Comparison route

Single service comparison

Back to main page

Database Security

Cloud SQL Security Insights

Security and audit controls layered over Google Cloud SQL managed databases. The operating model is in-product posture and audit telemetry rather than a separate inline appliance: IAM-based access, Cloud Logging and Audit Logs export, Cloud KMS-backed encryption, and recommended hardening surfaced through Security Command Center. Insights are derived from native managed-database metadata and IAM context, not from a dedicated audit gateway deployed alongside the instance.

Google Cloud logo

Google Cloud

Service information

Cloud SQL Security Insights iconCloud SQL Security Insights

Shortname: SQL Security

Huawei equivalent shortnames: DBSS

Keywords: database security, audit, protection, compliance

Differences vs Huawei

Cloud SQL security is delivered as embedded features in a managed database plus cloud-native telemetry, while Huawei DBSS is a standalone Database Security Service deployed in out-of-path mode that audits RDS, ECS and BMS databases as a separate resource. Google's control surface lives in the Cloud SQL/IAM/Logging APIs themselves; Huawei owns a distinct DBSS instance with its own console, ruleset, agents (for ECS/BMS and self-built) or agentless audit (MySQL, GaussDB for MySQL). Expect to operate and size a new service rather than toggle flags on the database.

Audit scope and integration differ. Cloud SQL relies on Cloud Logging/Audit Logs and IAM contexts for who/what/when, with downstream pipelines to BigQuery or SIEM. DBSS records sessions and SQL statements with peak QPS (6,000 Professional, 30,000 Advanced), stores hundreds of millions online and tens of billions archived SQL statements, and emits real-time alarms for risky operations and SQL injection. DBSS also offers encryption Series 1/2 proxy gateway and O&M control series, which are not one-to-one with Cloud SQL's built-in encryption and IAM.

Scaling, HA and responsibility shift. Google scales insights with the managed database region/quota and the logging backend; quotas are shared Cloud SQL/Logging limits. DBSS is independently sized by edition (1-6 / 1-30 instances, fixed vCPU/RAM/disk) and billed per month per instance regardless of audit volume peak. You assume responsibility for selecting an edition that sustains peak QPS, retaining audit logs to the 180-day compliance floor, and archiving beyond online storage capacities.

Migration to Huawei

Assessment and target choice: inventory each Cloud SQL instance and its IAM-based access, audit-log reliance, KMS keys, and any Security Command Center findings that depend on Cloud SQL metadata. Select DBSS Professional or Advanced based on peak SQL QPS, monthly statement volume, instance count, and 180-day retention. Because DBSS supports RDS and self-built databases on ECS/BMS for MySQL, Oracle, PostgreSQL, SQL Server and GaussDB, confirm DBSS supports the exact engine/version after any database engine move. Do not assume Cloud SQL cross-region HA equals DBSS HA; DBSS instances are independent resources sized to the workload.

Data and configuration migration: there is no one-click migration from Cloud SQL security posture to DBSS. Recreate IAM-equivalent least-privilege at the RDS level, re-key encryption via Huawei Cloud KMS, then onboard each database into DBSS by configuring audit in out-of-path mode (agentless for MySQL/GaussDB for MySQL, agent for self-built). Re-author SQL injection and risky-operation rules, privacy masking rules and report templates from scratch, since Cloud SQL does not expose equivalent rule sets to import.

Validation and cutover: run DBSS audit in parallel with the existing Cloud Logging pipeline, compare statement coverage, sensitive-field masking fidelity, and alarm latency for risky operations and SQL injection. Verify report completeness (session, risk distribution, slow SQL, dirty-table) against current GCP outputs and confirm archive plumbing for 180-day retention plus remote log storage before switching consumers.

Gaps and cost model changes: features that read native Cloud SQL metadata or Security Command Center posture won't be replicated; maintain those controls separately in Huawei Cloud via Security Console, IAM and Cloud Trace where applicable. Pricing shifts from in-database feature inclusion and log ingestion volume to a fixed monthly DBSS edition fee per instance, plus optional Database Encryption or Database O&M series and potential Huawei Data Security Center for discovery/masking. Rebuild TCO against peak QPS, instance count, and retention before production cutover.

Huawei Cloud logo

Huawei Cloud

Huawei equivalent service

Database Security Service iconDatabase Security Service

Shortname: DBSS

General function: Database Security

Database access audit and security protection.

Keywords: database security, audit, protection