PostgreSQL TLS variables stop startup
This page helps you start the auth server when PostgreSQL’s PGSSL environment variables cause a configuration refusal.
What you see
Section titled “What you see”With GOIABADA_DB_TYPE=postgres, the auth server won’t start while one of these variables is set and not empty: PGSSLMODE, PGSSLROOTCERT, PGSSLCERT, PGSSLKEY, PGSSLPASSWORD, PGSSLSNI or PGSSLNEGOTIATION. It prints one malformed configuration: line naming each variable, never its value, and exits with status 2. For example:
malformed configuration: PGSSLMODE is set, which the auth server no longer reads: unset it and set GOIABADA_DB_TLS_MODE (--db-tls-mode) insteadmalformed configuration: PGSSLROOTCERT is set, which the auth server no longer reads: unset it and set GOIABADA_DB_TLS_CA_FILE (--db-tls-ca-file) instead
Fix the configuration
Section titled “Fix the configuration”-
Unset each variable the line names, wherever the auth server’s environment comes from: the Compose file,
goiabada.env, or the auth server’s ConfigMap. -
Set
GOIABADA_DB_TLS_MODEto the protection your database needs. Where the database sits explains the five modes. Onlyverify-fullchecks the database’s certificate and host name. -
For
verify-caorverify-full, setGOIABADA_DB_TLS_CA_FILEif the certificate’s signing authority isn’t in the system’s roots. -
Restart the auth server.
The auth server presents no client certificate, so PGSSLCERT, PGSSLKEY and PGSSLPASSWORD have nothing to replace them.