Docs

Browse releases →

postgresql

PostgreSQL object-relational database server

postgresql

PostgreSQL object-relational database server

18.6 · aarch64-darwin

Authentication and TLS

Host authentication rules are ordered and typed. Bootstrap, replication, certificate, private-key, and CA values use opaque credential references and never enter generated files.

Initialization and lifecycle

The database cluster is initialized once in durable package state. Desired changes conservatively restart the server because not every PostgreSQL parameter is safely reloadable.

Additional settings

postgresql.settings is reserved for non-secret parameters without a dedicated option. Dedicated or credential-bearing settings cannot be overridden through that map.

postgresql.tls

OptionTypeDescription
casubmodule or nullOptional opaque reference to the client-certificate CA bundle.
certificatesubmodule or nullOpaque reference to the PEM server certificate.
enablebooleanEnable TLS for TCP connections.
minimumProtocolone of ["TLSv1.2","TLSv1.3"]Minimum accepted TLS protocol version.
privateKeysubmodule or nullOpaque reference to the PEM server private key.