Review Cloud SQL PostgreSQL duration-based SQL logging

Balance diagnostic needs with the sensitivity of SQL content.

Description

log_min_duration_statement records the duration and SQL text of PostgreSQL statements that meet a duration threshold. Positive values without units are milliseconds; 0 records every statement, and -1 disables this duration-based logging.

The feature helps diagnose performance, but sensitive values in SQL can also enter logs. Disabling it does not disable every error or SQL log produced by other settings.

Potential impact

  • Sensitive SQL values can become visible to people with log access.
  • An overly low threshold can increase log volume and overhead, while unnecessary disabling can remove useful diagnostic evidence.

Remediation

  • Choose log_min_duration_statement to match diagnostic and audit needs. Use -1 only when this logging is unnecessary; otherwise choose a suitable threshold.
  • Restrict log access and retention, and check for sensitive SQL values. Verify log volume, performance impact and required diagnostic information after changes.

Examples

These examples show part of the instance settings. Choose a supported engine version and machine type, and provide omitted required configuration. The engine-version difference is not a prerequisite for changing this flag.

Before

hcl
resource "google_sql_database_instance" "db" {
  name             = "postgres-instance"
  database_version = "POSTGRES_14"
  region           = "us-central1"

  settings {
    database_flags {
      name  = "log_min_duration_statement"
      value = "2"
    }
  }
}

After

hcl
resource "google_sql_database_instance" "db" {
  name             = "postgres-instance"
  database_version = "POSTGRES_15"
  region           = "us-central1"

  settings {
    tier = "db-f1-micro"

    database_flags {
      name  = "log_min_duration_statement"
      value = "-1"
    }
  }
}

Explanation:

  • Before: 2 logs statements taking at least 2 milliseconds.
  • After: -1 disables this duration-based statement logging. It does not disable all PostgreSQL logs.

References