags and preserve other required flags. Check that connection events are collected and restrict access to the logs.

Examples

The examples compare connection logging. These logs do not replace query auditing or access controls. Supply the actual PostgreSQL version and JSON credential file.

Before

yaml
- name: create instance
  google.cloud.gcp_sql_instance:
    name: gcp-instance
    settings:
      database_flags:
        - name: log_connections
          value: "off"
      tier: db-n1-standard-1
    region: us-central1
    project: "{{ gcp_project_id }}"
    database_version: "{{ postgres_version }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_credentials_file }}"
    state: present

After

yaml
- name: create a instance
  google.cloud.gcp_sql_instance:
    name: gcp-instance
    settings:
      database_flags:
        - name: log_connections
          value: "on"
      tier: db-n1-standard-1
    region: us-central1
    project: "{{ gcp_project_id }}"
    database_version: "{{ postgres_version }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_credentials_file }}"
    state: present

References