Review Cloud SQL MySQL database-listing privileges

Limit database-name visibility to accounts that need it.

Description

With MySQL skip_show_database set to off, users can run SHOW DATABASES, but the databases they see depend on their privileges. The setting alone does not disclose every database name or its data.

When it is on, only users with the SHOW DATABASES privilege can run the command. That privilege allows the full list to be viewed, so review who holds it as well.

Potential impact

  • Unnecessary disclosure of database names can reveal internal structure.
  • Broadly restricting listing can disrupt administration tools that depend on it.

Remediation

  • If ordinary accounts should not list databases, set skip_show_database to on and minimize grants of SHOW DATABASES and broad global privileges.
  • Check administration-tool and application dependencies before changing the setting, and test required listing operations. Restrict actual data-access privileges separately.

Examples

These examples show part of the instance settings. Choose a supported engine version and machine type, and provide omitted required configuration.

Before

hcl
resource "google_sql_database_instance" "db" {
  name             = "mysql-instance"
  database_version = "MYSQL_8_0"
  region           = "us-central1"

  settings {
    database_flags {
      name  = "skip_show_database"
      value = "off"
    }
  }
}

After

hcl
resource "google_sql_database_instance" "db" {
  name             = "mysql-instance"
  database_version = "MYSQL_8_0"
  region           = "us-central1"

  settings {
    tier = "db-f1-micro"

    database_flags {
      name  = "skip_show_database"
      value = "on"
    }
  }
}

Explanation:

  • Before: The command is allowed, with visible names determined by the user’s privileges.
  • After: Running the command requires SHOW DATABASES privilege. Review grants of that privilege as well.

References