Postgres HA with REpmgr SSL

Hello, It looks like the Postgres HA with Repmgr template does not offer SSL by default and somehow it's still on Postgres 16. It there anyway this template could be updated to provide SSL and or be upgraded to Postgres 17? This Postgres template does come with SSL, but it does not come with HA 😦
13 Replies
Percy
Percyβ€’2mo ago
Project ID: 90b250a0-d964-46d1-9dab-8ea9d25584e5
Stevenson Michel
Stevenson MichelOPβ€’2mo ago
Project ID 90b250a0-d964-46d1-9dab-8ea9d25584e5
Brody
Brodyβ€’2mo ago
we are likely going to be keeping that template on 16 for the time being, as for SSL, it is not needed as long as you connect over the private network
Stevenson Michel
Stevenson MichelOPβ€’2mo ago
hmm, I think TLS termination should happen at least at pgpool wether or not connection is done via the private or public network.
Brody
Brodyβ€’2mo ago
there is no benefit to that since the private network is an encrypted wireguard tunnel
Stevenson Michel
Stevenson MichelOPβ€’2mo ago
hmm, I still see the use case for the public connection.
Brody
Brodyβ€’2mo ago
what's the usecase for connecting publicly?
Stevenson Michel
Stevenson MichelOPβ€’2mo ago
The connection is not encrypted.
Brody
Brodyβ€’2mo ago
hmmm not sure how that answers my question
Stevenson Michel
Stevenson MichelOPβ€’2mo ago
One use case for connecting publicly is that I have batch jobs that run outside of railway.
Brody
Brodyβ€’2mo ago
why can't those be ran within railway?
Stevenson Michel
Stevenson MichelOPβ€’2mo ago
The jobs will need to move off Google Dataflow first before they can be run within railway. Is there any specific reason why a self signed certificate is not generated for PGPool?
Brody
Brodyβ€’2mo ago
because pgpool does not generate a certificate
Want results from more Discord servers?
Add your server