Review Cloud SQL MySQL local file loading

Disable unneeded LOAD DATA LOCAL use and limit client file access.

Description

MySQL local_infile concerns transferring files from the client computer to the server through LOAD DATA LOCAL. Both server and client must permit the feature, and the process’s file access and SQL privileges also apply.

An untrusted server can request unintended file transfers from a client, so limit the connections and clients that need the feature. This differs from reading files on the server.

Potential impact

  • Files readable by the client process can be transferred unintentionally.
  • Disabling the feature indiscriminately can break legitimate file-loading workflows.

Remediation

  • If local file loading is unnecessary, set local_infile to off and disable LOCAL capability in clients as well.
  • Where it is needed, verify the identity of a trusted server and minimize client file access and SQL privileges. Test required loading workflows after changes.

Examples

These examples show part of the instance settings. Choose a supported engine version and machine type, and provide omitted required configuration.

Before

hcl
resource "google_sql_database_instance" "db" {
  name             = "mysql-instance"
  database_version = "MYSQL_8_0"
  region           = "us-central1"

  settings {
    database_flags {
      name  = "local_infile"
      value = "on"
    }
  }
}

After

hcl
resource "google_sql_database_instance" "db" {
  name             = "mysql-instance"
  database_version = "MYSQL_8_0"
  region           = "us-central1"

  settings {
    tier = "db-f1-micro"

    database_flags {
      name  = "local_infile"
      value = "off"
    }
  }
}

Explanation:

  • Before: The server permits local file loading. Client settings and privileges are also needed to use it.
  • After: Server-side permission for local loading is disabled. Other file-access permissions are not removed.

References