From 001670cc13f6bae826187894444dfa4f9fb2fd3a Mon Sep 17 00:00:00 2001 From: Eric Paulsen Date: Fri, 21 Jul 2023 10:36:11 -0400 Subject: [PATCH] docs: add steps for postgres SSL cert config (#8648) * docs: add steps for postgres SSL cert config * make fmt * Update docs/install/kubernetes.md Co-authored-by: Cian Johnston * fixup! Update docs/install/kubernetes.md --------- Co-authored-by: Cian Johnston --- docs/install/kubernetes.md | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) diff --git a/docs/install/kubernetes.md b/docs/install/kubernetes.md index bea77f9370..191ef1aba0 100644 --- a/docs/install/kubernetes.md +++ b/docs/install/kubernetes.md @@ -179,6 +179,39 @@ In certain enterprise environments, the [Azure Application Gateway](https://lear - Websocket traffic (required for workspace connections) - TLS termination +## PostgreSQL Certificates + +Your organization may require connecting to the database instance over SSL. To supply +Coder with the appropriate certificates, and have it connect over SSL, follow the steps below: + +1. Create the certificate as a secret in your Kubernetes cluster, if not already present: + +```console +$ kubectl create secret tls postgres-certs -n coder --key="postgres.key" --cert="postgres.crt" +``` + +1. Define the secret volume and volumeMounts in the Helm chart: + +```yaml +coder: + volumes: + - name: "pg-certs-mount" + secret: + secretName: "postgres-certs" + volumeMounts: + - name: "pg-certs-mount" + mountPath: "$HOME/.postgresql" + readOnly: true +``` + +1. Lastly, your PG connection URL will look like: + +```console +postgres://:@databasehost:/?sslmode=require&sslcert=$HOME/.postgresql/postgres.crt&sslkey=$HOME/.postgresql/postgres.key" +``` + +> More information on connecting to PostgreSQL databases using certificates can be found [here](https://www.postgresql.org/docs/current/libpq-ssl.html#LIBPQ-SSL-CLIENTCERT). + ## Upgrading Coder via Helm To upgrade Coder in the future or change values,