Description
Setting security_ips to include 0.0.0.0/0 in alicloud_db_instance permits every IPv4 source address at the allow-list level. Where a connection path exists, clients that do not need database access can attempt connections. Authentication and database permissions still apply.
The value 0.0.0.0 is not an equivalent alternative. Official RDS for MySQL guidance describes it as invalid input. Replace it with required client addresses rather than changing it to the unrestricted 0.0.0.0/0 range just to resolve the error.
An IP allow-list is only part of connection control. Review public endpoints, network paths, the allow-list's network type, and security groups together. Check access granted through either IP allow-lists or security groups.
Potential impact
- Allowing all IPv4 sources when an external connection path exists exposes the database to unnecessary connection attempts. Weaknesses in authentication or permissions could then lead to data disclosure or modification.
- Invalid IP entries can cause configuration errors or prevent the intended access restriction from taking effect. An invalid entry does not itself demonstrate that all external access is allowed.
Remediation
- Remove unrestricted ranges and invalid entries from
security_ips, and replace them with the actual client IP addresses or smallest required CIDR ranges. If clients use NAT, identify the source addresses used for the connections. - Review the allow-list's network type and security groups together. Use internal connectivity when a public endpoint is unnecessary, and apply appropriate database permissions and encryption in transit.
- Validate against the provider schema and inspect the change plan. After applying it, test that required application and administrative connections still work and unauthorized sources are denied.
Examples
These partial examples compare allowed source ranges. Define variables and network resources separately, and choose an engine version, instance class, and storage size supported together in the Region. Review the connect_timeout value against application requirements.
Allowing all IPv4 addresses
resource "alicloud_db_instance" "default" {
engine = "MySQL"
engine_version = var.engine_version
instance_type = var.instance_type
instance_storage = var.instance_storage
security_ips = ["0.0.0.0/0", "10.23.12.0/24"]
parameters {
name = "connect_timeout"
value = "50"
}
}
The 0.0.0.0/0 entry already includes all IPv4 addresses. Adding a private range to the same list does not narrow access.
Allowing only a required client
resource "alicloud_db_instance" "default" {
engine = "MySQL"
engine_version = var.engine_version
instance_type = var.instance_type
instance_storage = var.instance_storage
security_ips = ["10.23.12.24"]
parameters {
name = "connect_timeout"
value = "50"
}
}
This specifies one client address. Replace it with the address of a client that needs access and apply it to the correct network type. Review the complete allow-list, security groups, connection paths, and authentication as well.