Sitelet https://github.com/cybertec-postgresql/pgwatch/pull/796
Skip to content

[+] add TLS encryption to RPC channel - #796

Merged
pashagolub merged 6 commits into
cybertec-postgresql:masterfrom
0xgouda:tls-client
Jun 18, 2025
Merged

pashagolub merged 6 commits into
cybertec-postgresql:masterfrom
0xgouda:tls-client

Conversation

@0xgouda

@0xgouda 0xgouda commented Jun 11, 2025

Copy link
Copy Markdown
Collaborator

add new root-ca $PW_RPC_ROOT_CA flag for CA file path.
use tls package to listen for connection and add user provided CA as a trusted authority.
add rpc_tests_sinks dir containing test-only certificates to use in rpc_test.go

@coveralls

coveralls commented Jun 11, 2025 •

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 15727504734

Details

  • 29 of 35 (82.86%) changed or added relevant lines in 2 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage increased (+0.1%) to 61.287%

Changes Missing Coverage Covered Lines Changed/Added Lines %
internal/sinks/rpc.go 28 34 82.35%
Totals Coverage Status
Change from base Build 15705150926: 0.1%
Covered Lines: 2742
Relevant Lines: 4474

馃挍 - Coveralls

@pashagolub

Copy link
Copy Markdown
Collaborator

Thanks for the PR.

I don't want to add additional option. I want all needed options for sinks to be present in the connection url.

For example, if one wants to use root CA with Postgres connection, they will just use sslrootcert option in connection string, e.g.

pgwatch .. --sink=postgresql://user@host/dbname?sslrootcert=filename

I want to use the same approach for all sinks, so we don't bloat cmd options. This situation will hit us hard if one want to use two or more sinks but with different option values.

Comment thread internal/sinks/rpc.go Outdated
Comment thread internal/sinks/rpc.go Outdated
Comment thread internal/sinks/rpc.go Outdated
@pashagolub pashagolub self-assigned this Jun 13, 2025
@pashagolub pashagolub added enhancement New feature or request sinks Where and how to store monitored data labels Jun 13, 2025
0xgouda added 6 commits June 18, 2025 10:12
add new `root-ca $PW_RPC_ROOT_CA` flag for CA file path.
use `tls` package to listen for connection and add user provided CA as a trusted authority.
add rpc_tests_sinks dir containing test-only certificates to use in rpc_test.go
@pashagolub

Copy link
Copy Markdown
Collaborator

Thanks a lot! Good job!

@pashagolub
pashagolub merged commit 8681001 into cybertec-postgresql:master Jun 18, 2025
@0xgouda
0xgouda deleted the tls-client branch June 20, 2025 11:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request sinks Where and how to store monitored data

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants