You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Checkov检测GCP PostgreSQL的pgAudit与log_min_messages配置失败求助

Checkov检测失败问题排查(GCP PostgreSQL实例)

检测失败项

  • CKV_GCP_109:确保GCP PostgreSQL数据库日志级别设置为ERROR或更低
    • 失败资源:google_sql_database_instance.cloud_sql
    • 文件路径:/cloud_sql.tf:1-74
  • CKV_GCP_110:确保GCP PostgreSQL数据库启用pgAudit
    • 失败资源:google_sql_database_instance.cloud_sql
    • 文件路径:/cloud_sql.tf:1-74
  • CKV_GCP_55:确保PostgreSQL数据库log_min_messages标志设置为有效值
    • 失败资源:google_sql_database_instance.cloud_sql
    • 文件路径:/cloud_sql.tf:1-74

修改后的Terraform配置

resource "google_sql_database_instance" "cloud_sql" {
  name             = "cloud-sql"
  database_version = "POSTGRES_15"
  region           = var.region
  project          = var.project_id

  settings {
    tier = "db-f1-micro"

    backup_configuration {
      enabled = true
    }
    ip_configuration {
      ipv4_enabled = false
      require_ssl     = false
      private_network = "projects/${var.project_id}/global/networks/${var.network}"
    }
    database_flags {
      name  = "log_statement"
      value = "all"
    }
    database_flags {
      name  = "log_lock_waits"
      value = "on"
    }
    database_flags {
      name  = "log_connections"
      value = "on"
    }
    database_flags {
      name  = "log_checkpoints"
      value = "on"
    }
    database_flags {
      name  = "log_disconnections"
      value = "on"
    }
    database_flags {
      name  = "log_hostname"
      value = "on"
    }
    database_flags {
      name  = "log_min_error_statement"
      value = "ERROR"
    }
    database_flags {
      name  = "log_min_messages"
      value = "ERROR"
    }
#    database_flags {
#      name  = "log_min_messages"
#      value = "DEBUG5"
#    }
#    database_flags {
#      name  = "enable_pgaudit"
#      value = "on"
#    }
    database_flags {
      name  = "pgaudit.log"
      value = "'all'"
    }
    database_flags {
      name  = "log_duration"
      value = "on"
    }
  }
  deletion_protection = false
  depends_on          = [google_service_networking_connection.private_vpc_connection]
}

已尝试的调整措施

针对CKV_GCP_110(pgAudit启用)

  • 添加enable_pgaudit数据库标志:
    database_flags {
      name  = "enable_pgaudit"
      value = "on"
    }
    
  • 移除pgaudit.log值中的单引号:
    database_flags {
      name  = "pgaudit.log"
      value = "all"  // 原配置为"'all'"
    }
    

针对CKV_GCP_109和CKV_GCP_55(日志级别配置)

  • 尝试将log_min_messages设置为ERROR、DEBUG5等不同取值
  • 添加log_min_error_statement配置并设置为ERROR

以上调整均未解决检测失败问题。

内容的提问来源于stack exchange,提问作者Marcin Kulik

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 19:53:16