Skip to main content
compliance · gcp

Cloud SQL instances with a public IPv4 address assigned

resource types
1
rule IDs covered
1
severity
critical

What does ZopNight detect here?

Cloud SQL instances with `ipv4Enabled` set carry a static public IPv4 address that anyone on the internet can attempt to reach, limited only by authorized networks and database credentials. ZopNight flags every Cloud SQL instance with public IP turned on, as a critical compliance finding with no saving, and recommends moving clients to private IP.

Signal and threshold

How ZopNight evaluates Cloud SQL instances with a public IPv4 address assigned.
Field Value
Rule IDsRC-136
Categorycompliance
Severitycritical
Metricnone — pure configuration read
Thresholdpublic IPv4 enabled
SourceZopNight
Permissions usedcloudsql.instances.list · cloudsql.instances.get

What a public IP on Cloud SQL exposes

When public IP is on, Cloud SQL gives the instance a static public IPv4 address. The public IP configuration page explains that connections are then controlled by the authorized networks you add in CIDR notation, and that you should also enforce SSL on such an instance. The database port now lives on the internet. Its safety depends on nobody ever adding a broad range to authorized networks, and on every database password being strong and rotated.

Private IP avoids the question. An instance reachable only on its VPC address, through private services access, cannot be scanned or brute-forced from outside your network at all.

Listing instances with a public address

Terminal window
gcloud sql instances list \
--format="table(name, databaseVersion, settings.ipConfiguration.ipv4Enabled, ipAddresses)"

True in the ipv4Enabled column means a public address is assigned. Then look at authorized networks on each hit:

Terminal window
gcloud sql instances describe INSTANCE_NAME \
--format="yaml(settings.ipConfiguration.authorizedNetworks)"

The condition that triggers it

ZopNight reads the instance’s IP configuration from the Cloud SQL Admin API. When that configuration says public IPv4 is enabled, the rule fires. It does not weigh the authorized networks list, the SSL mode or the engine. Public exposure is treated as a critical finding in its own right.

When the rule says nothing

The rule fires only on a confirmed “enabled” value. If the IP configuration was not collected, or the value is missing, it does not assume the instance is public. Private-IP-only instances are silent. Unencrypted connections are a separate concern, reported by GCP Cloud SQL Instance Does Not Require SSL.

Critical exposure with no saving

ZopNight reports a $0 saving. Google charges a small amount for the IP address while the instance is off, but the reason to fix this is attack surface, not cost: an internet-reachable database is open to probing by anyone who finds its address.

Moving an instance to private IP

  1. Set up private services access for the VPC the clients run in, if it is not configured yet, following Google’s private IP steps.

  2. Add private IP to the instance with --network, and move every client to the private address. For laptops and CI, use the Cloud SQL Auth Proxy rather than authorized networks.

  3. Once nothing uses the public address, remove it:

    Terminal window
    gcloud sql instances patch INSTANCE_NAME --no-assign-ip
  4. Confirm with the list command above that ipv4Enabled is now False.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·