PostgreSQL 17 with pgAudit and pgAuditLogToFile for enhanced security compliance logging.
3.8K
A security-enhanced PostgreSQL 17 image with integrated audit logging capabilities using pgAudit and pgAuditLogToFile extensions.
This Docker image extends the official PostgreSQL 17 image with advanced audit logging capabilities to meet compliance requirements and enhance security monitoring. It incorporates:
latest: PostgreSQL 17 with pgAudit and pgAuditLogToFile extensionsdocker run -d \
--name postgres-audit \
-e POSTGRES_PASSWORD=mysecretpassword \
-p 5432:5432 \
talismar/postgres-audit:latest
docker-compose.yml
services:
posgresql:
build: .
environment:
POSTGRES_PASSWORD: admin123
ports:
- 5433:5432
This image accepts all the environment variables from the official PostgreSQL image:
POSTGRES_PASSWORD: Required password for the PostgreSQL superuserPOSTGRES_USER: Optional username for the PostgreSQL superuser (default: postgres)POSTGRES_DB: Optional name for the default database (default: same as POSTGRES_USER)POSTGRES_INITDB_ARGS: Optional arguments to send to postgres initdbPOSTGRES_INITDB_WALDIR: Optional directory for the transaction logPOSTGRES_HOST_AUTH_METHOD: Authentication method for local connections (use with caution)PGDATA: Optional data directory path (default: /var/lib/postgresql/data)The pgAudit extension provides detailed logging of database activities:
This extension allows:
The image includes a custom postgresql.conf file with pre-configured audit settings. You can override these settings by:
Mounting your own configuration file:
docker run -d \
--name postgres-audit \
-e POSTGRES_PASSWORD=mysecretpassword \
-v /path/to/your/postgresql.conf:/etc/postgresql/postgresql.conf \
talismar/postgres-audit:latest
Setting parameters at runtime:
docker run -d \
--name postgres-audit \
-e POSTGRES_PASSWORD=mysecretpassword \
talismar/postgres-audit:latest \
postgres -c "pgaudit.log=write" -c "config_file=/etc/postgresql/postgresql.conf"
| Parameter | Description | Default |
|---|---|---|
pgaudit.log | Sets which statement classes to log | write, ddl |
pgaudit.log_catalog | Enable/disable logging of catalog objects | on |
pgaudit.log_parameter | Includes statement parameters in logs | on |
pgaudit.log_relation | Controls logging of relations in READ/WRITE statements | off |
pgaudit.log_statement_once | Logs statement just once rather than for each row | off |
pgaudit.role | Specifies the role for object-level audit logging | None |
pgaudit.filename | Audit log destination file | audit_%Y-%m-%d_%H%M%S.log |
pgaudit.log_directory | Directory to store audit logs | log |
pgaudit.max_files | Maximum number of retained log files | 100 |
pgaudit.max_file_size_mb | Maximum size of each log file | 10 |
Mount volumes to persist your data and logs:
docker run -d \
--name postgres-audit \
-e POSTGRES_PASSWORD=mysecretpassword \
-v postgres_data:/var/lib/postgresql/data \
-v postgres_audit_logs:/var/lib/postgresql/log \
talismar/postgres-audit:latest
The image includes an initialization script in /docker-entrypoint-initdb.d/ that:
You can add additional initialization scripts by mounting them to the /docker-entrypoint-initdb.d/ directory.
⚠️ IMPORTANT: Do not create a file named
create_extensions.sqlin your initialization scripts directory as the image already includes this file. Creating a file with this name will overwrite the built-in initialization script and may prevent the audit extensions from being properly configured. If you need to customize the extensions setup, consider using a different filename for your script.
This image is built in two stages:
This image includes:
https://github.com/Talismar/docker-postgres-audit - Source code and additional documentation.
For issues or support requests, please file an issue on the GitHub repository.
Content type
Image
Digest
sha256:d8a633279…
Size
177.8 MB
Last updated
8 months ago
docker pull talismar/postgres-audit