Review Cloud SQL SQL Server cross-database ownership chaining

Disable unnecessary cross-database ownership chaining and use explicit permissions.

Description

cross db ownership chaining permits ownership chains across databases when the required conditions hold. Permission checks on a referenced object can be skipped when the referring and referenced objects have the same owner and chaining applies, potentially enabling unintended data access.

Cloud SQL deprecates this flag for all SQL Server versions and does not permit newly setting it to on. For existing enabled instances, check dependencies before removing it or setting it to off.

Potential impact

  • Someone able to change objects in one database may gain unintended access to another database’s data.
  • Disabling chaining without checking dependencies can break cross-database operations.

Remediation

  • Review cross-database calls and ownership before removing existing cross db ownership chaining or setting it to off.
  • Provide necessary access through explicit least privileges or a supported alternative such as signed stored procedures. Test legitimate workflows and rejection of unwanted access.

Examples

These excerpts compare part of the instance settings. Use a supported engine version and SQL Server machine type, and supply var.sql_server_tier and omitted required inputs. Changing this flag does not require the engine-version change shown in the examples. The before setting of on is historical and is not a setting to apply to a new instance today.

Before

hcl
resource "google_sql_database_instance" "db" {
  name             = "sqlserver-instance"
  database_version = "SQLSERVER_2017_EXPRESS"
  region           = "us-central1"

  settings {
    database_flags {
      name  = "cross db ownership chaining"
      value = "on"
    }
  }
}

After

hcl
resource "google_sql_database_instance" "db" {
  name             = "sqlserver-instance"
  database_version = "SQLSERVER_2019_STANDARD"
  region           = "us-central1"

  settings {
    tier = var.sql_server_tier

    database_flags {
      name  = "cross db ownership chaining"
      value = "off"
    }
  }
}

Explanation:

  • Before: The historical configuration enables cross-database ownership chaining. It does not unconditionally grant access to every database.
  • After: The flag is disabled. Required cross-database operations still need appropriate permissions.

References