fix: disable PostgreSQL TLS for refusing RDS endpoint

This commit is contained in:
2026-08-16 23:26:03 +08:00
parent acf368b6fe
commit ed978142eb
17 changed files with 340 additions and 180 deletions

View File

@@ -63,9 +63,6 @@ spec:
name: zhinian-go-bootstrap
key: ZHINIAN_BOOTSTRAP_ADMIN_PASSWORD
volumeMounts:
- name: rds-ca
mountPath: /etc/zhinian/rds
readOnly: true
- name: data
mountPath: /var/lib/zhinian
- name: tmp
@@ -106,9 +103,6 @@ spec:
runAsGroup: 10001
readOnlyRootFilesystem: true
volumes:
- name: rds-ca
secret:
secretName: zhinian-rds-ca
- name: data
emptyDir: {}
- name: tmp

View File

@@ -3,24 +3,13 @@
# intentionally not injected by the minimal production Deployment.
apiVersion: v1
kind: Secret
metadata:
name: zhinian-rds-ca
namespace: zhinian
type: Opaque
stringData:
# Public CA certificate for the RDS endpoint used in DATABASE_URL.
ca.pem: |
REPLACE_WITH_RDS_CA_PEM
---
apiVersion: v1
kind: Secret
metadata:
name: zhinian-migration-db
namespace: zhinian
type: Opaque
stringData:
# Manual schema execution only: run database/migrations/*.sql with this role.
DATABASE_URL: "postgresql://MIGRATION_USER:MIGRATION_PASSWORD@RDS_INTERNAL_HOST:5432/APP_DATABASE?sslmode=verify-full&sslrootcert=/etc/zhinian/rds/ca.pem"
# Manual schema execution only. This connection intentionally uses plaintext.
DATABASE_URL: "postgresql://MIGRATION_USER:MIGRATION_PASSWORD@RDS_INTERNAL_HOST:5432/APP_DATABASE?sslmode=disable"
---
apiVersion: v1
kind: Secret
@@ -40,8 +29,8 @@ metadata:
namespace: zhinian
type: Opaque
stringData:
# Application role (least privilege): grants applied manually after the SQL.
DATABASE_URL: "postgresql://APP_USER:APP_PASSWORD@RDS_INTERNAL_HOST:5432/APP_DATABASE?sslmode=verify-full&sslrootcert=/etc/zhinian/rds/ca.pem"
# Application role (least privilege). PostgreSQL transport is plaintext.
DATABASE_URL: "postgresql://APP_USER:APP_PASSWORD@RDS_INTERNAL_HOST:5432/APP_DATABASE?sslmode=disable"
---
apiVersion: v1
kind: Secret