Skip to content
Merged
Show file tree
Hide file tree
Changes from 59 commits
Commits
Show all changes
72 commits
Select commit Hold shift + click to select a range
9bdf028
chore: ignore docs/superpowers (private session artifacts)
May 11, 2026
b74df6b
feat(config): startup_parameters field on general and pool with valid…
May 11, 2026
b95987b
fix(config): align startup_parameters budget with PG StartupMessage cap
May 11, 2026
320e3c0
feat(protocol): startup() accepts operator-supplied extra parameters
May 11, 2026
7230ced
feat(server, pool): cascade resolver and per-pool quarantine state
May 11, 2026
bc28204
comments: drop spec-decision shorthand from startup_parameters code
May 11, 2026
969e2b6
feat(server): Server::startup wires startup_parameters and quarantine
May 11, 2026
ed3f813
feat(auth_query): per-user startup_parameters via optional JSON column
May 11, 2026
4c95817
feat(pool): resolve startup_parameters per-backend and wire quarantine
May 11, 2026
f49317e
feat(observability): metrics and SHOW POOLS for startup_parameters he…
May 11, 2026
e498575
test(bdd): startup_parameters end-to-end scenarios
May 11, 2026
01c354b
fix(server): preserve 57P SQLSTATE mapping for Patroni fallback
May 11, 2026
7463754
fix(pool): post-cascade size check prevents oversize StartupMessage
May 11, 2026
a2ef85e
fix(server): only quarantine startup parameters pg_doorman actually sent
May 11, 2026
15a5f5f
docs(metrics): correct backend_startup_parameter_errors label list
May 11, 2026
cb015ee
fix(server): reset rejection counter on successful backend startup
May 11, 2026
3647c64
docs(config): describe shipped startup_parameters behaviour
May 11, 2026
7b2ae91
fix(quarantine): hot-reload threshold and TTL knobs on config reload
May 11, 2026
be3bcb4
fix(quarantine): clear gauge on TTL expiry without waiting for new sp…
May 11, 2026
541715a
fix(auth_query): point operator at ::text cast on column-type mismatch
May 11, 2026
3c4d06f
docs: operator tutorial for PostgreSQL startup_parameters (EN + RU)
May 11, 2026
6eb77a3
fix(ci): wait past postgres init-restart in docker-smoke
May 11, 2026
5d27039
release: 3.9.0 (per-pool startup_parameters)
May 11, 2026
ecec40f
ci(bdd): run @startup-parameters scenarios in CI
May 11, 2026
19b7c46
admin/web: surface operator-injected startup_parameters + codex fixes
May 11, 2026
3e09aad
startup_parameters: forward PG errors verbatim; close codex HIGH #2/#…
May 12, 2026
bb95309
fix(bdd): enable log capture in the every-connect-fails scenario
May 12, 2026
c2efe79
perf(startup_parameters): cache pool baseline, single-alloc StartupMe…
May 12, 2026
3aabbfe
fix(metrics): keep backend_startup_parameter_errors_total accurate un…
May 12, 2026
93e384b
fix(startup_parameters): forward PG sqlstate verbatim + counter for p…
May 12, 2026
b70e313
refactor(startup_parameters): explicit ServerPool dependency, closure…
May 12, 2026
c438d6f
feat(metrics): count dedicated_mode startup_parameters drops
May 12, 2026
1a88da2
feat(grafana): startup_parameters row on the dashboard
May 12, 2026
42894c7
fix(pool): pass base_startup_parameters to retain test helper
May 12, 2026
2cb0944
ci(grafana): allow empty Startup Parameters panels in demo smoke
May 12, 2026
2d8340b
docs: tighten startup_parameters changelog, tutorial, and SHOW reference
May 12, 2026
c8df8e2
fix(pool): advance startup hash only after reload commit
May 12, 2026
69b3235
fix(pool): skip TLS retry on operator startup-parameter rejection
May 12, 2026
560fbcc
fix(pool): recycle dynamic pools on pool.startup_parameters reload
May 12, 2026
221bfdf
fix(pool): freeze per-user auth_query overlay at dynamic pool creation
May 12, 2026
db2ada3
fix(web): redact startup_parameter values for anonymous /api/pools
May 12, 2026
176e583
fix(pool): preserve ServerStartupParameterRejection on fallback path
May 12, 2026
46f514d
fix(auth_query): drop dynamic pool when refetch changes per-user overlay
