You can create, enable, disable, modify, and delete blacklist rules in the PolarDB console. This topic describes blacklist rules and how to configure them.
Blacklist rules
The proxy provides a blocking feature. You can configure blacklist rules to block specific types of SQL statements or individual SQL statements.
You can configure blacklist rules in the following three modes:
-
fixed rule mode: A common mode for configuring blacklist rules in the console. Each rule can be applied to a specific account and cluster. For a list of supported common rules, see Configure SQL Firewall rules.
-
custom parameterized SQL mode: This mode parameterizes all variables in your SQL statements and saves the generated template to the database. The proxy then blocks any SQL statement that matches this template.
-
custom SQL mode: This mode blocks a specific SQL statement verbatim, without parameterizing any variables. SQL statements that have different parameters are not affected.
Create a blacklist rule
- Log on to the PolarDB console.
-
In the upper-left corner, select the region where the cluster is deployed.
-
Find the target cluster and click its ID.
-
In the left-side navigation pane, choose .
-
On the SQL Firewall tab, click Add on the left.
-
In the Create a Rule dialog box, configure the parameters based on your desired blacklist mode.
-
fixed rule mode
-
If you select fixed rule mode, configure the following parameters.
Table 1. Parameters for SQL Firewall rules Parameter
Required
Description
Basic Information
Rule Name
Yes
The name of the SQL Firewall rule. The name must meet the following requirements:
-
Consist of letters and digits.
-
Be up to 30 characters long.
Description
No
A description for easy identification and management.
NoteThe description can be up to 64 characters in length.
Endpoint
Yes
The endpoint to which the rule applies.
Configurations
Rule Type
Yes
Select Blacklist Rule.
Current Mode
No
The mode for the SQL Firewall rule. This is always set to Protection Mode, meaning SQL statements that match a blacklist rule are blocked.
Database Account Name
No
The database accounts to which this rule applies. The following options are available:
-
All Accounts: Applies the rule to all database accounts in the cluster. You do not need to enter anything in the text box.
-
Include: Applies the rule only to the specified database accounts. Enter one or more comma-separated account names.
-
Exclude: Applies the rule to all database accounts in the cluster except for the ones you specify. Enter one or more comma-separated account names.
NoteThe database account name that you enter must be in one of the following formats:
-
AccountName. Example:user. -
AccountName@IPAddress. Example:user@10.0.0.0.
Block SQLs With Asterisks (*)
No
Blocks SQL statements that contain an asterisk (
*). Valid values:-
Enable: Blocks SQL statements that contain an asterisk (
*). -
Close: Does not block SQL statements that contain an asterisk (
*).
Block SQLs of Specific Types
No
Blocks specific types of SQL statements. Valid values:
-
Enable: Blocks specific types of SQL statements. If you enable Block SQLs of Specific Types, you must select at least one type. Supported types:
-
CREATE -
DROP -
ALTER -
TRUNCATE -
RENAME -
INSERT -
UPDATE -
SELECT -
DELETE
-
-
Close: Does not block specific types of SQL statements.
Block SQLs Without WHERE
No
Blocks SQL statements that do not have a WHERE clause. Valid values:
-
Enable: Blocks specified types of SQL statements that do not have a WHERE clause. If you enable Block SQLs Without WHERE, you must select at least one type. Supported types:
-
UPDATE -
SELECT -
DELETE
-
-
Close: Does not block SQL statements that do not have a WHERE clause.
NoteThis parameter applies only to
SELECT,UPDATE, andDELETEstatements that contain at least one table name. The proxy does not block statements such asSELECT 1;.Block SQLs With Specific Columns
No
Blocks SQL statements that contain specific column names. Valid values:
-
Enable: Blocks SQL statements that contain specific column names. If you enable Block SQLs With Specific Columns, the following options are available:
-
All: Applies the rule to all column names in the cluster. You do not need to enter anything in the text box.
-
Include: Applies the rule only to the specified column names. You must enter one or more column names, separated by commas (,).
-
Exclude: Applies the rule to all column names in the cluster except for the ones you specify. You must enter one or more column names, separated by commas (,).
-
-
Close: Does not block SQL statements that contain specific column names.
Block SQLs With Specific Functions
No
Blocks SQL statements that use specific functions. Valid values:
-
Enable: Blocks SQL statements that use specific functions. If you enable Block SQLs With Specific Functions, the following options are available:
-
All: Applies the rule to all functions executed in the cluster's databases. You do not need to enter anything in the text box.
-
Include: Applies the rule only to the specified functions. You must enter one or more function names, separated by commas (,).
-
Exclude: Applies the rule to all functions except for the ones you specify. You must enter one or more function names, separated by commas (,).
-
-
Close: Does not block SQL statements that use specific functions.
Block SQLs With Specific Columns and Specific Functions
No
Blocks SQL statements that contain specific functions and reference specific column names. Valid values:
-
Enable: Blocks SQL statements that contain specific functions and reference specific column names. If you enable Block SQLs With Specific Columns and Specific Functions, you must enter one or more Function Name and Column Name values. Specifically:
-
If Function Name is set to Include and Column Name is also set to Include, the rule applies to SQL statements in the cluster that use a specific function and reference a specific column name.
-
If Function Name is set to Include and Column Name is set to Exclude, the rule applies to statements that use a specified function on any column except the ones specified.
-
If Function Name is set to Exclude and Column Name is set to Include, the rule applies to statements that use any function except the ones specified on a specified column.
-
If you select Exclude for Function Name and also select Exclude for Column Name, this means the rule applies to SQL statements in the cluster that use functions other than the specified ones and reference columns other than the specified ones.
