From 60a22cc6dc670cfd800aa0a6c571acecc24cc1b0 Mon Sep 17 00:00:00 2001 From: Lev Kokotov Date: Mon, 5 Oct 2026 21:28:29 -0700 Subject: [PATCH 1/2] feat: add identity and tlsClientCaCertificate --- Chart.yaml | 4 ++-- templates/config.yaml | 3 +++ templates/secrets.yaml | 3 +++ test/values-tls-paths.yaml | 6 ++++++ values.yaml | 5 +++++ 5 files changed, 19 insertions(+), 2 deletions(-) diff --git a/Chart.yaml b/Chart.yaml index 78f3585..bc67cf2 100644 --- a/Chart.yaml +++ b/Chart.yaml @@ -1,4 +1,4 @@ apiVersion: v1 name: pgdog -version: v0.83 -appVersion: "v0.1.58" +version: v0.84 +appVersion: "v0.1.60" diff --git a/templates/config.yaml b/templates/config.yaml index 67af5bf..552e46f 100644 --- a/templates/config.yaml +++ b/templates/config.yaml @@ -87,6 +87,9 @@ data: tls_private_key = {{ .Values.tlsPrivateKey | quote }} {{- end }} {{- end }} + {{- if .Values.tlsClientCaCertificate }} + tls_client_ca_certificate = {{ .Values.tlsClientCaCertificate | quote }} + {{- end }} {{- if hasKey .Values "tlsClientRequired" }} tls_client_required = {{ .Values.tlsClientRequired }} {{- end }} diff --git a/templates/secrets.yaml b/templates/secrets.yaml index 9000d3f..d71a6b6 100644 --- a/templates/secrets.yaml +++ b/templates/secrets.yaml @@ -3,6 +3,9 @@ [[users]] name = {{ .name | quote }} database = {{ .database | quote }} +{{- if .identity }} +identity = {{ .identity | quote }} +{{- end }} {{- if .passwords }} passwords = [{{ range $i, $p := .passwords }}{{ if $i }}, {{ end }}{{ $p | quote }}{{ end }}] {{- else if .password }} diff --git a/test/values-tls-paths.yaml b/test/values-tls-paths.yaml index f9a65f1..00014ea 100644 --- a/test/values-tls-paths.yaml +++ b/test/values-tls-paths.yaml @@ -1,8 +1,14 @@ # Test explicit TLS path settings in pgdog.toml. tlsCertificate: /etc/ssl/certs/ssl-cert-snakeoil.pem tlsPrivateKey: /etc/ssl/private/ssl-cert-snakeoil.key +tlsClientCaCertificate: /etc/ssl/certs/ca-certificates.crt tlsServerCaCertificate: /etc/ssl/certs/ca-certificates.crt +users: + - name: app + database: primary + identity: app + databases: - name: primary host: postgres.example.com diff --git a/values.yaml b/values.yaml index be912f3..0214421 100644 --- a/values.yaml +++ b/values.yaml @@ -246,6 +246,7 @@ databases: [] # users contains the list of user entries in users.toml # Supports all arguments from users.toml. Arguments are named in # camelCase format. +# Set identity on a user to match the identity in its client TLS certificate. users: [] # mirrors contains a list of databases to replicate traffic from/to. @@ -619,6 +620,10 @@ control: # Note: certificates are regenerated on every helm upgrade. # tlsGenerateSelfSignedCert: false +# tlsClientCaCertificate is the path to the CA certificate used to verify +# client TLS certificates. Mount it with extraVolumes/extraVolumeMounts. +# tlsClientCaCertificate: /etc/pgdog-client-ca/ca.crt + # rdsCertificateBundle includes the AWS RDS CA certificate bundle so pgdog can # verify TLS connections to RDS/Aurora instances. When enabled, # tls_server_ca_certificate is automatically configured in pgdog.toml. From 39a94d30d07332b344a1a71314951b5c61de2490 Mon Sep 17 00:00:00 2001 From: Lev Kokotov Date: Mon, 5 Oct 