Serve TLS from the local dev Postgres - #9
Merged
Merged
Conversation
Enable TLS on the in-cluster Postgres so local dev exercises the backend's new PostgreSQL TLS support (PGSSLMODE). An init container generates a self-signed server certificate (owned by the postgres uid, 0600 perms) and the server starts with ssl=on. The backend defaults to PGSSLMODE=prefer, so the local workers now connect over TLS automatically with no extra configuration. Documented the TLS behavior and how to verify an encrypted connection in the README.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Enable TLS on the in-cluster Postgres so local dev exercises the backend's
new PostgreSQL TLS support (
PGSSLMODE). An init container generates aself-signed server certificate (owned by the postgres uid, 0600 perms) and
the server starts with
ssl=on.The backend defaults to
PGSSLMODE=prefer, so the local workers now connectover TLS automatically with no extra configuration. The README documents the
TLS behavior and how to verify an encrypted connection.
Companion to platzio/backend#110, which adds the TLS support itself.
Generated by Claude Code