Description
Setting internet_service to 1 on Tencent Cloud CDB enables an internet connection path to the database. Unnecessary public access can increase exposure to external scans and login attempts.
An internet path does not grant data access: authentication and database permissions still apply. Security groups and network settings also affect actual connectivity.
Potential impact
- External clients may attempt unnecessary database connections or logins.
- Misuse of leaked credentials or service vulnerabilities can lead to data reads, changes or deletion.
Remediation
If internet access is unnecessary, configure and test private connectivity for applications and administrators before setting internet_service to 0. Where public access is required, restrict security groups to approved clients and retain strong authentication and least-privilege data permissions. Verify legitimate connections and the blocking of unapproved access after the change.
Examples
These excerpts compare the internet-service setting on the same instance. Engine version and capacity are example values; use supported values and the required authentication and network configuration for deployment.
Before
resource "tencentcloud_mysql_instance" "app_db" {
internet_service = 1
engine_version = "5.7"
charge_type = "POSTPAID"
slave_deploy_mode = 0
instance_name = "tf-example-mysql"
mem_size = 4000
volume_size = 200
}
This enables an internet connection path. Also check the sources actually allowed and database permissions.
After
resource "tencentcloud_mysql_instance" "app_db" {
internet_service = 0
engine_version = "5.7"
charge_type = "POSTPAID"
slave_deploy_mode = 0
instance_name = "tf-example-mysql"
mem_size = 4000
volume_size = 200
}
This disables internet service. Required clients must be able to connect through the prepared private path.