You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Postgres 11下pg_bouncer与Kerberos结合认证可行性及配置咨询

pg_bouncer 与 Kerberos 结合的实践方案

pg_bouncer 完全支持与 Kerberos 认证机制结合,不管是客户端到 pg_bouncer 的身份验证,还是 pg_bouncer 到 PostgreSQL 后端的身份验证都能实现,以下是具体配置方法和实践说明:

一、客户端到 pg_bouncer 的 Kerberos 认证配置

  • 先确认 pg_bouncer 具备 Kerberos 支持:发行版预编译包(如 Debian/Ubuntu 的 pgbouncer)通常默认开启,自行编译需添加 --with-krb5 参数。
  • 修改 pgbouncer.ini 核心配置:
    1. 在 [databases] 块中,为目标数据库指定 Kerberos 认证类型:
      [databases]
      mydb = host=pg-server port=5432 dbname=mydb auth_type=krb5
      
    2. 在 [pgbouncer] 块中配置认证文件和 Kerberos 密钥文件:
      [pgbouncer]
      auth_file = /etc/pgbouncer/userlist.txt
      krb_server_keyfile = /etc/pgbouncer/pgbouncer.keytab
      
      • userlist.txt 中需添加与 Kerberos 主体匹配的用户名(无需密码,格式为 "user@EXAMPLE.COM" "")
  • 配置 Kerberos KDC:
    • 创建 pg_bouncer 的服务主体,格式为 pgbouncer/your-pgbouncer-host@EXAMPLE.COM
    • 生成对应 keytab 文件并复制到 pg_bouncer 服务器,设置权限:chown pgbouncer:pgbouncer /etc/pgbouncer/pgbouncer.keytab && chmod 600 /etc/pgbouncer/pgbouncer.keytab

二、pg_bouncer 到 PostgreSQL 后端的 Kerberos 认证配置

  • 确保 PostgreSQL 11 已完成 Kerberos 基础配置(pg_hba.conf 中存在 host all all 0.0.0.0/0 krb5 类规则)
  • 在 pgbouncer.ini 的 [databases] 块中,为后端连接指定 Kerberos 用户主体:
    [databases]
    mydb = host=pg-server port=5432 dbname=mydb auth_type=krb5 krb5_user=pgbouncer-service@EXAMPLE.COM
    
  • 为 pg_bouncer 配置长期 Kerberos 票据:
    • 生成服务主体的 keytab 文件,执行 kinit -kt /etc/pgbouncer/service.keytab pgbouncer-service@EXAMPLE.COM 获取票据
    • 可将该命令加入 pg_bouncer 的 systemd 服务启动脚本,确保进程启动时自动获取票据

三、实践案例说明

在企业级 PostgreSQL 部署场景(如金融、政企)中,这种组合非常常见:

  • 所有业务客户端通过 Kerberos 统一身份认证接入 pg_bouncer,实现集中式身份管控
  • pg_bouncer 以专用服务主体连接后端 PostgreSQL,既减少了后端的连接数压力,又通过 Kerberos 保证了后端连接的安全性
  • 部分场景会结合 LDAP 与 Kerberos 联动,进一步强化身份管理的灵活性

内容的提问来源于stack exchange,提问作者Gerzzog

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 10:21:12