Review public access to a NIFCLOUD RDB instance

Check whether database public access is needed and which clients are actually allowed.

Description

Setting publicly_accessible to true on a NIFCLOUD RDB instance enables a public access path. Unnecessary public access combined with broad DB security-group permissions can increase exposure to external connections and login attempts.

Public access does not grant permission to read data. Network paths and DB security groups govern connectivity, while authentication and database permissions govern data operations.

Potential impact

  • External clients that do not need access may attempt database connections or logins.
  • Misuse of leaked credentials or vulnerabilities can lead to data reads, changes or deletion.

Remediation

If public access is unnecessary, configure and test private connectivity for applications and administrators before setting publicly_accessible to false. Where public access is required, still restrict the DB security group to approved clients. Use strong authentication and least-privilege data permissions, then verify legitimate connectivity and the blocking of unapproved access.

Examples

These excerpts compare public-access settings on the same RDB instance. Engine, authentication and private-network configuration are omitted.

Before

hcl
resource "nifcloud_db_instance" "app_db" {
  identifier          = "example"
  instance_class      = "db.large8"
  publicly_accessible = true
}

Public access is explicitly enabled. Check the DB security group’s actual permitted sources and connection paths too.

After

hcl
resource "nifcloud_db_instance" "app_db" {
  identifier          = "example"
  instance_class      = "db.large8"
  publicly_accessible = false
}

Public access is disabled. Applications must be able to reach the database through the prepared private path.

References