Review Cloud SQL PostgreSQL connection logging

Collect required connection history and verify delivery and retention.

Description

PostgreSQL log_connections records connection attempts and successful authentication and authorization. Missing required connection history can make suspicious access or operational failures harder to investigate.

This differs from SQL statement auditing, and off does not mean every authentication failure or error log disappears.

Potential impact

  • Evidence of connection identities and timing may be insufficient.
  • Investigating access failures or unusual activity can take longer.

Remediation

  • Enable required connection records using the log_connections format supported by your PostgreSQL version. The PostgreSQL 15 examples use on.
  • Verify log receipt and configure appropriate retention and access permissions. Review volume and sensitive content, and configure SQL auditing separately if needed.

Examples

These examples show part of the instance settings. Choose a supported engine version and machine type, and provide omitted required configuration.

Before

hcl
resource "google_sql_database_instance" "db" {
  name             = "postgres-instance"
  database_version = "POSTGRES_15"
  region           = "us-central1"

  settings {
    database_flags {
      name  = "log_connections"
      value = "off"
    }
  }
}

After

hcl
resource "google_sql_database_instance" "db" {
  name             = "postgres-instance"
  database_version = "POSTGRES_15"
  region           = "us-central1"

  settings {
    tier = "db-f1-micro"

    database_flags {
      name  = "log_connections"
      value = "on"
    }
  }
}

Explanation:

  • Before: Connection logging is disabled. This does not disable every other error log.
  • After: PostgreSQL 15 connection logging is enabled. Verify actual delivery and usability.

References