Cloud SQL instances must have backups enabled so you can recover from accidental deletion, data corruption, or ransomware. Without backups, data loss can be permanent and service restoration time increases.
For Ansible resources using google.cloud.gcp_sql_instance or gcp_sql_instance, ensure the settings.backup_configuration.enabled property is present and set to true. Resources missing settings, settings.backup_configuration, or settings.backup_configuration.enabled, or where enabled is false, are flagged.
Secure configuration example:
- name:Create Cloud SQL instance with backups enabledgoogle.cloud.gcp_sql_instance:name:my-instancesettings:tier:db-f1-microbackup_configuration:enabled:truestart_time:"03:00"
Compliant Code Examples
- name:create a instancegoogle.cloud.gcp_sql_instance:name:'{{ resource_name }}-2'settings:backup_configuration:binary_log_enabled:yesenabled:yestier:db-n1-standard-1region:us-central1project:test_projectauth_kind:serviceaccountservice_account_file:/tmp/auth.pemstate:present
Non-Compliant Code Examples
---- name:create a instancegoogle.cloud.gcp_sql_instance:name:"{{ resource_name }}-2"region:us-central1project:test_projectauth_kind:serviceaccountservice_account_file:"/tmp/auth.pem"state:present- name:create a second instancegoogle.cloud.gcp_sql_instance:name:"{{ resource_name }}-2"settings:tier:db-n1-standard-1region:us-central1project:test_projectauth_kind:serviceaccountservice_account_file:"/tmp/auth.pem"state:present- name:create a third instancegoogle.cloud.gcp_sql_instance:name:"{{ resource_name }}-2"settings:backup_configuration:binary_log_enabled:yestier:db-n1-standard-1region:us-central1project:test_projectauth_kind:serviceaccountservice_account_file:"/tmp/auth.pem"state:present- name:create a forth instancegoogle.cloud.gcp_sql_instance:name:"{{ resource_name }}-2"settings:backup_configuration:binary_log_enabled:yesenabled:notier:db-n1-standard-1region:us-central1project:test_projectauth_kind:serviceaccountservice_account_file:"/tmp/auth.pem"state:present
1
2
rulesets:- Ansible / GCP # Rules to enforce / GCP.
맞춤형 데모 요청
Datadog 시작하기
Ask AI
AI-generated responses may be inaccurate. Verify important info.