-
-
Close: Does not block SQL statements that contain specific functions and reference specific column names.
-
-
After you configure the rule, click OK.
-
-
custom parameterized SQL mode
-
If you select custom parameterized SQL mode, configure the required parameters. For more information, see Parameters for SQL Firewall rules.
NoteWhen you use the custom parameterized SQL mode, you do not need to enable any blocking rules under Configurations.
-
After you configure the rule, click OK.
-
Use the Database Account Name from the previous step to connect to the specified database endpoint. To block an SQL statement, add the
hintcommand/* store_to_blacklist */before the statement. For example, to block the SQL statementselect id from sqlblack_test where id = 1;, run the following command:/* store_to_blacklist */ select id from sqlblack_test where id = 1;The parameterized template is as follows:
select id from sqlblack_test where id = ?In this template,
?represents any value.After about 5 seconds, the proxy blocks any SQL statement from this account that matches the template. The following error is returned:
ERROR 1141 (HY000): This SQL is rejected by SQL Firewall. Access denied for user 'xxx'@'x.x.x.x' to database 'xzh': This SQL is on blacklist bl_test.In this message,
bl_testis the name of the blacklist rule.
Note-
If you use the MySQL command-line client, you must add the
-coption. Otherwise, thehintcommand will not take effect. -
The rule takes effect after about 5 seconds.
-
-
custom SQL mode
-
If you select custom SQL mode, configure the required parameters. For more information, see Parameters for SQL Firewall rules.
NoteWhen you use the custom SQL mode, you do not need to enable any blocking rules under Configurations.
-
After you configure the rule, click OK.
-
Use the Database Account Name from the previous step to connect to the specified database endpoint. To block an SQL statement, add the
hintcommand/* orginal_store_to_blacklist */before the statement. For example, to block the statementupdate t set k = 2 where id = 2;, run the following command:/* orginal_store_to_blacklist */ update t set k = 2 where id = 2;After about 5 seconds, when you use this account to execute the exact SQL statement
update t set k = 2 where id = 2;, the proxy blocks the statement. Other SQL statements are not affected. The following error is returned:ERROR 1141 (HY000): This SQL is rejected by SQL Firewall. Access denied for user 'xxx'@'x.x.x.x' to database 'xzh': This SQL is on blacklist bl_test.In this message,
bl_testis the name of the blacklist rule.
Note-
If you use the MySQL command-line client, you must add the
-coption. Otherwise, thehintcommand will not take effect. -
The rule takes effect after about 5 seconds.
-
-
Enable or disable a blacklist rule
- Log on to the PolarDB console.
-
In the upper-left corner, select the region where the cluster is deployed.
-
Find the target cluster and click its ID.
-
In the left-side navigation pane, choose .
-
On the SQL Firewall tab, find the rule that you want to enable or disable and click the Enable/Disable switch.
NoteYou can also select multiple rules in the list and click Enable or Disable at the bottom of the list to enable or disable them in bulk.
-
In the Enable or Disable dialog box that appears, click OK.
Modify a blacklist rule
- Log on to the PolarDB console.
-
In the upper-left corner, select the region where the cluster is deployed.
-
Find the target cluster and click its ID.
-
In the left-side navigation pane, choose .
-
On the SQL Firewall tab, find the rule that you want to modify, and click Modify in the Operation column. In the Modify A Rule dialog box, modify the parameters. For details about the parameters, see Parameters for SQL Firewall rules.
NoteYou cannot modify a rule's Rule Name.
-
After you modify the rule, click OK.
From the console, you cannot modify parameterized SQL statements in rules created using custom parameterized SQL mode, nor can you modify specific SQL statements in rules created using custom SQL mode. To change these statements, you must delete them from the database table and add them again.
Delete a blacklist rule
- Log on to the PolarDB console.
-
In the upper-left corner, select the region where the cluster is deployed.
-
Find the target cluster and click its ID.
-
In the left-side navigation pane, choose .
-
On the SQL Firewall tab, find the rule that you want to delete and click Delete in the Operation column.
NoteYou can also select multiple rules in the list and click Delete at the bottom of the list to delete them in bulk.
-
In the Delete dialog box that appears, click OK.
Remove rules for custom modes
-
custom parameterized SQL mode blacklist rule
You can remove a custom parameterized SQL mode blacklist rule in one of the following ways:
-
You can remove a blacklist rule for the custom parameterized SQL mode by enabling or disabling a blacklist rule or deleting a blacklist rule.
NoteIf you only disable the blacklist rule in the console without deleting the corresponding parameterized SQL statement from the
proxy_auditing.sql_listtable, the rule takes effect again if you re-enable it for the same account. -
Connect to the primary node of the endpoint by using a super administrator account, and delete the corresponding SQL statement from the
proxy_auditing.sql_listtable. After about 5 seconds, the proxy will no longer block the statement.NoteDo not use the
DROPcommand to delete the table.
-
-
custom SQL mode blacklist rule
You can remove a custom SQL mode blacklist rule in one of the following ways:
-
To manage a custom SQL mode blacklist rule, you can enable or disable a blacklist rule or delete a blacklist rule.
NoteIf you only disable the blacklist rule in the console without deleting the corresponding SQL statement from the
proxy_auditing.org_sql_listtable, the rule takes effect again if you re-enable it for the same account. -
Connect to the primary node of the endpoint by using a super administrator account, and delete the corresponding SQL statement from the
proxy_auditing.org_sql_listtable. After about 5 seconds, the proxy will no longer block the statement.NoteDo not use the
DROPcommand to delete the table.
-