ce42a9b984
continuous-integration/drone/push Build is passing
Update `docker-compose.yml` and `server/db.ts` to allow dynamic configuration of PostgreSQL SSL connections via the `DATABASE_SSL` environment variable. Add `DOCKER-DATABASE-SSL-GUIDE.md` detailing SSL options and troubleshooting. Replit-Commit-Author: Agent Replit-Commit-Session-Id: ceced2fc-aa46-458d-ba87-ddd4b7bb1518 Replit-Commit-Checkpoint-Type: full_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/659922a9-0087-461c-90dd-6d9a58b81d4d/ceced2fc-aa46-458d-ba87-ddd4b7bb1518/flNt5I4
301 lines
6.7 KiB
Markdown
301 lines
6.7 KiB
Markdown
# PostgreSQL SSL Configuration Guide 🔒
|
|
|
|
## The Issue
|
|
|
|
PostgreSQL servers have different SSL requirements:
|
|
- Some **require** SSL encryption
|
|
- Some **support** SSL but don't require it
|
|
- Some **don't support** SSL at all
|
|
|
|
Your TaskFlow application now supports all three scenarios via the `DATABASE_SSL` environment variable.
|
|
|
|
## How to Configure
|
|
|
|
### Option 1: No SSL (Default)
|
|
|
|
Use this for:
|
|
- ✅ Local PostgreSQL (docker-compose postgres container)
|
|
- ✅ PostgreSQL servers without SSL configured
|
|
- ✅ Development environments
|
|
|
|
**Configuration:**
|
|
```yaml
|
|
# docker-compose.yml or .env
|
|
DATABASE_SSL= # Leave unset or empty
|
|
```
|
|
|
|
**Or simply omit the variable entirely.**
|
|
|
|
### Option 2: SSL with Self-Signed Certificates
|
|
|
|
Use this for:
|
|
- ✅ PostgreSQL servers with self-signed certificates
|
|
- ✅ Internal/private PostgreSQL servers with SSL
|
|
- ✅ Cloud PostgreSQL with SSL enabled
|
|
|
|
**Configuration:**
|
|
```yaml
|
|
# docker-compose.yml or .env
|
|
DATABASE_SSL=true
|
|
```
|
|
|
|
### Option 3: SSL with Valid CA Certificates
|
|
|
|
Use this for:
|
|
- ✅ PostgreSQL servers with CA-signed certificates
|
|
- ✅ Public cloud databases (AWS RDS, Google Cloud SQL, etc.)
|
|
- ✅ Maximum security requirements
|
|
|
|
**Configuration:**
|
|
```yaml
|
|
# docker-compose.yml or .env
|
|
DATABASE_SSL=require
|
|
```
|
|
|
|
## How to Determine Which Option You Need
|
|
|
|
### Test Method 1: Check Error Messages
|
|
|
|
**Error: "no encryption" or "requires SSL"**
|
|
→ Use `DATABASE_SSL=true`
|
|
|
|
**Error: "does not support SSL"**
|
|
→ Use `DATABASE_SSL=` (unset) or leave blank
|
|
|
|
**Error: "certificate verify failed"**
|
|
→ Your server has invalid cert, use `DATABASE_SSL=true`
|
|
|
|
**No errors, but want encryption**
|
|
→ Try `DATABASE_SSL=true`
|
|
|
|
### Test Method 2: Try Connection
|
|
|
|
```bash
|
|
# Test without SSL
|
|
psql "postgresql://user:pass@host:5432/db?sslmode=disable"
|
|
|
|
# Test with SSL
|
|
psql "postgresql://user:pass@host:5432/db?sslmode=require"
|
|
```
|
|
|
|
If the second command works, use `DATABASE_SSL=true` or `DATABASE_SSL=require`.
|
|
|
|
## Deployment Scenarios
|
|
|
|
### Scenario 1: Using docker-compose.yml (Local PostgreSQL)
|
|
|
|
The included PostgreSQL container **does not** have SSL configured.
|
|
|
|
**Use:**
|
|
```yaml
|
|
environment:
|
|
DATABASE_URL: postgresql://taskflow:taskflow_password@postgres:5432/taskflow
|
|
DATABASE_SSL: # Leave empty (no SSL)
|
|
```
|
|
|
|
**Deploy:**
|
|
```bash
|
|
docker-compose up -d
|
|
```
|
|
|
|
### Scenario 2: External PostgreSQL (No SSL)
|
|
|
|
Your own PostgreSQL server without SSL.
|
|
|
|
**Use:**
|
|
```yaml
|
|
environment:
|
|
DATABASE_URL: postgresql://user:password@your-postgres-server:5432/taskflow
|
|
DATABASE_SSL: # Leave empty (no SSL)
|
|
```
|
|
|
|
### Scenario 3: External PostgreSQL (With SSL)
|
|
|
|
Your own PostgreSQL server with SSL enabled.
|
|
|
|
**Use:**
|
|
```yaml
|
|
environment:
|
|
DATABASE_URL: postgresql://user:password@your-postgres-server:5432/taskflow
|
|
DATABASE_SSL: true # Enable SSL
|
|
```
|
|
|
|
### Scenario 4: Cloud PostgreSQL (AWS RDS, etc.)
|
|
|
|
Cloud-hosted databases typically require SSL.
|
|
|
|
**Use:**
|
|
```yaml
|
|
environment:
|
|
DATABASE_URL: postgresql://user:password@your-rds-endpoint.amazonaws.com:5432/taskflow
|
|
DATABASE_SSL: true # Enable SSL
|
|
```
|
|
|
|
## For Your Current Setup
|
|
|
|
Based on the error "The server does not support SSL connections", your PostgreSQL server **does not have SSL configured**.
