
PostgreSQL
Protect access to PostgreSQL services through Pomerium TCP routes.
Overview
PostgreSQL, also called Postgres, is an open-source object-relational database system. Clients and servers use the PostgreSQL frontend/backend protocol over TCP or a local socket. Pomerium can protect a PostgreSQL TCP endpoint without exposing the database to a broad network.
Database ports carry sensitive administrative and application traffic. A Pomerium TCP route adds identity-aware policy before a client can establish a tunnel to the private database. PostgreSQL then applies its normal database authentication and authorization controls.
Pomerium provides an authenticated transport path. It does not assign PostgreSQL roles, rotate database passwords, or replace PostgreSQL access rules.
How it works
Create a Pomerium route with a tcp+https public address and a tcp PostgreSQL upstream address. Attach the required Pomerium access policy.
The user starts a local tunnel with Pomerium CLI or Pomerium Desktop. The client opens a loopback listener. The user points psql, a database tool, or an application driver at that local address.
Pomerium encrypts traffic between the user and the Pomerium gateway. Configure PostgreSQL TLS when the deployment also needs encryption and server verification between Pomerium and PostgreSQL.
Example
A database administrator starts a local tunnel for the protected PostgreSQL route with Pomerium CLI or Desktop. The administrator then connects psql to the local listener. Pomerium authenticates the user and checks route policy when the tunnel starts. PostgreSQL authenticates the database account and controls permitted SQL operations.
Considerations
- Pomerium does not inspect or filter SQL statements.
- PostgreSQL authentication, roles, passwords, certificates, and pg_hba.conf rules still apply.
- Pomerium checks policy when the TCP connection starts.
- A long-running connection does not end automatically after a later policy change.
