The Secure Way
Databases, the secure way
Postgres with TLS that verifies, backups you can restore, least-privilege roles and row-level security.
4 guides
- CloudNativePG backups to object storage, the secure wayBack up CloudNativePG to S3-compatible storage with the Barman Cloud Plugin: a bucket-scoped key, verified TLS, encryption at rest, retention, and restore tests.
- CloudNativePG TLS and pg_hba, the secure wayCloudNativePG's default pg_hba rule accepts plaintext passwords over TCP. Add hostnossl reject, allow the app only over TLS, and use your own server CA.
- Least-privilege Postgres roles for an app, the secure wayGive an application its own Postgres login that can read and write rows but not drop tables, change the schema or run programs, with default privileges. Tested.
- Testing row-level security in CI, the secure wayTest Postgres row-level security like any other code: a small suite that runs as the app's login, checks tenant isolation, views and new tables, and fails the build.
T Academy
Every guide here is taught hands-on in H2-CSPE Secure Platform Engineering: a real host in your browser, and every objective checked on the machine.
Start free