Severity Framework
Snyk CCSS
Rule category
Logging / Configuration
Is your enviroment affected by this misconfiguration?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsFrameworks
CIS-Controls
CIS-Google
HIPAA
ISO-27001
NIST-800-53
SOC-2
- Snyk ID SNYK-CC-00357
- credit Snyk Research Team
Description
The PostgreSQL database instance flag 'log_lock_waits' causes a session wait to be logged if it takes longer than the 'deadlock_timeout' value to acquire a lock. This is useful to identify poor performance due to locking delays or if a specially-crafted SQL query is attempting to starve resources through holding locks for excessive amounts of time.
How to fix?
Set settings.database_flags.name
attribute to "log_lock_waits"
, and settings.database_flags.value
attribute to "on"
.
Example Configuration
resource "google_sql_database_instance" "allowed" {
name = "master-instance"
database_version = "POSTGRES_11"
region = "us-central1"
settings {
tier = "db-f1-micro"
database_flags {
name = "log_lock_waits"
value = "on"
}
}
}