Review PostgreSQL server log levels

Choose the PostgreSQL server message level required for operations, avoiding invalid values and excessive or insufficient logging.

Description

In Cloud SQL for PostgreSQL, log_min_messages sets the minimum message level written to the server log. An invalid value can cause configuration updates to fail. Even a valid value can omit needed messages or produce excessive logs if it does not suit operational needs.

The PostgreSQL default is warning. For server logging, log ranks above error and below fatal, so choosing log excludes ordinary warning and error messages. A valid value does not necessarily capture every message needed for operations.

Potential impact

  • Missing warnings and errors can make failures or unusual activity harder to investigate.
  • Excessively detailed logging can increase processing costs and operational noise.

Remediation

  • Set a supported log_min_messages value in settings.database_flags, choosing a level that includes the warnings and errors you need.
  • Review other PostgreSQL logging settings as well. This setting alone does not provide an audit record of every database operation.
  • Check actual message collection, log volume, and performance after the change.

The SQL module in google.cloud 1.14.0 does not support updates to existing instances. These examples configure creation; change flags on existing instances through supported Cloud SQL tooling or APIs.

Examples

Use a supported PostgreSQL version and instance tier, actual project and resource names, and a service account JSON file. These examples compare the validity and coverage of message levels.

Before

yaml
- name: Cloud SQL 인스턴스 생성
  google.cloud.gcp_sql_instance:
    auth_kind: serviceaccount
    database_version: POSTGRES_13
    name: "{{ resource_name }}-2"
    project: test_project
    region: us-central1
    service_account_file: /tmp/auth.pem
    settings:
      database_flags:
        - name: log_min_messages
          value: debug6
      tier: db-custom-1-3840
    state: present

debug6 is not a supported message level and cannot be used as a valid deployment setting.

After

yaml
- name: Cloud SQL 인스턴스 생성
  google.cloud.gcp_sql_instance:
    auth_kind: serviceaccount
    database_version: POSTGRES_13
    name: "{{ resource_name }}-2"
    project: test_project
    region: us-central1
    service_account_file: /tmp/auth.pem
    settings:
      database_flags:
        - name: log_min_messages
          value: log
      tier: db-custom-1-3840
    state: present

log is valid but excludes ordinary warning and error messages. Confirm that it provides the required coverage; choose an appropriate level such as warning when warnings must be included.

References