Legacy Azure MySQL Server public network access needs review

Restrict MySQL connection paths and firewall rules, and migrate to a supported service.

Description

Enabling public network access on an Azure MySQL Server alongside broad firewall rules can permit unnecessary external connection attempts. Manage network reachability separately from database authentication and permissions.

azurerm_mysql_server is the legacy resource for Azure Database for MySQL Single Server, which retired on September 16, 2024. Review current network settings while migrating to Flexible Server.

Potential impact

  • Unapproved external sources may attempt connections and logins.
  • Continued reliance on a retired service configuration can complicate security maintenance and operational recovery.

Remediation

When migrating to supported MySQL Flexible Server, configure and test the required private path and DNS before disabling unnecessary public access. If public connections are needed, allow only actual client addresses in the firewall. When maintaining legacy Single Server configuration, check the effect of public_network_access_enabled=false and its connection path. Restrict authentication and data permissions separately.

Examples

These legacy Single Server excerpts show the network option. Other required settings, including SKU and version, are omitted. Do not use them as a current deployment example, and do not use the sample password in production.

Before

hcl
resource "azurerm_mysql_server" "app_db" {
  name                = "example-mysqlserver"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  administrator_login          = "mysqladminun"
  administrator_login_password = "H@Sh1CoR3!"
}

This legacy server configuration does not explicitly disable public network access.

After

hcl
resource "azurerm_mysql_server" "app_db" {
  name                         = "example-mysqlserver"
  location                     = azurerm_resource_group.example.location
  resource_group_name          = azurerm_resource_group.example.name
  administrator_login          = "mysqladminun"
  administrator_login_password = "H@Sh1CoR3!"
  public_network_access_enabled = false
}

This sets public_network_access_enabled to false on the legacy server. Use the network options and migration procedure supported by Flexible Server for current deployments.

References