May 12, 2026
a2f5c5f
fix(pool): keep baseline when oversize auth_query overlay would strip it
May 12, 2026
ac43df0
fix(metrics): count silent auth_query startup_parameter drops
May 12, 2026
1aa3fe3
fix(metrics): unify startup_parameters_dropped_total on per-event units
May 12, 2026
b59d724
perf(pool): resolve startup_parameters once per fallback round
May 12, 2026
2c3e8c2
docs(metrics): clarify pool label is the pool name, not user@database
May 12, 2026
963027b
perf(auth_query): share startup_parameters via Arc on cache hit
May 12, 2026
a60eaed
fix(grafana): drop user/database selectors from startup_parameters pa…
May 12, 2026
8394efd
fix(admin/web): cross-check SHOW STARTUP_PARAMETERS against wire-read…
May 12, 2026
03ed3e9
perf: single-pass packet sizing + Arc-shared operator key set
May 12, 2026
26853fa
perf(auth_query): validate JSON entries without per-entry BTreeMap
May 12, 2026
3f03823
ci(bdd): cap BDD matrix at 4 parallel suites
May 12, 2026
40a5822
fix(startup_parameters): reject role and session_authorization
May 12, 2026
a9acb6a
fix(web): redact startup_parameter values in anonymous /api/config
May 12, 2026
f151f9a
fix(auth): preserve ServerStartupParameterRejection through cold auth
May 12, 2026
702f7e4
fix(pool): recycle dedicated auth_query shared pool on parent config …
May 12, 2026
b5b8ec5
fix(pool): split startup_parameter resolver into pure + side-effectin…
May 12, 2026
ae7bba2
fix(server): canonicalize operator_managed_startup_keys for sync_para…
May 12, 2026
b5a9772
fix(auth_query): pass fetched overlay into create_dynamic_pool
May 12, 2026
882f884
ci: retry Grafana smoke and BDD suites on transient failure
May 12, 2026
f240a0f
docs: editorial pass on startup_parameters tutorials, references, and…
May 12, 2026
0280499
feat(web): render startup_parameter value and state in PoolDetail
May 12, 2026
09c41bd
chore(reference): regenerate pg_doorman.toml/yaml after fields.yaml e…
May 12, 2026
802a09f
feat(web): add opt-in HTTPS gate for SSO credentials
May 12, 2026
8332473
feat(web): redesign sign-in surface as a Bloomberg-style console
May 12, 2026
dd09d36
chore(gitignore): ignore nested cargo target dirs and internal-plans/
May 12, 2026
b6463d3
fix(web): allow http sso_proxy_url so SSO works behind a TLS-terminat…
May 12, 2026
e0b0f46
ci(bdd): bump cargo retry to 3 with 30s wait so DNS flakes settle
May 12, 2026
5b77586
ci(bdd): share host network and widen cargo retry so DNS isolation ca…
May 12, 2026
19313b2
ci(bdd): revert outer retry bump — DNS isolation is the real fix, not…
May 12, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .github/workflows/bdd-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -222,6 +222,12 @@ jobs:
packages: read
strategy:
fail-fast: false
# GitHub-hosted runners share CPU under heavy matrix fan-out, and
# the timing-sensitive scenarios (sleep-based retain/lifetime
# waits, SCRAM passthrough reconnect) lose their margin when 20+
# BDD jobs run in parallel. Cap concurrency so each suite gets a
# less contested runner.
max-parallel: 4
matrix:
suite:
- { name: "Go", cargo: "test --test bdd -- --tags @go" }
Expand All @@ -245,6 +251,7 @@ jobs:
- { name: "Patroni-assisted fallback", cargo: "test --test bdd -- --tags @patroni_fallback" }
- { name: "Server TLS", cargo: "test --test bdd -- --tags @server-tls" }
- { name: "TLS migration (vendored OpenSSL)", cargo: "test --features tls-migration --test bdd -- --tags @tls-migration" }
- { name: "Startup parameters", cargo: "test --test bdd -- --tags @startup-parameters" }
steps:
- name: Checkout repository
uses: actions/checkout@v4
Expand Down
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,9 @@ flamegraph-output/
# Superpowers brainstorm session workdir (VC mockups, server state)
.superpowers/

# Superpowers spec drafts (private session artifacts)
/docs/superpowers/