|
|
|
|
**Solution:**
|
|
|
|
1. **Option A: Keep SSL Disabled (Recommended)**
|
|
```bash
|
|
# Don't set DATABASE_SSL or set it to empty
|
|
DATABASE_SSL=
|
|
```
|
|
|
|
2. **Option B: Enable SSL on Your PostgreSQL Server**
|
|
|
|
If you need encryption, configure your PostgreSQL server to support SSL:
|
|
|
|
```bash
|
|
# On your PostgreSQL server
|
|
# Edit postgresql.conf
|
|
ssl = on
|
|
ssl_cert_file = 'server.crt'
|
|
ssl_key_file = 'server.key'
|
|
|
|
# Restart PostgreSQL
|
|
systemctl restart postgresql
|
|
```
|
|
|
|
## How the Code Works
|
|
|
|
```typescript
|
|
// server/db.ts
|
|
let sslConfig: any = false; // Default: no SSL
|
|
|
|
if (process.env.DATABASE_SSL === 'true') {
|
|
sslConfig = { rejectUnauthorized: false }; // SSL with self-signed certs
|
|
} else if (process.env.DATABASE_SSL === 'require') {
|
|
sslConfig = { rejectUnauthorized: true }; // SSL with valid certs only
|
|
}
|
|
|
|
pool = new Pool({
|
|
connectionString: databaseUrl,
|
|
ssl: sslConfig,
|
|
});
|
|
```
|
|
|
|
## Quick Fix for Your Deployment
|
|
|
|
**Update your deployment configuration:**
|
|
|
|
```yaml
|
|
# If using docker-compose
|
|
environment:
|
|
- DATABASE_URL=postgresql://taskflow:password@your-host:5432/taskflow
|
|
- DATABASE_SSL= # Empty = no SSL
|
|
|
|
# Or in your shell/environment
|
|
export DATABASE_SSL=
|
|
```
|
|
|
|
**Then redeploy:**
|
|
|
|
```bash
|
|
git add .
|
|
git commit -m "Configure PostgreSQL SSL settings"
|
|
git push
|
|
|
|
# After Drone CI builds
|
|
docker pull registry.local.nothaft.cloud/taskflow:latest
|
|
docker-compose up -d
|
|
```
|
|
|
|
## Expected Success Output
|
|
|
|
```
|
|
serving on port 5000
|
|
Checking database schema...
|
|
✓ Database schema is up to date
|
|
✓ Created default labels
|
|
✓ Database initialized successfully
|
|
```
|
|
|
|
## Troubleshooting
|
|
|
|
### Still Getting SSL Errors?
|
|
|
|
1. **Check your DATABASE_URL**
|
|
```bash
|
|
echo $DATABASE_URL
|
|
# Should not have sslmode parameter
|
|
```
|
|
|
|
2. **Verify DATABASE_SSL is not set**
|
|
```bash
|
|
echo $DATABASE_SSL
|
|
# Should be empty
|
|
```
|
|
|
|
3. **Test connection manually**
|
|
```bash
|
|
psql "$DATABASE_URL"
|
|
```
|
|
|
|
### Connection Refused
|
|
|
|
- ✅ Check PostgreSQL is running
|
|
- ✅ Check firewall allows port 5432
|
|
- ✅ Check DATABASE_URL has correct host/port
|
|
|
|
### Authentication Failed
|
|
|
|
- ✅ Check username in DATABASE_URL
|
|
- ✅ Check password in DATABASE_URL
|
|
- ✅ Check database exists
|
|
- ✅ Check user has permissions
|
|
|
|
## Security Considerations
|
|
|
|
### When to Use SSL
|
|
|
|
**Use SSL when:**
|
|
- ✅ Connecting over the internet
|
|
- ✅ Connecting across networks you don't control
|
|
- ✅ Regulatory compliance requires encryption
|
|
- ✅ Handling sensitive data
|
|
|
|
**SSL not required when:**
|
|
- ✅ PostgreSQL and app on same machine
|
|
- ✅ Both on same private network
|
|
- ✅ Using docker-compose with same network
|
|
- ✅ Local development
|
|
|
|
### Self-Signed vs CA Certificates
|
|
|
|
**`DATABASE_SSL=true` (self-signed)**
|
|
- Pro: Works with any SSL certificate
|
|
- Con: Doesn't verify server identity
|
|
- Use: Internal/private servers
|
|
|
|
**`DATABASE_SSL=require` (CA-signed)**
|
|
- Pro: Verifies server identity
|
|
- Con: Requires valid certificate
|
|
- Use: Public cloud, production
|
|
|
|
## Production Ready! 🎉
|
|
|
|
Your TaskFlow application now supports:
|
|
|
|
✅ **Any PostgreSQL configuration**
|
|
✅ **SSL or no SSL**
|
|
✅ **Self-signed or CA certificates**
|
|
✅ **Flexible deployment options**
|
|
|
|
**Status: Production Ready!** 🚀
|
|
|
|
## Summary
|
|
|
|
| PostgreSQL Type | DATABASE_SSL Setting | Use Case |
|
|
|----------------|---------------------|----------|
|
|
| Local docker-compose | _(unset)_ | Default setup |
|
|
| Internal server (no SSL) | _(unset)_ | Private network |
|
|
| Internal server (with SSL) | `true` | Encrypted internal |
|
|
| Cloud database | `true` | AWS RDS, etc. |
|
|
| High security | `require` | Valid cert only |
|
|
|
|
---
|
|
|
|
**Next Step:** Set `DATABASE_SSL` appropriately for your PostgreSQL server and redeploy!
|