Skip to content

fix(stack): give native postgres the host CA bundle (CLI-2627) - #7023

Merged
7ttp merged 6 commits into
developfrom
7ttp/cli-2627-stack-outbound-https-from-postgres-http-pg_net-fails
Oct 7, 2026
Merged

7ttp merged 6 commits into
developfrom
7ttp/cli-2627-stack-outbound-https-from-postgres-http-pg_net-fails

Conversation

@7ttp

@7ttp 7ttp commented Oct 6, 2026

Copy link
Copy Markdown
Member

TL;DR

fixes https requests from http and pg_net failing certificate verification on the native runtime on macOS arm64.

whats broken?

the OpenSSL bundled with native postgres looks for its CA bundle under /nix, which a macOS host does not have, so http_get to an https url failed with unable to get local issuer certificate.
the native launcher also kept a host SSL_CERT_FILE away from postgres, so exporting one did not help.

now fixed by:

the native postgres launch now forwards an exported SSL_CERT_FILE and SSL_CERT_DIR, and when SSL_CERT_FILE is not exported it uses the first CA bundle on the host, /etc/ssl/cert.pem on macOS.

ref:

@7ttp 7ttp self-assigned this Oct 6, 2026
@7ttp
7ttp requested a review from a team as a code owner October 6, 2026 15:46

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 AI Review

Both independent reviews were available. Confirmed the privilege-drop edge case and the missing process-wiring test. The libcurl finding remains uncertain because the bundled extensions, library configuration, and startup wrapper are unavailable in this checkout. All three findings are preserved; none overlap.

Findings

Severity Location Category Sources Claim
🟠 MAJOR packages/stack/src/services/Database.ts:438 correctness codex Setting SSL_CERT_FILE or SSL_CERT_DIR does not fix HTTPS verification in http and pg_net when their libcurl uses a compiled-in CA bundle path.
🟡 MINOR packages/stack/src/services/Database.ts:429 correctness claude Exported SSL_CERT_FILE or SSL_CERT_DIR paths bypass the system-bundle fallback without checking whether the lower-privilege PostgreSQL user can access them.
⚪ NIT packages/stack/src/services/Database.unit.test.ts:24 test-coverage claude The new tests exercise nativeTrustStore only in isolation and would still pass if its result stopped being forwarded to native PostgreSQL.

Stats

Claude findings: 2 · Codex findings: 1 · Confirmed: 2 · Refuted: 0 · Uncertain: 1


Models: claude-opus-5-5 + gpt-6.1-sol · Trigger: auto · Workflow run

This review runs once per PR. A maintainer can request another with a /ai-review comment.

Comment thread packages/stack/src/services/Database.ts Outdated
Comment thread packages/stack/src/services/Database.unit.test.ts Outdated
Comment thread packages/stack/src/services/Database.ts Outdated

@jgoux jgoux left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for tracking this down. Passing the CA settings to native PostgreSQL is the right fix. Comments are inline: the main one asks for coverage at the real boundary; the other two are smaller edge cases.

Comment thread packages/stack/src/services/Database.unit.test.ts Outdated
Comment thread packages/stack/src/services/Database.ts Outdated
Comment thread packages/stack/src/services/Database.ts Outdated
@7ttp
7ttp requested a review from jgoux October 6, 2026 17:35

@jgoux jgoux left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Forwarding the host trust store to native postgres is correct, the native integration test proves http and pg_net verify against the forwarded CA, and all earlier feedback is addressed. Two small follow-ups below.

Comment thread packages/stack/src/services/Database.ts Outdated
Comment thread packages/stack/src/services/Database.integration.test.ts
@7ttp
7ttp enabled auto-merge October 7, 2026 09:55
@7ttp
7ttp added this pull request to the merge queue Oct 7, 2026
Merged via the queue into develop with commit 07a22b3 Oct 7, 2026
39 checks passed
@7ttp
7ttp deleted the 7ttp/cli-2627-stack-outbound-https-from-postgres-http-pg_net-fails branch October 7, 2026 10:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

stack: outbound HTTPS from Postgres (http, pg_net) fails certificate verification on native darwin-arm64

2 participants