Description
Cloud SQL IP settings determine public addressing and the networks allowed to connect directly. Overly broad authorized networks can let clients that do not need database access attempt to connect. In particular, 0.0.0.0/0 includes all IPv4 addresses and does not restrict access to the clients that need it.
Public addressing, network admission and database authentication are separate controls. Authorized networks apply to direct IP connections; the Cloud SQL Auth Proxy can provide IAM-authorized connections without an authorized-network list. If IP settings or authorized networks are omitted, review the connection method and the running instance's actual configuration together.
Potential impact
- Network settings that allow unnecessary external connections can let unwanted clients attempt database authentication.
- Inadequate authentication or database permissions can also lead to data disclosure or modification. A public IP address alone does not grant data access.
- Incorrect address ranges or settings that do not suit the connection method can prevent legitimate application connections or allow access beyond the intended scope.
Remediation
- Choose the required private or public network path, then decide whether to use an authenticated connector or a direct connection over that path. A connector can also use a private IP. If a public IP is unnecessary, establish the private path before disabling it.
- Register only the actual required client addresses for direct connections. Check the authorized-network requirements for the chosen connection method, along with database authentication, permissions and TLS.
- Define
settings.ip_configurationexplicitly and remove overly broad ranges such as0.0.0.0/0. After deployment, verify the actual settings and test legitimate application connections.
IP configuration examples
These incomplete excerpts support a review of IP settings. resource_name, the project and the service-account file path need environment-specific values. The string 0.0.0.0 differs from the all-IPv4 CIDR 0.0.0.0/0. Do not treat the example addresses or network labels as verified client information.
Connection settings to review
- name: sql_instance
google.cloud.gcp_sql_instance:
auth_kind: serviceaccount
name: "{{ resource_name }}-2"
project: test_project
region: us-central1
service_account_file: /tmp/auth.pem
settings:
ip_configuration:
authorized_networks:
- name: "google dns server"
value: "0.0.0.0"
tier: db-n1-standard-1
state: present
- name: sql_instance2
google.cloud.gcp_sql_instance:
auth_kind: serviceaccount
name: "{{ resource_name }}-2"
project: test_project
region: us-central1
service_account_file: /tmp/auth.pem
settings:
ip_configuration:
ipv4_enabled: yes
tier: db-n1-standard-1
state: present
A single-address entry
- name: sql_instance
google.cloud.gcp_sql_instance:
auth_kind: serviceaccount
name: "{{ resource_name }}-2"
project: test_project
region: us-central1
service_account_file: /tmp/auth.pem
settings:
ip_configuration:
authorized_networks:
- name: app-admin-host
value: 8.8.8.8/32
tier: db-n1-standard-1
state: present
Explanation:
- Connection settings to review: Replace the first task's
value: "0.0.0.0"with the actual required client address. The second task specifiesipv4_enabled: yeswithout authorized networks. Review the intended connection method and authentication configuration; this setting alone does not let anyone connect directly. - A single-address entry:
8.8.8.8/32identifies the Google Public DNS address. Naming itapp-admin-hostdoes not make it an administration host for your organization. Configure the verified address of the actual client.