Google Cloud SQL network settings need review

Review Cloud SQL connection paths and authorized client addresses, and restrict unnecessary public access.

Description

An overly broad address range for direct public-IP connections to Cloud SQL can permit connection attempts from clients that do not need database access. An authorized_networks value of 0.0.0.0/0 includes every IPv4 address. Network connectivity does not bypass database authentication and permissions.

A public IP without authorized networks does not allow direct connections from every internet address. The Cloud SQL Auth Proxy and connectors can connect with appropriate authentication without an authorized-network entry, and can use either public or private IP paths.

Potential impact

  • An unnecessarily broad connection range can increase opportunities for credential attacks or vulnerability exploitation.
  • Allowed clients with valid credentials and database permissions may gain unintended access to data or make unwanted changes.

Remediation

  • If direct public connections are required, allow only the actual client addresses in authorized_networks and remove unnecessary unrestricted ranges.
  • If access should be private only, prepare and test a private-IP or Private Service Connect path before disabling public IP. Choose the IP connection path separately from whether to use a proxy or connector.
  • Check IAM and database authentication and permissions. Verify that required connections succeed and unauthorized direct connections are blocked. Omitting ipv4_enabled does not disable public IP.

Examples

Check support for the provider and database versions you use. The after-example requires a separately defined google_compute_network.private and a private services access connection. For an existing instance, review the Terraform plan, including name changes, and plan the connection transition.

Before

hcl
resource "google_sql_database_instance" "public_sql_instance" {
  name             = "postgres-instance-2"
  database_version = "POSTGRES_11"

  settings {
    tier = "db-f1-micro"

    ip_configuration {
      authorized_networks {
        name  = "pub-network"
        value = "0.0.0.0/0"
      }
    }
  }
}

Every IPv4 address is included in the allowed range for direct public-IP connections. This does not bypass database authentication.

After

hcl
resource "google_sql_database_instance" "private_sql_instance" {
  name             = "private-instance-1"
  database_version = "POSTGRES_11"

  settings {
    tier = "db-f1-micro"

    ip_configuration {
      ipv4_enabled    = false
      private_network = google_compute_network.private.id
    }
  }
}

Public IPv4 is disabled and a VPC network is specified. Complete the required private connectivity alongside these settings and verify client connections.

References