Skip to content

fix: authenticate PostgreSQL IAM connections on demand - #421

Open
deinspanjer wants to merge 2 commits into
bytebase:mainfrom
deinspanjer:dre/fix/on-demand-postgres-iam
Open

deinspanjer wants to merge 2 commits into
bytebase:mainfrom
deinspanjer:dre/fix/on-demand-postgres-iam

Conversation

@deinspanjer

@deinspanjer deinspanjer commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

PostgreSQL IAM authentication currently rotates pools every 14 minutes even though token expiry does not invalidate an established database session. This replaces healthy connections and can trigger credential renewal without an incoming request.

Resolve IAM passwords through pg's async password callback when a physical connection opens. Existing sessions stay available, and a later request can retry failed authentication without restarting DBHub.

  • Share in-flight token requests per source configuration, including after a socket timeout, without adding background authentication retries or SQL replay.
  • Preserve upstream's idle-pool error handling, SSH failure cleanup, credential-file refresh, and MySQL/MariaDB timer recovery.
  • Preserve per-source pool limits, TLS/client-certificate settings, and signing of the original RDS endpoint through SSH.
  • Correct the PostgreSQL SSL type annotation to use pg.PoolConfig["ssl"].
  • Document SSO/credential-process login, per-source idle timeouts, and browser/connection-timeout behavior.

Validation after rebasing onto main (8c09c86, v1.4.0):

  • 1,162 unit tests pass across 40 files, including real pg loopback authentication/idle-disconnect recovery and real AWS SDK tests with isolated synthetic credentials and a credential process.
  • Backend build and all six configured import smoke tests pass.
  • tsc --noEmit reports 135 diagnostics versus 136 on clean upstream with the same locked dependencies. The existing PostgreSQL SSL type error is fixed, with no new diagnostics.
  • The original branch was used live from September 12 through September 28 with no reported problems. Earlier read-only MCP probes also verified replacement physical sessions after pool idle eviction. The rebase was validated in an isolated copy; the running local build was not replaced.
  • The full Docker integration suite was not run locally. SSO, web identity, role assumption, and container/instance providers retain SDK routing, but not every authentication pattern was exercised end to end.

@deinspanjer

Copy link
Copy Markdown
Contributor Author

I'll spend next week testing this build live in my normal workflow, including credential renewal and recovery after authentication failures. I'll keep this PR in draft and mark it ready for review after that testing is complete.

@tianzhou

Copy link
Copy Markdown
Member

@deinspanjer any update

@deinspanjer

Copy link
Copy Markdown
Contributor Author

Oh shoot, I'm sorry I forgot about this. It works great. I've been using the branch since I posted with no problems.
Let me get the branch resolved with latest and I'll mark the PR ready

Daniel E. added 2 commits September 28, 2026 12:36
Resolve IAM passwords when opening a connection so failed login attempts remain retryable.

- Keep pools available after idle disconnects and share concurrent authentication.
- Preserve AWS provider selection and reread refreshed credential files.
- Cover recovery with real pg and isolated AWS SDK checks.
- Use the pool SSL type instead of the nonexistent pg.ConnectionOptions export.
@deinspanjer
deinspanjer force-pushed the dre/fix/on-demand-postgres-iam branch from d83685b to 333a24b Compare September 28, 2026 16:37
@deinspanjer
deinspanjer marked this pull request as ready for review September 28, 2026 16:37
@deinspanjer

Copy link
Copy Markdown
Contributor Author

The integration test failure looks to be Docker related, not my code. Please let me know if I need to rebase again after a fix.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Authentication lifecycle changes are high-impact, and several AWS provider paths were not exercised end to end.

Review effort: Balanced
Findings: None

What changed in this PR

Moves PostgreSQL RDS IAM authentication from timed pool rotation to on-demand password callbacks.

Changes:

  • Generates and shares in-flight IAM tokens when PostgreSQL opens physical connections.
  • Preserves MySQL/MariaDB rotation, SSH cleanup, TLS, and pool settings.
  • Adds authentication recovery tests and operational documentation.
File Description
src/​utils/​aws-rds-signer.ts Updates token-refresh documentation.
src/​utils/​__tests__/​aws-rds-credentials.test.ts Tests credential refresh and process recovery.
src/​connectors/​postgres/​index.ts Supports asynchronous passwords and corrects SSL typing.
src/​connectors/​manager.ts Implements on-demand PostgreSQL IAM authentication.
src/​connectors/​interface.ts Adds the password callback option.
src/​connectors/​__tests__/​postgres-auth.test.ts Tests physical-session authentication recovery.
src/​connectors/​__tests__/​manager.test.ts Tests token sharing, retries, and SSH behavior.
docs/​config/​toml.mdx Documents IAM lifecycle and credential-provider behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants