Skip to content

Commit 497fa51

Browse files
committed
fix: enforce PostgreSQL SCRAM authentication
1 parent 2c929d9 commit 497fa51

2 files changed

Lines changed: 20 additions & 1 deletion

File tree

‎root/usr/local/bin/app-healthcheck‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,11 @@
11
#!/usr/bin/env bash
22
set -euo pipefail
3+
4+
. /usr/local/bin/file-env
5+
6+
if [[ -n "${POSTGRES_PASSWORD:-}" ]]; then
7+
export PGPASSWORD="$POSTGRES_PASSWORD"
8+
exec psql -h 127.0.0.1 -p 5432 -U "${POSTGRES_USER:-postgres}" -d "${POSTGRES_DB:-postgres}" -tAc 'SELECT 1;' >/dev/null
9+
fi
10+
311
exec pg_isready -h 127.0.0.1 -p 5432 -U "${POSTGRES_USER:-postgres}"

‎root/usr/local/bin/start-app‎

Lines changed: 12 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,18 @@ if [[ ! -s "$PGDATA/PG_VERSION" ]]; then
2424
echo "unix_socket_directories = '/run/postgresql'"
2525
} >> "$PGDATA/postgresql.conf"
2626

27-
echo "host all all all scram-sha-256" >> "$PGDATA/pg_hba.conf"
27+
cat > "$PGDATA/pg_hba.conf" <<'EOF'
28+
# Local socket access is allowed for the container runtime user.
29+
local all all trust
30+
# TCP access must authenticate with SCRAM.
31+
host all all 127.0.0.1/32 scram-sha-256
32+
host all all ::1/128 scram-sha-256
33+
host all all all scram-sha-256
34+
EOF
35+
36+
{
37+
echo "password_encryption = 'scram-sha-256'"
38+
} >> "$PGDATA/postgresql.conf"
2839

2940
if [[ -n "${POSTGRES_PASSWORD:-}" ]]; then
3041
echo "Setting initial PostgreSQL password for $POSTGRES_USER"

0 commit comments

Comments
 (0)