Azure PostgreSQL checkpoint logging is disabled

Use checkpoint logs to investigate PostgreSQL disk writes and performance problems.

Description

Checkpoint logs help explain disk write load, performance degradation and checkpoint activity. Missing required logs can make performance and incident diagnosis harder. This feature does not itself prevent security incidents.

Potential impact

  • Logs needed to diagnose performance degradation may be missing.
  • Investigating database conditions around an incident can take longer.

Remediation

Set log_checkpoints to on on Flexible Server and verify the effective value and actual log collection. Configure log destinations, access and retention for operational needs. Configure connection and audit logs separately where required.

Examples

The before example uses retired Single Server settings. The after example sets a parameter on an existing Flexible Server and does not create or migrate a server.

Before

hcl
resource "azurerm_postgresql_configuration" "example" {
  name                = "log_checkpoints"
  resource_group_name = data.azurerm_resource_group.example.name
  server_name         = azurerm_postgresql_server.example.name
  value               = "OFF"
}

After

hcl
resource "azurerm_postgresql_flexible_server_configuration" "example" {
  name      = "log_checkpoints"
  server_id = azurerm_postgresql_flexible_server.example.id
  value     = "on"
}

The after example enables checkpoint logging. Verify actual collection before relying on these logs for performance and incident analysis.

References