Sign inSign up

constructiveio/postgres-plus

By constructiveio

•Updated about 2 months ago

Lean PostgreSQL 18 with pgvector, PostGIS, pg_textsearch, pg_partman

Image
0

10K+

constructiveio/postgres-plus repository overview

⁠Constructive DB

The official Docker image for the Constructive database.

constructive

Lean PostgreSQL 18 image with essential extensions for modern applications.

⁠Extensions

ExtensionVersionDescription
pgvector⁠0.8.2Vector similarity search for embeddings
PostGIS⁠3.6.4 (+ security patches)Spatial and geographic data
pg_textsearch⁠1.3.1BM25 full-text search
pg_partman⁠5.4.3Partition management
pg_stat_statements⁠built-inQuery performance statistics

⁠Usage

# Pull the image
docker pull constructiveio/postgres-plus:latest

# Run
docker run -d \
  --name postgres \
  -e POSTGRES_PASSWORD=secret \
  -p 5432:5432 \
  constructiveio/postgres-plus:latest

Enable extensions as needed:

CREATE EXTENSION vector;
CREATE EXTENSION postgis;
CREATE EXTENSION pg_textsearch;
CREATE EXTENSION pg_partman;
CREATE EXTENSION pg_stat_statements;

⁠Configuration

track_io_timing is enabled by default for accurate I/O metrics in pg_stat_statements. This powers the usage metering and query stats collection pipeline.

⁠Build

make build            # Build image
make test             # Build, verify extensions, and run the PostGIS security gate
make verify-security  # Run the security gate against an already-running container
make run              # Run container
make shell            # psql into container
make clean            # Remove image

⁠PostGIS security patches

PostGIS is built from the 3.6.4 tarball with the upstream security fixes in patches/⁠ applied on top — no released tarball carries them yet:

PatchFixes
0001-flatgeobuf-validate-input-buffers-before-decodingCVE-2026-73515 — out-of-bounds read decoding a FlatGeobuf buffer (ST_FromFlatGeobuf). postgis/stable-3.6 53e273fae, landed after 3.6.4.
0002-address_standardizer-harden-scanner-and-rule-parsingCVE-2026-73514 — equivalent to 423570b in the split-out postgis/address_standardizer⁠ repo.
0003-address_standardizer-clean-up-partial-2D-allocationsleak/partial-allocation cleanup accompanying the above.
0004-Avoid-out-of-bounds-write-uninitialized-memorythe parse_rule() off-by-one write past rule_arr[MAX_RULE_LENGTH] plus an uninitialized RULE_PARAM.

Each is a git format-patch of the upstream commit cherry-picked onto the 3.6.4 tag, so the provenance stays greppable and a patch that stops applying fails the build rather than being silently skipped.

scripts/verify-postgis-security.sh <container> is the gate that keeps a vulnerable build from reaching a tag. It asserts against the installed extension, not the Dockerfile args: release floor, the patch manifest baked into the image, that a truncated FlatGeobuf buffer is rejected with the backend still alive, and that standardize_address() still works. CI runs it on every PR and on the pushed digest before the latest/18 manifests move.

Drop the patches when a PostGIS release contains all four fixes; the gate's POSTGIS_MIN_VERSION floor and manifest check are what to update then.

⁠Building manually

docker buildx build \
  --platform linux/amd64,linux/arm64 \
  -t constructiveio/postgres-plus:18 \
  -t constructiveio/postgres-plus:latest \
  --push .

Tag summary

Content type

Image

Digest

sha256:ce10c30b6…

Size

163.9 MB

Last updated

about 2 months ago

docker pull constructiveio/postgres-plus