fix: disable PostgreSQL TLS for refusing RDS endpoint

This commit is contained in:
2026-08-16 23:26:03 +08:00
parent acf368b6fe
commit ed978142eb
17 changed files with 340 additions and 180 deletions

View File

@@ -43,8 +43,8 @@ ZHINIAN_DATA_BACKEND=local
DATABASE_URL=
# Migration runner only: PostgreSQL role used by the Go API DATABASE_URL.
DATABASE_APP_ROLE=
# Optional URL query for an explicit RDS CA, for example:
# postgresql://user:password@rds-host:5432/app?sslmode=verify-full&sslrootcert=/etc/zhinian/rds/ca.pem
# PostgreSQL transport is intentionally plaintext; clients force sslmode=disable.
# Example: postgresql://user:password@rds-host:5432/app?sslmode=disable
DATABASE_POOL_MAX=10
DATABASE_IDLE_TIMEOUT_MS=30000
DATABASE_CONNECTION_TIMEOUT_MS=5000