Skip to content

Add TLS support for PostgreSQL connections - #110

Merged
popen2 merged 3 commits into
mainfrom
claude/database-tls-support-efpda0
Jun 13, 2026
Merged

popen2 merged 3 commits into
mainfrom
claude/database-tls-support-efpda0

Conversation

@popen2

@popen2 popen2 commented Jun 13, 2026 •

Copy link
Copy Markdown
Member

Platz connected to PostgreSQL without TLS: credentials and the
LISTEN/NOTIFY event stream traveled in plaintext, with no way to enable
encryption in transit. Because the backend assembles the connection URL
itself and does not link libpq, libpq-style controls (PGSSLMODE, ...) had
no effect.

Add a rustls-based TLS connector (tokio-postgres-rustls) wired into both
the diesel-async connection pool (via ManagerConfig::custom_setup) and the
dedicated tokio_postgres LISTEN/NOTIFY connection in events.rs.

TLS is configured via PGSSLMODE (mirroring libpq), defaulting to prefer
for opportunistic, backward-compatible encryption:

  • disable plaintext (previous behavior)
  • prefer use TLS if offered, else plaintext; cert not verified
  • require always TLS; cert not verified
  • verify-full always TLS; verify cert chain + hostname against the
    system trust store or PGSSLROOTCERT

Closes #104

Platz connected to PostgreSQL without TLS: credentials and the
LISTEN/NOTIFY event stream traveled in plaintext, with no way to enable
encryption in transit. Because the backend assembles the connection URL
itself and does not link libpq, libpq-style controls (PGSSLMODE, ...) had
no effect.

Add a rustls-based TLS connector (tokio-postgres-rustls) wired into both
the diesel-async connection pool (via ManagerConfig::custom_setup) and the
dedicated tokio_postgres LISTEN/NOTIFY connection in events.rs.

TLS is configured via PGSSLMODE (mirroring libpq), defaulting to `prefer`
for opportunistic, backward-compatible encryption:

  - disable      plaintext (previous behavior)
  - prefer       use TLS if offered, else plaintext; cert not verified
  - require      always TLS; cert not verified
  - verify-full  always TLS; verify cert chain + hostname against the
                 system trust store or PGSSLROOTCERT

Closes #104
@popen2
popen2 force-pushed the claude/database-tls-support-efpda0 branch from e65eb62 to 846e61a Compare June 13, 2026 13:19
claude added 2 commits June 13, 2026 13:28
Verifies the rustls connector against a running PostgreSQL: prefer/require
produce encrypted sessions (per pg_stat_ssl), verify-full succeeds when the
server CA is trusted, and verify-full rejects an untrusted certificate.

Skipped unless PLATZ_TLS_TEST_URL is set (PLATZ_TLS_TEST_CA points at the
server CA for the verify-full case), so it stays out of the default
`cargo test` run.
Replace the manually-gated live-server test with tests/tls_modes.rs, which
spins up a TLS-enabled PostgreSQL via testcontainers (minting its own
CA -> server chain with rcgen) and drives every PGSSLMODE end to end:
disable stays plaintext, prefer/require encrypt, and verify-full accepts a
trusted cert while rejecting an untrusted one. It also exercises the actual
diesel-async pool setup path. Skips cleanly when Docker is unavailable.

Expose the `tls` module and re-export SslMode/SslSettings so the test can
drive each mode (the global init_db can only initialize once per process).
Document the observed connectivity behavior in the tls module docs.

Derive SslMode's FromStr via strum instead of a hand-written impl.
@popen2
popen2 merged commit 1274e51 into main Jun 13, 2026
6 checks passed
@popen2
popen2 deleted the claude/database-tls-support-efpda0 branch June 13, 2026 16:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

Database connections to PostgreSQL are plaintext (no TLS support)

2 participants