2026 22:04:29 -0700 Subject: [PATCH 2/2] settings --- templates/config.yaml | 12 ++++++++++++ test/values-tls-paths.yaml | 4 ++++ values.yaml | 8 ++++++++ 3 files changed, 24 insertions(+) diff --git a/templates/config.yaml b/templates/config.yaml index 552e46f..838f5e1 100644 --- a/templates/config.yaml +++ b/templates/config.yaml @@ -101,6 +101,12 @@ data: {{- else if .Values.tlsServerCaCertificate }} tls_server_ca_certificate = {{ .Values.tlsServerCaCertificate | quote }} {{- end}} + {{- if .Values.tlsServerCertificate }} + tls_server_certificate = {{ .Values.tlsServerCertificate | quote }} + {{- end }} + {{- if .Values.tlsServerPrivateKey }} + tls_server_private_key = {{ .Values.tlsServerPrivateKey | quote }} + {{- end }} {{- if hasKey .Values "shutdownTimeout" }} shutdown_timeout = {{ include "pgdog.intval" .Values.shutdownTimeout }} {{- end }} @@ -352,6 +358,12 @@ data: {{- if hasKey . "lbWeight" }} lb_weight = {{ include "pgdog.intval" .lbWeight }} {{- end }} + {{- if .tlsServerCertificate }} + tls_server_certificate = {{ .tlsServerCertificate | quote }} + {{- end }} + {{- if .tlsServerPrivateKey }} + tls_server_private_key = {{ .tlsServerPrivateKey | quote }} + {{- end }} {{- end }} {{- range .Values.mirrors }} diff --git a/test/values-tls-paths.yaml b/test/values-tls-paths.yaml index 00014ea..d923115 100644 --- a/test/values-tls-paths.yaml +++ b/test/values-tls-paths.yaml @@ -3,6 +3,8 @@ tlsCertificate: /etc/ssl/certs/ssl-cert-snakeoil.pem tlsPrivateKey: /etc/ssl/private/ssl-cert-snakeoil.key tlsClientCaCertificate: /etc/ssl/certs/ca-certificates.crt tlsServerCaCertificate: /etc/ssl/certs/ca-certificates.crt +tlsServerCertificate: /etc/ssl/certs/ssl-cert-snakeoil.pem +tlsServerPrivateKey: /etc/ssl/private/ssl-cert-snakeoil.key users: - name: app @@ -13,3 +15,5 @@ databases: - name: primary host: postgres.example.com port: 5432 + tlsServerCertificate: /etc/ssl/certs/ssl-cert-snakeoil.pem + tlsServerPrivateKey: /etc/ssl/private/ssl-cert-snakeoil.key diff --git a/values.yaml b/values.yaml index 0214421..c9bee14 100644 --- a/values.yaml +++ b/values.yaml @@ -241,6 +241,8 @@ loadBalancingStrategy: round_robin # databases contains the list of database entries in pgdog.toml # Supports all arguments from pgdog.toml. Arguments are named in # camelCase format. +# Set tlsServerCertificate and tlsServerPrivateKey on a database to use +# a different certificate and key for its PostgreSQL connections. databases: [] # users contains the list of user entries in users.toml @@ -624,6 +626,12 @@ control: # client TLS certificates. Mount it with extraVolumes/extraVolumeMounts. # tlsClientCaCertificate: /etc/pgdog-client-ca/ca.crt +# tlsServerCertificate and tlsServerPrivateKey are paths to the certificate +# and private key PgDog presents when authenticating to PostgreSQL with mTLS. +# Mount these files with extraVolumes/extraVolumeMounts. +# tlsServerCertificate: /etc/pgdog-server-tls/tls.crt +# tlsServerPrivateKey: /etc/pgdog-server-tls/tls.key + # rdsCertificateBundle includes the AWS RDS CA certificate bundle so pgdog can # verify TLS connections to RDS/Aurora instances. When enabled, # tls_server_ca_certificate is automatically configured in pgdog.toml.