Skip to main content

SSL mode

A database's SSL Mode, in its App Kind, is how the apps of its environment are to connect to it: whether they use TLS, and how far they check the database's certificate. It is not a setting of the database itself: the database does TLS or not, depending on how it is set up.

The database shares it as HIVEPAAS_SSL_MODE. For PostgreSQL, Link to another app writes it into the variables it suggests: sslmode= in DATABASE_URL, DB_SSL_MODE, and PGSSLMODE.

The modes​

They are PostgreSQL's, which most PostgreSQL drivers understand:

ModeThe client
DisableNever uses TLS.
PreferUses TLS if the database offers it, and connects without it otherwise.
RequireUses TLS, or does not connect. It does not check the certificate.
Verify CAAlso checks that the certificate is signed by an authority it trusts.
Verify FullAlso checks that the certificate is for the host name it connects to.

Which one to choose​

The apps of the environment reach the database on their private network, straight, and never through Traefik: what counts is whether the database itself does TLS.

The databaseSSL mode
Has no TLS of its own: as deployed from the app store, and when Traefik ends TLS for clients outsideDisable
Has its own TLS turned on, such as for TLS passthroughRequire

Left unset, it is Disable.

Verify CA and Verify Full rarely fit here. The apps reach the database by its key, such as db, which is not the name its certificate is for, and they need the authority's certificate, mounted into each of them.

Changing it reaches the apps that refer to it on their next deployment.

Clients outside​

A client outside the cluster connects through its domain, and chooses its own mode:

  • Verify Full checks the certificate the domain serves, which comes from a public authority, such as Let's Encrypt. libpq looks for the authority in ~/.postgresql/root.crt: give it sslrootcert=system, from libpq 16, to use the system's authorities instead.

    psql "host=db.example.com dbname=app user=app sslmode=verify-full sslrootcert=system"
  • Require encrypts, without checking whom it talks to.

  • Disable is not let through: Traefik only routes connections that start TLS.

The other databases name it their own way:

DatabaseRequireCheck the certificate
MySQL, MariaDB--ssl-mode=REQUIRED--ssl-mode=VERIFY_IDENTITY
MongoDBtls=true&tlsAllowInvalidCertificates=truetls=true
Redis, Valkey--tls --insecure--tls, and rediss:// URLs