# Per-session agent handoff scratchpads — not part of public history.
.local/

Expand Down
2 changes: 1 addition & 1 deletion Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "pg_doorman"
version = "3.8.5"
version = "3.9.0"
edition = "2021"
rust-version = "1.87.0"
license = "MIT"
Expand Down
1 change: 1 addition & 0 deletions documentation/en/src/SUMMARY.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@
- [Pool Modes](concepts/pool-modes.md)
- [Pool Coordinator](concepts/pool-coordinator.md)
- [Anonymous Parse Caching](tutorials/prepared-statements.md)
- [PostgreSQL startup parameters](tutorials/startup-parameters.md)
- [Pool Pressure (advanced)](tutorials/pool-pressure.md)

# High Availability
Expand Down
6 changes: 5 additions & 1 deletion documentation/en/src/authentication/auth-query.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,11 @@ pools:
cache_failure_ttl: "30s"
```

The query must return a column named `passwd` or `password` containing the MD5 or SCRAM hash. Extra columns are ignored.
The query must return a column named `passwd` or `password` containing
the MD5 or SCRAM hash. Extra columns are ignored except for
`startup_parameters`. In passthrough mode, pg_doorman reads that column
as a `text` JSON object with per-user PostgreSQL startup parameters.
Dedicated mode ignores the column and logs a warning.

`user` and `password` are the credentials PgDoorman uses to run the lookup query. They must have permission to read the credential column. Either grant access to a custom view (recommended) or use a user in `pg_read_server_files` group.

Expand Down
80 changes: 80 additions & 0 deletions documentation/en/src/changelog.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,85 @@
# Changelog

### 3.9.0

Per-pool PostgreSQL startup parameters. pg_doorman can now add
operator-defined GUCs to each backend `StartupMessage`. Values merge in
three layers: `general.startup_parameters`, `pools.<name>.startup_parameters`,
and the optional `startup_parameters` column returned by passthrough
`auth_query`.

PostgreSQL stores these values as the session reset defaults, so
client-side `RESET ALL` and `DISCARD ALL` return to the operator value.
This gives one pool a different `plan_cache_mode`, `statement_timeout`,
`work_mem`, or `idle_in_transaction_session_timeout` without changing
`postgresql.conf`, `ALTER ROLE`, or `ALTER DATABASE`.

#### Cascade resolution

- `general.startup_parameters`, `pools.<name>.startup_parameters`, and
the optional `startup_parameters` text column on an `auth_query` row
merge per key. The later layer wins.
- Dedicated `auth_query` mode uses a shared `server_user`, so
pg_doorman ignores the per-user column there and logs one warning per
pool and username.
- A reload that changes startup parameters recycles the affected pools.
Idle backends with the old reset defaults are not reused.

#### Validation and protocol safety

- Reserved protocol keys (`user`, `database`, `replication`,
`options`, the `_pq_.*` extension prefix) are refused at config load.
- Keys must match the PG GUC naming shape `[A-Za-z_][A-Za-z0-9_.]*`,
values must not contain null bytes, and each level fits the operator
budget of `MAX_STARTUP_PACKET_LENGTH - 512` bytes.
- The full cascade is checked before each backend startup against PG's 10 000-byte
`MAX_STARTUP_PACKET_LENGTH`; if the union would overflow, all
operator-supplied keys are dropped for that spawn and the event is
logged. That backend starts with PostgreSQL defaults for those keys.

#### Behaviour on PG-side rejection

- If PostgreSQL rejects an operator-supplied startup parameter at
backend startup, pg_doorman forwards the `ErrorResponse` to the
client unchanged. There is no retry with the key removed and no
per-key quarantine. Fix the parameter in the config; until then,
backend startup for that pool fails with PostgreSQL's own SQLSTATE and
message.
- SQLSTATE class `57P` (server unavailable) keeps mapping to
`ServerUnavailableError` first so the Patroni-assisted fallback
path can route around the failed node before the startup-parameter
log line fires.
