fix: disable PostgreSQL TLS for refusing RDS endpoint
This commit is contained in:
@@ -63,9 +63,6 @@ spec:
|
||||
name: zhinian-go-bootstrap
|
||||
key: ZHINIAN_BOOTSTRAP_ADMIN_PASSWORD
|
||||
volumeMounts:
|
||||
- name: rds-ca
|
||||
mountPath: /etc/zhinian/rds
|
||||
readOnly: true
|
||||
- name: data
|
||||
mountPath: /var/lib/zhinian
|
||||
- name: tmp
|
||||
@@ -106,9 +103,6 @@ spec:
|
||||
runAsGroup: 10001
|
||||
readOnlyRootFilesystem: true
|
||||
volumes:
|
||||
- name: rds-ca
|
||||
secret:
|
||||
secretName: zhinian-rds-ca
|
||||
- name: data
|
||||
emptyDir: {}
|
||||
- name: tmp
|
||||
|
||||
@@ -3,24 +3,13 @@
|
||||
# intentionally not injected by the minimal production Deployment.
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: zhinian-rds-ca
|
||||
namespace: zhinian
|
||||
type: Opaque
|
||||
stringData:
|
||||
# Public CA certificate for the RDS endpoint used in DATABASE_URL.
|
||||
ca.pem: |
|
||||
REPLACE_WITH_RDS_CA_PEM
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: zhinian-migration-db
|
||||
namespace: zhinian
|
||||
type: Opaque
|
||||
stringData:
|
||||
# Manual schema execution only: run database/migrations/*.sql with this role.
|
||||
DATABASE_URL: "postgresql://MIGRATION_USER:MIGRATION_PASSWORD@RDS_INTERNAL_HOST:5432/APP_DATABASE?sslmode=verify-full&sslrootcert=/etc/zhinian/rds/ca.pem"
|
||||
# Manual schema execution only. This connection intentionally uses plaintext.
|
||||
DATABASE_URL: "postgresql://MIGRATION_USER:MIGRATION_PASSWORD@RDS_INTERNAL_HOST:5432/APP_DATABASE?sslmode=disable"
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
@@ -40,8 +29,8 @@ metadata:
|
||||
namespace: zhinian
|
||||
type: Opaque
|
||||
stringData:
|
||||
# Application role (least privilege): grants applied manually after the SQL.
|
||||
DATABASE_URL: "postgresql://APP_USER:APP_PASSWORD@RDS_INTERNAL_HOST:5432/APP_DATABASE?sslmode=verify-full&sslrootcert=/etc/zhinian/rds/ca.pem"
|
||||
# Application role (least privilege). PostgreSQL transport is plaintext.
|
||||
DATABASE_URL: "postgresql://APP_USER:APP_PASSWORD@RDS_INTERNAL_HOST:5432/APP_DATABASE?sslmode=disable"
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
|
||||
Reference in New Issue
Block a user