Skip to content

Commit

Permalink
fix(release): postgres socket options
Browse files Browse the repository at this point in the history
  • Loading branch information
Betree committed May 3, 2023
1 parent e4122c4 commit 8edadfd
Showing 1 changed file with 21 additions and 10 deletions.
31 changes: 21 additions & 10 deletions config/releases.exs
Original file line number Diff line number Diff line change
Expand Up @@ -69,22 +69,33 @@ end

# ---- [APP CONFIG] :db ----

# Location of root certificates to verify database SSL connection.
# For example: /opt/homebrew/etc/openssl@3/cert.pem
database_ca_cert_filepath =
load_secret.({"DATABASE_CA_CERT_FILEPATH", "/etc/ssl/certs/ca-certificates.crt"})

postgres_enable_ssl? = load_bool.({"db_ssl", "false"})
postgres_socket_options = if postgres_enable_ssl?, do: [:inet6], else: []
postgres_ssl_options = []

if postgres_enable_ssl? do
postgres_ssl_options = [
server_name_indication: to_charlist(load_secret.("db_hostname")),
verify: :verify_peer,
cacertfile: database_ca_cert_filepath,
customize_hostname_check: [match_fun: :public_key.pkix_verify_hostname_match_fun(:https)]
]
end

config :db, DB.Repo,
hostname: load_secret.("db_hostname"),
username: load_secret.("db_username"),
password: load_secret.("db_password"),
database: load_secret.("db_name"),
pool_size: load_int.({"db_pool_size", 10}),
socket_options: if load_bool.({"db_ssl", "false"}), do: [:inet6], else: [],
ssl: load_bool.({"db_ssl", "false"}),
ssl_opts: [
server_name_indication: to_charlist(load_secret.("db_hostname")),
verify: :verify_peer,
customize_hostname_check: [
# Our hosting provider uses a wildcard certificate. By default, Erlang does not support wildcard certificates.
match_fun: :public_key.pkix_verify_hostname_match_fun(:https)
]
]
socket_options: postgres_socket_options,
ssl: postgres_enable_ssl?,
ssl_opts: postgres_ssl_options

config :ex_aws,
access_key_id: [load_secret.("s3_access_key_id"), :instance_role],
Expand Down

0 comments on commit 8edadfd

Please sign in to comment.