Review Alibaba Cloud RDS PostgreSQL connection logging

Configure connection logs to support investigation of database access attempts.

Description

When log_connections is disabled in RDS PostgreSQL, less information may be available to investigate connection attempts and successful connections. Connection logs help investigate account misuse and unusual access patterns; they do not block access by themselves.

Potential impact

  • Missing connection history makes unusual logins and repeated attempts harder to investigate.
  • Determining the scope of account misuse or external access can take longer.

Remediation

Check parameter support for the PostgreSQL version and set log_connections to ON in parameters. Verify the effective value and log collection, and set the required retention and access permissions. For other engines, use their corresponding connection-auditing features.

Examples

These excerpts show RDS PostgreSQL connection logging. Choose version, instance type and storage inputs supported in the target region, and configure network and other creation settings separately.

Before

hcl
resource "alicloud_db_instance" "default" {
  engine           = "PostgreSQL"
  engine_version   = var.postgresql_version
  instance_type    = var.db_instance_type
  instance_storage = var.db_instance_storage
}

After

hcl
resource "alicloud_db_instance" "default" {
  engine           = "PostgreSQL"
  engine_version   = var.postgresql_version
  instance_type    = var.db_instance_type
  instance_storage = var.db_instance_storage

  parameters {
    name  = "log_connections"
    value = "ON"
  }
}

The before example does not specify the logging value, so check its effective parameter value. The after example sets log_connections to ON; verify that connection attempts produce the expected logs.

References