Description
If Cloud SQL also permits unencrypted direct connections, clients may send credentials or data in plaintext. Require encryption with ssl_mode. Cloud SQL Auth Proxy and Connectors automatically encrypt their own connections.
Potential impact
Unencrypted connections may expose data to interception or modification along the network path.
Remediation
Use ENCRYPTED_ONLY for SQL Server. MySQL and PostgreSQL support ENCRYPTED_ONLY or TRUSTED_CLIENT_CERTIFICATE_REQUIRED, which also requires valid client certificates. Prepare client settings first and close existing plaintext connections after the change.
Examples
These PostgreSQL examples require both encryption and valid client certificates. Prepare the client certificates and the omitted network configuration separately.
Before
resource "google_sql_database_instance" "sql_instance" {
name = "private-instance"
region = "us-central1"
database_version = "POSTGRES_15"
settings {
tier = "db-f1-micro"
ip_configuration {
ipv4_enabled = false
private_network = google_compute_network.private_network.id
ssl_mode = "ALLOW_UNENCRYPTED_AND_ENCRYPTED"
}
}
}
After
resource "google_sql_database_instance" "sql_instance" {
name = "private-instance"
region = "us-central1"
database_version = "POSTGRES_15"
settings {
tier = "db-f1-micro"
ip_configuration {
ipv4_enabled = false
private_network = google_compute_network.private_network.id
ssl_mode = "TRUSTED_CLIENT_CERTIFICATE_REQUIRED"
}
}
}