Cloud SQL instances with a public IPv4 address assigned
What does ZopNight detect here?
Cloud SQL instances with `ipv4Enabled` set carry a static public IPv4 address that anyone on the internet can attempt to reach, limited only by authorized networks and database credentials. ZopNight flags every Cloud SQL instance with public IP turned on, as a critical compliance finding with no saving, and recommends moving clients to private IP.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-136 |
| Category | compliance |
| Severity | critical |
| Metric | none — pure configuration read |
| Threshold | public IPv4 enabled |
| Source | ZopNight |
| Permissions used | cloudsql.instances.list · cloudsql.instances.get |
Where it applies
What a public IP on Cloud SQL exposes
When public IP is on, Cloud SQL gives the instance a static public IPv4 address. The public IP configuration page explains that connections are then controlled by the authorized networks you add in CIDR notation, and that you should also enforce SSL on such an instance. The database port now lives on the internet. Its safety depends on nobody ever adding a broad range to authorized networks, and on every database password being strong and rotated.
Private IP avoids the question. An instance reachable only on its VPC address, through private services access, cannot be scanned or brute-forced from outside your network at all.
Listing instances with a public address
gcloud sql instances list \ --format="table(name, databaseVersion, settings.ipConfiguration.ipv4Enabled, ipAddresses)"True in the ipv4Enabled column means a public address is assigned. Then look at authorized
networks on each hit:
gcloud sql instances describe INSTANCE_NAME \ --format="yaml(settings.ipConfiguration.authorizedNetworks)"The condition that triggers it
ZopNight reads the instance’s IP configuration from the Cloud SQL Admin API. When that configuration says public IPv4 is enabled, the rule fires. It does not weigh the authorized networks list, the SSL mode or the engine. Public exposure is treated as a critical finding in its own right.
When the rule says nothing
The rule fires only on a confirmed “enabled” value. If the IP configuration was not collected, or the value is missing, it does not assume the instance is public. Private-IP-only instances are silent. Unencrypted connections are a separate concern, reported by GCP Cloud SQL Instance Does Not Require SSL.
Critical exposure with no saving
ZopNight reports a $0 saving. Google charges a small amount for the IP address while the instance is off, but the reason to fix this is attack surface, not cost: an internet-reachable database is open to probing by anyone who finds its address.
Moving an instance to private IP
-
Set up private services access for the VPC the clients run in, if it is not configured yet, following Google’s private IP steps.
-
Add private IP to the instance with
--network, and move every client to the private address. For laptops and CI, use the Cloud SQL Auth Proxy rather than authorized networks. -
Once nothing uses the public address, remove it:
Terminal window gcloud sql instances patch INSTANCE_NAME --no-assign-ip -
Confirm with the list command above that
ipv4Enabledis nowFalse.