Description
log_connections records connection attempts and successful authentication and authorization. Disabling it reduces evidence for investigating account connections and unusual access patterns.
Potential impact
Investigating account misuse or application connection problems can become harder.
Remediation
Set log_connections to the string on in settings.database_flags and preserve other required flags. Check that connection events are collected and restrict access to the logs.
Examples
The examples compare connection logging. These logs do not replace query auditing or access controls. Supply the actual PostgreSQL version and JSON credential file.
Before
yaml
- name: create instance
google.cloud.gcp_sql_instance:
name: gcp-instance
settings:
database_flags:
- name: log_connections
value: "off"
tier: db-n1-standard-1
region: us-central1
project: "{{ gcp_project_id }}"
database_version: "{{ postgres_version }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_credentials_file }}"
state: present
After
yaml
- name: create a instance
google.cloud.gcp_sql_instance:
name: gcp-instance
settings:
database_flags:
- name: log_connections
value: "on"
tier: db-n1-standard-1
region: us-central1
project: "{{ gcp_project_id }}"
database_version: "{{ postgres_version }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_credentials_file }}"
state: present