fix: authenticate PostgreSQL IAM connections on demand - #421
deinspanjer wants to merge 2 commits into
Conversation
|
I'll spend next week testing this build live in my normal workflow, including credential renewal and recovery after authentication failures. I'll keep this PR in draft and mark it ready for review after that testing is complete. |
|
@deinspanjer any update |
|
Oh shoot, I'm sorry I forgot about this. It works great. I've been using the branch since I posted with no problems. |
Resolve IAM passwords when opening a connection so failed login attempts remain retryable. - Keep pools available after idle disconnects and share concurrent authentication. - Preserve AWS provider selection and reread refreshed credential files. - Cover recovery with real pg and isolated AWS SDK checks.
- Use the pool SSL type instead of the nonexistent pg.ConnectionOptions export.
d83685b to
333a24b
Compare
|
The integration test failure looks to be Docker related, not my code. Please let me know if I need to rebase again after a fix. |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Authentication lifecycle changes are high-impact, and several AWS provider paths were not exercised end to end.
Review effort: Balanced
Findings: None
What changed in this PR
Moves PostgreSQL RDS IAM authentication from timed pool rotation to on-demand password callbacks.
Changes:
- Generates and shares in-flight IAM tokens when PostgreSQL opens physical connections.
- Preserves MySQL/MariaDB rotation, SSH cleanup, TLS, and pool settings.
- Adds authentication recovery tests and operational documentation.
| File | Description |
|---|---|
src/utils/aws-rds-signer.ts |
Updates token-refresh documentation. |
src/utils/__tests__/aws-rds-credentials.test.ts |
Tests credential refresh and process recovery. |
src/connectors/postgres/index.ts |
Supports asynchronous passwords and corrects SSL typing. |
src/connectors/manager.ts |
Implements on-demand PostgreSQL IAM authentication. |
src/connectors/interface.ts |
Adds the password callback option. |
src/connectors/__tests__/postgres-auth.test.ts |
Tests physical-session authentication recovery. |
src/connectors/__tests__/manager.test.ts |
Tests token sharing, retries, and SSH behavior. |
docs/config/toml.mdx |
Documents IAM lifecycle and credential-provider behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
PostgreSQL IAM authentication currently rotates pools every 14 minutes even though token expiry does not invalidate an established database session. This replaces healthy connections and can trigger credential renewal without an incoming request.
Resolve IAM passwords through pg's async password callback when a physical connection opens. Existing sessions stay available, and a later request can retry failed authentication without restarting DBHub.
pg.PoolConfig["ssl"].Validation after rebasing onto main (
8c09c86, v1.4.0):tsc --noEmitreports 135 diagnostics versus 136 on clean upstream with the same locked dependencies. The existing PostgreSQL SSL type error is fixed, with no new diagnostics.