Review Azure PostgreSQL throttling of failed authentication

Limit repeated incorrect-password connections and monitor authentication failures.

Description

Azure PostgreSQL connection throttling temporarily limits repeated connection attempts using incorrect passwords from the same IP address. It is not a general concurrent-connection limit or protection against every denial-of-service attack. Without this protection, repeated authentication attempts can be harder to mitigate.

Potential impact

  • Repeated incorrect-password connections can be harder to reduce.
  • Clients sharing an IP address can experience legitimate connection failures during temporary throttling caused by authentication failures.

Remediation

Set connection_throttle.enable to on on Flexible Server and check authentication failure logs and actual connectivity. Correct stale client credentials and excessive retries. Manage connection pools and concurrent-connection limits separately, and allow only required network access.

Examples

The before example uses connection_throttling on retired Single Server. The after example configures the current parameter on an existing Flexible Server; it does not create or migrate the server.

Before

hcl
resource "azurerm_postgresql_configuration" "example" {
  name                = "connection_throttling"
  resource_group_name = data.azurerm_resource_group.example.name
  server_name         = azurerm_postgresql_server.example.name
  value               = "OFF"
}

After

hcl
resource "azurerm_postgresql_flexible_server_configuration" "example" {
  name      = "connection_throttle.enable"
  server_id = azurerm_postgresql_flexible_server.example.id
  value     = "on"
}

The after example enables temporary throttling after repeated password authentication failures from the same IP. It does not specify the total allowed connection count.

References