On Wed, Mar 6, 2019 at 10:49:17AM -0800, Jeremy Schneider wrote: > Might it make sense to generalize a little bit to secret management? It > would be *great* if PostgreSQL could have a standard "secrets" API which > could then use plugins or extensions to provide an internal > implementation (software or hardware based) and/or plug in to an > external secret management service, whether an OSS package installed on > the box or some 3rd party service off the box. > > The two obvious use cases are encryption keys (mentioned here) and > passwords for things like logical replication, FDWs, dblinks, other > extensions, etc. Aside from adding new encryption key secrets, the way > PostgreSQL handles the existing secrets it already has today leaves room > for improvement.
See this email for a possible implementation: https://www.postgresql.org/message-id/20190222035816.uozqvc4wjyag3...@momjian.us -- Bruce Momjian <br...@momjian.us> http://momjian.us EnterpriseDB http://enterprisedb.com + As you are, so once was I. As I am, so you will be. + + Ancient Roman grave inscription +