Encrypted connections not enforced in GCP Cloud SQL

Require SSL/TLS encryption for direct Cloud SQL connections

Description

If Cloud SQL also permits unencrypted direct connections, clients may send credentials or data in plaintext. Require encryption with ssl_mode. Cloud SQL Auth Proxy and Connectors automatically encrypt their own connections.

Potential impact

Unencrypted connections may expose data to interception or modification along the network path.

Remediation

Use ENCRYPTED_ONLY for SQL Server. MySQL and PostgreSQL support ENCRYPTED_ONLY or TRUSTED_CLIENT_CERTIFICATE_REQUIRED, which also requires valid client certificates. Prepare client settings first and close existing plaintext connections after the change.

Examples

These PostgreSQL examples require both encryption and valid client certificates. Prepare the client certificates and the omitted network configuration separately.

Before

hcl
resource "google_sql_database_instance" "sql_instance" {
  name   = "private-instance"
  region = "us-central1"
  database_version = "POSTGRES_15"

  settings {
    tier = "db-f1-micro"
    ip_configuration {
      ipv4_enabled    = false
      private_network = google_compute_network.private_network.id
      ssl_mode        = "ALLOW_UNENCRYPTED_AND_ENCRYPTED"
    }
  }
}

After

hcl
resource "google_sql_database_instance" "sql_instance" {
  name   = "private-instance"
  region = "us-central1"
  database_version = "POSTGRES_15"

  settings {
    tier = "db-f1-micro"
    ip_configuration {
      ipv4_enabled    = false
      private_network = google_compute_network.private_network.id
      ssl_mode        = "TRUSTED_CLIENT_CERTIFICATE_REQUIRED"
    }
  }
}

References