Phoenix 1.7.7升级后连接Heroku PostgreSQL的SSL配置报错求助
Phoenix 1.7.7 + Ecto 3.10.3 连接Heroku PostgreSQL SSL报错解决方案
问题背景
升级Phoenix到1.7.7、Ecto到3.10.3后,原有的仅设置ssl: true的数据库配置无法连接Heroku PostgreSQL,报错提示SSL选项冲突:
[error] Postgrex.Protocol (#PID<0.2449.0>) failed to connect: ** (DBConnection.ConnectionError) ssl connect: Options (or their values) can not be combined: [{verify,verify_peer}, {cacerts,undefined}] - {:options, :incompatible, [verify: :verify_peer, cacerts: :undefined]}
问题原因
新版本的Postgrex/Ecto默认启用了verify: :verify_peer的SSL验证规则,但Heroku提供的DATABASE_URL中未包含CA证书相关配置,导致cacerts参数未定义,触发选项冲突。
解决方法
方法一:配置合法CA证书(推荐生产环境)
- 添加
certifi依赖到mix.exs,用于获取系统根证书:
defp deps do [ # 其他已有依赖 {:certifi, "~> 2.11"} ] end
执行mix deps.get安装依赖。
- 更新Repo配置,补充SSL选项:
config :abc, abc.Repo, url: System.get_env("DATABASE_URL"), pool_size: String.to_integer(System.get_env("POOL_SIZE") || "10"), ssl: true, ssl_opts: [ cacertfile: Certifi.cacertfile(), verify: :verify_peer, server_name_indication: String.to_charlist(URI.parse(System.get_env("DATABASE_URL")).host) ]
cacertfile:通过certifi提供根证书路径,满足验证要求server_name_indication:指定数据库主机名,匹配SSL证书的域名
方法二:临时关闭证书验证(仅测试环境用)
如果只是临时测试,可暂时关闭peer验证,但不推荐生产环境使用:
config :abc, abc.Repo, url: System.get_env("DATABASE_URL"), pool_size: String.to_integer(System.get_env("POOL_SIZE") || "10"), ssl: true, ssl_opts: [verify: :verify_none]
内容的提问来源于stack exchange,提问作者tomwang1013
相关产品推荐
相关产品推荐

