Description
The alicloud_db_instance resource in Alibaba Cloud provider 1.293.0 does not support a top-level address attribute. Putting 0.0.0.0/0 or a private address there does not create a valid access control. The address attribute belongs inside the PostgreSQL-specific pg_hba_conf block.
Manage RDS connectivity through supported IP allow-lists and network settings. A pg_hba_conf.address value of 0.0.0.0/0 covers all IPv4 sources for the users and databases in that rule. Actual connections also depend on network paths, the instance's IP allow-list, and authentication settings.
Potential impact
- An unsupported attribute can cause Terraform validation errors and prevent deployments or updates. The intended access restriction may never take effect.
- Overly broad source ranges in actual connection controls can expose the service to unnecessary connection attempts. Data access also depends on authentication and database permissions.
Remediation
- Check the provider schema in use, remove the top-level
address, and runterraform validate. Do not merely replace its value with a private address. - Set
security_ipsto the actual source addresses or smallest required network ranges of authorized clients. For PostgreSQLpg_hba_conf, review users, databases, and authentication methods as well as addresses. - Assess the need for a public endpoint and use internal connectivity where possible. Establish the required client paths before the change, then test both permitted connections and connections that should be denied.
Examples
These partial examples compare attribute placement. Define the variables and virtual switch separately, and select an engine version, instance class, and storage size supported together in the Region. Replace the example IP with the address of a client that needs access.
Unsupported attribute
resource "alicloud_db_instance" "example" {
engine = "MySQL"
engine_version = var.engine_version
instance_type = var.instance_type
instance_storage = var.instance_storage
instance_charge_type = "Postpaid"
instance_name = var.name
vswitch_id = alicloud_vswitch.example.id
monitoring_period = "60"
address = "0.0.0.0/0"
}
The top-level address is unsupported, so this configuration is invalid. It does not demonstrate a public-access setting that has taken effect.
Supported IP allow-list
resource "alicloud_db_instance" "example" {
engine = "MySQL"
engine_version = var.engine_version
instance_type = var.instance_type
instance_storage = var.instance_storage
instance_charge_type = "Postpaid"
instance_name = var.name
vswitch_id = alicloud_vswitch.example.id
monitoring_period = "60"
security_ips = ["10.23.12.24/32"]
}
The supported security_ips setting specifies one client address. It neither creates a private connection path nor replaces database authentication. Check the complete effective IP allow-list and the client's connection path as well.