Severity Framework
Snyk CCSS
Rule category
Logging / Configuration
Is your enviroment affected by this misconfiguration?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsFrameworks
CIS-Controls
CIS-Google
HIPAA
ISO-27001
NIST-800-53
SOC-2
- Snyk ID SNYK-CC-00363
- credit Snyk Research Team
Description
The PostgreSQL database instance flag 'log_disconnections' causes session terminations to be logged. This data is useful for troubleshooting and identifying unusual activity. This flag and the 'log_connections' flag are typically used together.
How to fix?
Set the settings.database_flags.name
attribute to "log_disconnections"
and settings.database_flags.value
attribute to "on"
.
Example Configuration
resource "google_sql_database_instance" "allowed" {
name = "master-instance"
database_version = "POSTGRES_11"
region = "us-central1"
settings {
tier = "db-f1-micro"
database_flags {
name = "log_disconnections"
value = "on"
}
}
}