Add TLS support for PostgreSQL connections - #110
Merged
Merged
Conversation
Platz connected to PostgreSQL without TLS: credentials and the
LISTEN/NOTIFY event stream traveled in plaintext, with no way to enable
encryption in transit. Because the backend assembles the connection URL
itself and does not link libpq, libpq-style controls (PGSSLMODE, ...) had
no effect.
Add a rustls-based TLS connector (tokio-postgres-rustls) wired into both
the diesel-async connection pool (via ManagerConfig::custom_setup) and the
dedicated tokio_postgres LISTEN/NOTIFY connection in events.rs.
TLS is configured via PGSSLMODE (mirroring libpq), defaulting to `prefer`
for opportunistic, backward-compatible encryption:
- disable plaintext (previous behavior)
- prefer use TLS if offered, else plaintext; cert not verified
- require always TLS; cert not verified
- verify-full always TLS; verify cert chain + hostname against the
system trust store or PGSSLROOTCERT
Closes #104
popen2
force-pushed
the
claude/database-tls-support-efpda0
branch
from
June 13, 2026 13:19
e65eb62 to
846e61a
Compare
Verifies the rustls connector against a running PostgreSQL: prefer/require produce encrypted sessions (per pg_stat_ssl), verify-full succeeds when the server CA is trusted, and verify-full rejects an untrusted certificate. Skipped unless PLATZ_TLS_TEST_URL is set (PLATZ_TLS_TEST_CA points at the server CA for the verify-full case), so it stays out of the default `cargo test` run.
Replace the manually-gated live-server test with tests/tls_modes.rs, which spins up a TLS-enabled PostgreSQL via testcontainers (minting its own CA -> server chain with rcgen) and drives every PGSSLMODE end to end: disable stays plaintext, prefer/require encrypt, and verify-full accepts a trusted cert while rejecting an untrusted one. It also exercises the actual diesel-async pool setup path. Skips cleanly when Docker is unavailable. Expose the `tls` module and re-export SslMode/SslSettings so the test can drive each mode (the global init_db can only initialize once per process). Document the observed connectivity behavior in the tls module docs. Derive SslMode's FromStr via strum instead of a hand-written impl.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Platz connected to PostgreSQL without TLS: credentials and the
LISTEN/NOTIFY event stream traveled in plaintext, with no way to enable
encryption in transit. Because the backend assembles the connection URL
itself and does not link libpq, libpq-style controls (PGSSLMODE, ...) had
no effect.
Add a rustls-based TLS connector (tokio-postgres-rustls) wired into both
the diesel-async connection pool (via ManagerConfig::custom_setup) and the
dedicated tokio_postgres LISTEN/NOTIFY connection in events.rs.
TLS is configured via PGSSLMODE (mirroring libpq), defaulting to
preferfor opportunistic, backward-compatible encryption:
system trust store or PGSSLROOTCERT
Closes #104