Review Cloud SQL automated backup settings

Enable backups suited to recovery objectives and verify that restoration works.

Description

When required automated backups are disabled, recovering Cloud SQL data after accidental deletion or corruption can be difficult. Check retention and recent successful backups as well as whether backups are enabled.

High-availability replication does not replace backups, and enabling automated backups alone does not configure point-in-time recovery.

Potential impact

  • Missing recent recovery points can increase data loss or downtime.
  • Even available backups may not meet recovery-time needs if restoration has not been tested.

Remediation

  • Enable backup_configuration.enabled and configure scheduling and retention to meet recovery objectives. If point-in-time recovery is required, check the additional engine-specific settings.
  • Monitor backup success and test restoration regularly. Limit backup and restore permissions to the people who need them.

Examples

These examples show part of the instance settings. Choose a supported engine version and machine type, and provide omitted required configuration.

Before

hcl
resource "google_sql_database_instance" "db" {
  name             = "master-instance"
  database_version = "POSTGRES_11"
  region           = "us-central1"

  settings {
    tier = "db-f1-micro"

    backup_configuration {
      enabled = false
    }
  }
}

After

hcl
resource "google_sql_database_instance" "db" {
  name             = "master-instance"
  database_version = "POSTGRES_11"
  region           = "us-central1"

  settings {
    backup_configuration {
      enabled = true
    }
  }
}

Explanation:

  • Before: Automated backups are disabled. Check whether other recovery measures meet requirements.
  • After: Automated backups are enabled. Verify successful runs, retention and restoration procedures separately.

References