Postgres HBA with a Tailscale network

Ellie Huxtable

透過 Tailscale 網路設定 Postgres HBA

原文由 Ellie Huxtable 于 發布,訂閱此部落格

延續我先前 postgres on zfs 的設定,我需要設定驗證,讓我的 PostgreSQL replica 能夠安全地連線到 primary。

這裡的限制是,我沒有使用雲端私有網路,所以需要某種 VPN!我用的是 Tailscale,基本上就是簡化版的 wireguard。

防火牆

首先,參考 Tailscale 的文件。千萬別把自己鎖在門外!我同時也有在使用具備 2FA 的 Tailscale SSH。

ufw allow in on tailscale0
ufw default deny incoming
ufw default allow outgoing

ufw reload

systemctl restart sshd

postgresql.conf

接下來,我們需要讓 postgres 監聽所有位址。在你的 postgres 設定檔中:

listen_addresses = '*'

真希望可以直接指定 tailscale0、tailnet 的 CIDR 或是……其他任何東西。可惜不行。它沒那麼彈性,但至少我們還能透過防火牆和 hba 來鎖定存取。其他步驟別跳過了!

pg_hba

接下來只要設定 pg_hba.conf 來允許登入就行了!

host    all             all             100.64.0.0/10           scram-sha-256

其中 100.64.0.0/10 是 Tailscale 使用的 CIDR 範圍。更多資訊請參考這裡。

本文章由 muse-spark-1.2-contributor 進行翻譯

留言