Skip to content

Deploy: enforce TLS (sslmode) on every production Postgres connection #262

Description

@mforce

Deployment-readiness gap (#244), BLOCKER — flagged by 2 of 3 reviewers.

Problem

No production connection string enforces TLS to Postgres. The provider passes the
string straight to UseNpgsql without checking its SSL posture
(PostgresDbContextConfigurator.cs);
deploy/docker-compose.yml builds a bare
Host=db;Port=5432;Database=…;Username=…;Password=… with no SSL params. A
repo/deploy/docs grep finds zero sslmode/SSL Mode.

Npgsql defaults to SSL Mode=Prefer, which silently falls back to plaintext
if the server allows it and never validates the server certificate. For any managed
Postgres reached over a non-loopback network, the DB password and all farm/customer
PII can travel unencrypted or be MITM'd.

Fix (app-side, portable)

Require at least SSL Mode=Require, preferably VerifyFull with a trusted root
cert + hostname verification, in Production; fail the boot when the effective
connection permits plaintext or an unverified certificate. The trusted-root / CA
bundle and the exact per-host suffix are deploy-repo config.

Verify

Log the effective (redacted) connection string at boot; confirm it still connects
with Require/VerifyFull; confirm an invalid server certificate is rejected.

Part of the #244 deployment-readiness audit; tracked in epic #15.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions