Sign inSign up

detoxd/postgres

By detoxd

•Updated 6 months ago

Image
0

2.9K

detoxd/postgres repository overview

⁠PostgreSQL - Detoxd Hardened Image

⁠Overview

PostgreSQL is a powerful, open-source object-relational database system with over 35 years of active development. Known for its reliability, feature robustness, and performance, PostgreSQL has earned a strong reputation for architecture, data integrity, and extensibility.

⁠Common Use Cases

  • Enterprise Applications - OLTP workloads with complex transactions
  • Geospatial Data - PostGIS extension for location data
  • Data Warehousing - Analytical queries and reporting
  • Time Series - TimescaleDB extension for IoT and metrics
  • JSON Storage - Native JSONB for document-style data
  • Full-text Search - Built-in text search capabilities

⁠Security Concerns

Database servers are high-value targets:

  • SQL Injection - Application-level vulnerabilities
  • Authentication Bypass - Weak password policies
  • Privilege Escalation - Overly permissive roles
  • Data Exposure - Unencrypted connections, backups
  • Remote Access - Default configurations may allow network access

⁠What Detoxd Does

⁠Authentication Hardening
  • Enforces scram-sha-256 authentication (strongest available)
  • Sets secure POSTGRES_INITDB_ARGS for initialization
  • Removes unnecessary system users
⁠System Hardening
  • Updates all system packages to latest versions
  • Removes unnecessary packages and development tools
  • Cleans package caches
  • Sets secure file permissions
⁠Network Security
  • Exposes only port 5432
  • Ready for SSL/TLS configuration
⁠pg_hba.conf
# TYPE  DATABASE        USER            ADDRESS                 METHOD
local   all             postgres                                peer
host    all             all             127.0.0.1/32            scram-sha-256
host    all             all             ::1/128                 scram-sha-256
hostssl all             all             0.0.0.0/0               scram-sha-256
# Reject all other connections
host    all             all             0.0.0.0/0               reject
⁠postgresql.conf
# Connection Settings
listen_addresses = '127.0.0.1'
port = 5432
max_connections = 100

# SSL
ssl = on
ssl_cert_file = '/path/to/server.crt'
ssl_key_file = '/path/to/server.key'
ssl_min_protocol_version = 'TLSv1.2'

# Logging
log_connections = on
log_disconnections = on
log_statement = 'ddl'
log_line_prefix = '%t [%p]: [%l-1] user=%u,db=%d,app=%a,client=%h '

# Password Security
password_encryption = scram-sha-256
⁠Role Best Practices
-- Create application-specific roles with minimal privileges
CREATE ROLE app_readonly;
GRANT CONNECT ON DATABASE myapp TO app_readonly;
GRANT USAGE ON SCHEMA public TO app_readonly;
GRANT SELECT ON ALL TABLES IN SCHEMA public TO app_readonly;

-- Revoke default public permissions
REVOKE ALL ON SCHEMA public FROM PUBLIC;
REVOKE ALL ON DATABASE postgres FROM PUBLIC;

⁠Environment Variables

POSTGRES_PASSWORD=your_secure_password
POSTGRES_INITDB_ARGS="--auth-host=scram-sha-256 --auth-local=peer"
POSTGRES_HOST_AUTH_METHOD=scram-sha-256

⁠References

Tag summary

Content type

Image

Digest

sha256:86dec7606…

Size

106 MB

Last updated

6 months ago

docker pull detoxd/postgres:17.9-alpine3.23-detox.1