Skip to content

fix(postgres): require TLS for query_render_postgres connections - #33

Open
aniruddhaadak80 wants to merge 1 commit into
render-oss:mainfrom
aniruddhaadak80:fix/postgres-require-tls
Open

aniruddhaadak80 wants to merge 1 commit into
render-oss:mainfrom
aniruddhaadak80:fix/postgres-require-tls

Conversation

@aniruddhaadak80

Copy link
Copy Markdown

What changed

  • query_render_postgres now parses the Render connection string via parsePostgresConnConfig, which enforces sslmode=require semantics: upgrades TLS-less configs and drops plaintext pgx fallbacks while keeping TLS multi-host fallbacks.
  • Added TestParsePostgresConnConfigEnforcesTLS covering no-sslmode, prefer, require, and disable inputs.

Why

Render-managed Postgres always requires SSL. pgx defaults to sslmode=prefer (TLS primary plus a plaintext fallback), so any TLS hiccup silently downgrades to an unencrypted attempt that the server rejects with FATAL: SSL/TLS required (SQLSTATE 28000). This matches the reports in #6 where psql works but query_render_postgres fails, especially on IP-allowlisted instances.

Repro (before fix, pgx.ParseConfig on postgres://user:pass@host.ohio-postgres.render.com:5432/mydb):

  • primary TLS nil: false, num fallbacks: 1, fallback 0 TLS nil: true
    After fix: primary TLS present, zero plaintext fallbacks.

How tested

  • go test ./pkg/postgres -count=1 -v (all pass, including new TestParsePostgresConnConfigEnforcesTLS 4/4)
  • go vet ./pkg/postgres ./pkg/validate clean
  • go build ./... clean

Fixes #6

Render-managed Postgres always requires SSL, but pgx defaults to
sslmode=prefer, leaving a plaintext fallback that silently downgrades
on any TLS hiccup and surfaces as FATAL: SSL/TLS required.

Parse via a helper that upgrades TLS-less configs and drops
plaintext fallbacks so IP-allowlisted instances connect like psql.

Fixes render-oss#6

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SSL/TLS Error for queries

1 participant