← PostgreSQL: operations and recovery
01 / 6 · 40 MIN

Connections, identities, and privileges

Diagnose access by layer and test with the actual application identity.

Concept and mechanism

A PostgreSQL connection crosses networking, TLS, authentication, and authorization. pg_hba.conf selects the first rule matching connection type, source, database, and role. An invalid password does not trigger a later rule. On Unix, changes need reloading; an old session does not demonstrate that new connections will succeed. Migrating to SCRAM requires compatible clients and new passwords stored in the appropriate format. Changing password_encryption does not convert existing hashes. In libpq, verify-full checks the trust chain and server name; requiring encryption alone does not necessarily meet that requirement. Retain correct trust and names instead of bypassing certificate errors.

Guided application

In a fictional batch moving to another subnet, collect the complete error and confirm the source observed by the server before editing rules. After authentication, check CONNECT, schema USAGE, and privileges on required objects. Current grants do not solve access to future tables: default privileges depend on the role creating objects. RLS needs testing with the runtime identity because owners normally bypass policies; superusers and BYPASSRLS have their own exceptions. RUN handover should identify who manages roles, rotation, and revocation, how to validate a new connection, and how to reverse a change without widening access scope.

IN PRACTICE

A session opened before the change remains active while the new batch connection fails: test the new path rather than the old session.

Common pitfalls

HBA as a fallback list; TLS as SELECT; defaults as retroactive grants; testing RLS as owner.

Related topics: Transactions, blocking, and resumption · Plans, indexes, and memory · Vacuum, configuration, and capacity

Take this idea with you

Validate networking, identity, and privileges through a fresh representative connection.

Create account

Reference: Authentication rule order · PostgreSQL 18 reference semantics;18.6 current stable at review