Skip to main content
See All Integrations

PostgreSQL

Protect access to PostgreSQL services through Pomerium TCP routes.

First-party Pomerium connection guide

Categories
Databases, Non-HTTP Services

Overview

PostgreSQL, also called Postgres, is an open-source object-relational database system. Clients and servers use the PostgreSQL frontend/backend protocol over TCP or a local socket. Pomerium can protect a PostgreSQL TCP endpoint without exposing the database to a broad network.

Database ports carry sensitive administrative and application traffic. A Pomerium TCP route adds identity-aware policy before a client can establish a tunnel to the private database. PostgreSQL then applies its normal database authentication and authorization controls.

Pomerium provides an authenticated transport path. It does not assign PostgreSQL roles, rotate database passwords, or replace PostgreSQL access rules.

How it works

Create a Pomerium route with a tcp+https public address and a tcp PostgreSQL upstream address. Attach the required Pomerium access policy.

The user starts a local tunnel with Pomerium CLI or Pomerium Desktop. The client opens a loopback listener. The user points psql, a database tool, or an application driver at that local address.

Pomerium encrypts traffic between the user and the Pomerium gateway. Configure PostgreSQL TLS when the deployment also needs encryption and server verification between Pomerium and PostgreSQL.

Example

A database administrator starts a local tunnel for the protected PostgreSQL route with Pomerium CLI or Desktop. The administrator then connects psql to the local listener. Pomerium authenticates the user and checks route policy when the tunnel starts. PostgreSQL authenticates the database account and controls permitted SQL operations.

Considerations

  • Pomerium does not inspect or filter SQL statements.
  • PostgreSQL authentication, roles, passwords, certificates, and pg_hba.conf rules still apply.
  • Pomerium checks policy when the TCP connection starts.
  • A long-running connection does not end automatically after a later policy change.

Sources and official resources

  • Protect access to pgAdmin 4 when it runs in server mode as an upstream web application.

  • Connect DBeaver to protected database services through Pomerium TCP routes.

  • Protect access to MySQL services through Pomerium TCP routes.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo