Description
An overly broad address range for direct public-IP connections to Cloud SQL can permit connection attempts from clients that do not need database access. An authorized_networks value of 0.0.0.0/0 includes every IPv4 address. Network connectivity does not bypass database authentication and permissions.
A public IP without authorized networks does not allow direct connections from every internet address. The Cloud SQL Auth Proxy and connectors can connect with appropriate authentication without an authorized-network entry, and can use either public or private IP paths.
Potential impact
- An unnecessarily broad connection range can increase opportunities for credential attacks or vulnerability exploitation.
- Allowed clients with valid credentials and database permissions may gain unintended access to data or make unwanted changes.
Remediation
- If direct public connections are required, allow only the actual client addresses in
authorized_networksand remove unnecessary unrestricted ranges. - If access should be private only, prepare and test a private-IP or Private Service Connect path before disabling public IP. Choose the IP connection path separately from whether to use a proxy or connector.
- Check IAM and database authentication and permissions. Verify that required connections succeed and unauthorized direct connections are blocked. Omitting
ipv4_enableddoes not disable public IP.
Examples
Check support for the provider and database versions you use. The after-example requires a separately defined google_compute_network.private and a private services access connection. For an existing instance, review the Terraform plan, including name changes, and plan the connection transition.
Before
resource "google_sql_database_instance" "public_sql_instance" {
name = "postgres-instance-2"
database_version = "POSTGRES_11"
settings {
tier = "db-f1-micro"
ip_configuration {
authorized_networks {
name = "pub-network"
value = "0.0.0.0/0"
}
}
}
}
Every IPv4 address is included in the allowed range for direct public-IP connections. This does not bypass database authentication.
After
resource "google_sql_database_instance" "private_sql_instance" {
name = "private-instance-1"
database_version = "POSTGRES_11"
settings {
tier = "db-f1-micro"
ip_configuration {
ipv4_enabled = false
private_network = google_compute_network.private.id
}
}
}
Public IPv4 is disabled and a VPC network is specified. Complete the required private connectivity alongside these settings and verify client connections.