Encrypting Cloud SQL database connections

Protect database connections with SSL/TLS and verify the server identity. Select settings that match the Cloud SQL engine and the actual connection path.

Description

An unencrypted database connection can expose credentials, queries and returned data to an attacker with access to the network path. Use SSL/TLS for Cloud SQL connections and configure clients to verify the server's identity.

Cloud SQL gives sslMode precedence over the legacy requireSsl setting. For MySQL and PostgreSQL, ENCRYPTED_ONLY with requireSsl: false still allows only encrypted connections. SQL Server pairs ENCRYPTED_ONLY with requireSsl: true. The TRUSTED_CLIENT_CERTIFICATE_REQUIRED mode additionally requires client certificates and is available for MySQL and PostgreSQL, but not SQL Server.

Potential impact

  • Unencrypted connections can expose credentials or business data.
  • Clients that do not verify the server's identity risk connecting to an unintended server.

Remediation

  • Apply the appropriate SSL/TLS mode for the engine through the Cloud SQL console or supported administration tooling/API. If the legacy requireSsl setting is also used, choose a compatible value. Prepare client TLS settings and any required certificates first.
  • The SQL instance module in google.cloud 1.14.0 provides require_ssl but not ssl_mode, and cannot update existing objects. Use another supported administration method to change an existing instance's mode.
  • Review the entire path from the application to the instance. Cloud SQL Auth Proxy encrypts the proxy-to-instance connection, but does not automatically encrypt the application-to-proxy segment. Verify that required connections work and disallowed unencrypted connections are rejected.

Examples

These examples compare the legacy require_ssl option. They omit the engine and SSL mode, so check compatibility with the actual environment. The 8.8.8.8/32 entry and google dns server label are not values to use for an allow-list of real database clients.

First configuration

yaml
- name: create a forth instance
  google.cloud.gcp_sql_instance:
    name: "{{ resource_name }}-2"
    settings:
      ip_configuration:
        require_ssl: no
        authorized_networks:
        - name: google dns server
          value: 8.8.8.8/32
      tier: db-n1-standard-1
    region: us-central1
    project: test_project
    auth_kind: serviceaccount
    service_account_file: "/tmp/auth.pem"
    state: present

The legacy option does not require encryption when set to require_ssl: no. Whether the current configuration enforces encrypted connections also depends on the applied sslMode.

Comparison configuration

yaml
- name: create a instance
  google.cloud.gcp_sql_instance:
    name: '{{ resource_name }}-2'
    settings:
      ip_configuration:
        require_ssl: yes
        authorized_networks:
        - name: google dns server
          value: 8.8.8.8/32
      tier: db-n1-standard-1
    region: us-central1
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present

This configuration enables the legacy option with require_ssl: yes. Choose an engine-compatible SSL mode, prepare any required client certificates, and verify the settings applied to the actual instance.

References