User configuration¶
By default, client connections will use password authentication encrypted with SCRAM-SHA-256. This method is secure and recommended for production usage.
PgDog supports using other methods, e.g., md5, plain and trust, which you can change with configuration:
Configuring users¶
The users.toml configuration file follows a TOML list structure. To allow a user to connect to PgDog, add a [[users]] section with the user name, password and a corresponding database name (located in pgdog.toml) to users.toml, for example:
The database parameter must match the name of one of the databases configured in pgdog.toml. For example:
In this example, the database parameter in the [[users]] prod entry matches the [[databases]] database prod entry.
User/database mismatch
If you add a user with a database name not specified in pgdog.toml, that entry will be ignored by PgDog at runtime and that user will not be able to connect.
The same username, database name and password will also be used by PgDog to connect to PostgreSQL. This makes configuration simpler since the Postgres connection options used by applications don't have to change when PgDog is deployed for the first time.
Read more about configuring users with password authentication here.
Configuring user options¶
PgDog supports setting user-specific options in users.toml. Some settings are overrides of equivalent global defaults set in the [general] section of pgdog.toml, while others can be set on users exclusively, for example:
Helm chart
Convert the setting name to camelCase if using our Helm chart.
The following settings are supported:
| User setting | Global setting | Description |
|---|---|---|
pooler_mode |
pooler_mode |
Transaction or session pooling mode. |
pool_size |
default_pool_size |
Size of the user's connection pool. |
min_pool_size |
min_pool_size |
Minimum number of idle connections in the user's pool. |
two_phase_commit |
two_phase_commit |
Enable/disable two-phase commit for this user. |
two_phase_commit_auto |
two_phase_commit_auto |
Enable/disable automatic two-phase-commit for this user. |
server_lifetime |
server_lifetime |
Maximum connection age for this user. |
server_lifetime_jitter |
server_lifetime_jitter |
Jitter added to server_lifetime for this user. |
cross_shard_disabled |
cross_shard_disabled |
Disable cross-shard queries for this user. |
User-only settings¶
In addition to overriding pgdog.toml defaults, some settings can only be set on users:
| User setting | Description |
|---|---|
statement_timeout |
Equivalent of executing SET statement_timeout TO <value> on connection pool creation. |
lock_timeout |
Equivalent of executing SET lock_timeout TO <value> on connection pool creation. |
idle_timeout |
Clients connected for longer than this (in ms) without executing queries will be disconnected. |
Example¶
Read more¶
Password authentication
Configure password authentication with SCRAM and other supported algorithms.
RDS IAM
Passwordless authentication to RDS PostgreSQL and Aurora databases.
mTLS
Passwordless authentication for client and server connections.