Review the default Tencent Cloud CDB intranet port

Manage the database port together with its access policy.

Description

CDB uses 3306 as the default MySQL intranet port. Using the default is not itself a vulnerability, and changing it does not replace authentication or network access controls.

Potential impact

Loose access controls can permit unwanted database connection attempts regardless of the port number.

Remediation

Set intranet_port according to operational policy and restrict permitted clients. If changing the port, update application connections and security group rules together.

Examples

These excerpts change the intranet port from 3306 to 3307 and omit other instance settings. The port change alone does not establish security.

Before

hcl
resource "tencentcloud_mysql_instance" "example" {
  instance_name   = "tf-example-mysql"
  mem_size        = 4000
  volume_size     = 200
  intranet_port   = 3306
  security_groups = [tencentcloud_security_group.security_group.id]
}

After

hcl
resource "tencentcloud_mysql_instance" "example" {
  instance_name   = "tf-example-mysql"
  mem_size        = 4000
  volume_size     = 200
  intranet_port   = 3307
  security_groups = [tencentcloud_security_group.security_group.id]
}

References