Authentication¶
PostgreSQL servers support many authentication mechanisms. PgDog supports a subset of those, with the aim to support all of them over time.
Additionally, PgDog supports some non-standard algorithms commonly used in the industry, like RDS IAM, Azure Identity, and others. This makes it relatively easy to deploy to a cloud environment without affecting security.
Supported methods¶
The following table summarizes the current level of support for client and server connection authentication methods:
| Authentication method | Client connections | Server connections |
|---|---|---|
| Password | ||
| Trust (no password) | ||
| AWS RDS IAM | No | |
| Azure Workload Identity | No | |
| HashiCorp Vault | No | |
| Mutual TLS (mTLS) |
Contributions
PgDog is an open source project. If you'd like to add an authentication method we don't currently support, please open an issue to discuss.
Read more¶
Configuring users
Configure users with authentication options and other settings.
Password authentication
Configure password authentication with SCRAM and other supported algorithms.
RDS IAM
Passwordless authentication to RDS PostgreSQL and Aurora databases.
mTLS
Passwordless authentication for client and server connections.