Posts tagged #security
5 posts.
pgAgroal 1.4.5: Frontend TLS and Stricter HBA Security
pgAgroal 1.4.5 adds TLS for client connections, optional mutual TLS, stricter HBA source validation, and hardened Kubernetes deployment through Helm.
Elevarq Signals 1.3.0: Know Who Can Access What
Elevarq Signals 1.3.0 adds object and default privilege collection, making PostgreSQL grants — including access through PUBLIC — explicit, normalized, and ready for analysis.
pgAgroal Enterprise 1.2.0: Verified TLS for Amazon RDS and Aurora
pgAgroal Enterprise 1.2.0 adds verified backend TLS (verify-ca / verify-full) so the pooler authenticates your RDS or Aurora certificate against a CA, not just encrypts it. It ships with a broad security-hardening batch and is live now on AWS Marketplace and GHCR.
Elevarq Signals Beta 7: the road to 1.0
Beta 7 of Elevarq Signals: passwordless cloud-IAM and live secret-store auth for read-only PostgreSQL diagnostics — and the road to 1.0.
pgagroal 1.1.0 is out: what changed, what to migrate, how it's signed
Today we shipped elevarq/pgagroal:1.1.0, our container packaging of upstream pgagroal 2.1.0 — a feature release with a security-relevant migration. New AES-256-GCM vault encryption and a GCM-only management protocol mean operators must re-key the master and upgrade every pgagroal-cli in lockstep. Verifiable end-to-end with cosign signatures, SBOM, and SLSA provenance.