- The operator-supplied parameter wins over the client sync path:
even if the client connect string carries an `application_name`
(or another tracked GUC like `TimeZone`), the per-checkout
`sync_parameters` call no longer overrides the operator value on
the backend. The operator-configured default stands until an
explicit `SET` statement on the client session changes it.

#### RELOAD coherence

- A SIGHUP that changes `general.startup_parameters` drains pools that
inherit that baseline. The per-pool config hash includes the general
startup map, and carried-over dynamic `auth_query` pools are recycled
when the baseline changes.

#### Observability

- `pg_doorman_backend_startup_parameter_errors_total{pool, sqlstate}`
counts every backend startup rejected by PostgreSQL because of an
operator-supplied parameter. The failing parameter name and
username are written to the warning log line, not to metric labels.
- `SHOW STARTUP_PARAMETERS` (admin SQL console) lists the per-pool
effective cascade with the layer that supplied each value. `psql` tab
completion on `SHOW <TAB>` now includes the command.
- The Web UI pool detail page shows the same data in a
"Startup parameters (operator-injected)" section, driven by the
new `startup_parameters[]` field on `/api/pools`.

See [PostgreSQL startup parameters](tutorials/startup-parameters.md)
for the operator walkthrough, plus [General Settings](reference/general.md)
and [Pool Settings](reference/pool.md) for the full parameter list.

### 3.8.5

The web console now accepts JWTs issued by an external SSO proxy
Expand Down
1 change: 1 addition & 0 deletions documentation/en/src/comparison.md
Original file line number Diff line number Diff line change
Expand Up @@ -77,6 +77,7 @@ See [Patroni-assisted fallback](tutorials/patroni-assisted-fallback.md), [`patro
| LISTEN / NOTIFY pinning in transaction mode | No | No | Experimental |
| Cross-rule connection cap (`shared_pool`) | No | No | Yes (since 1.5.1) |
| `PAUSE` / `RESUME` / `RECONNECT` admin commands | Yes | Yes | Yes (since 1.4.1) |
| Operator-defined PostgreSQL GUCs in backend `StartupMessage` per pool | Yes (`startup_parameters`, three-level cascade `general` → pool → `auth_query` passthrough; values survive client `RESET ALL` / `DISCARD ALL`; PG startup errors are forwarded unchanged) | No equivalent operator-defined cascade; selected client startup parameters can be tracked or ignored | No (`maintain_params` preserves client-side parameters across rebind; no operator-defined GUCs) |

See [Pool Coordinator](concepts/pool-coordinator.md), [Pool pressure](tutorials/pool-pressure.md).

Expand Down
14 changes: 14 additions & 0 deletions documentation/en/src/observability/admin-commands.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@ Admin commands are read with `SHOW <subcommand>` or executed with bare verbs (`P
| `SHOW LISTS` | Counts by category (databases, users, pools, clients, servers). |
| `SHOW USERS` | List of users and their pool modes. |
| `SHOW AUTH_QUERY` | `auth_query` cache hit/miss/refetch rates, auth success/failure, executor errors, dynamic pool counts. |
| `SHOW STARTUP_PARAMETERS` | Effective `startup_parameters` cascade per pool: parameter, value, and contributing layer. |
| `SHOW SOCKETS` | TCP and Unix socket counts by state (Linux only — reads `/proc/net/`). |
| `SHOW LOG_LEVEL` | Current log level. |
| `SHOW VERSION` | PgDoorman version. |
Expand Down Expand Up @@ -68,6 +69,19 @@ mydb | app | 12 | 4 | 0 | 4 | 36 | 0
- `sv_idle` matches free backends; `sv_active` is in-use; `sv_used` is reserved by the coordinator (see below).
- `maxwait` is the longest current wait in seconds. If it grows beyond `query_wait_timeout`, clients get errors.

### `SHOW STARTUP_PARAMETERS`

```
user | database | parameter | value | source
app | mydb | statement_timeout | 5s | general
app | mydb | plan_cache_mode | force_custom_plan | pool
```

- `source` shows the layer that supplied the winning value: `general`,
`pool`, or `auth_query`.
- The command reports the same effective cascade used for new backend
`StartupMessage` packets.

### `SHOW POOL_COORDINATOR`

```
Expand Down
172 changes: 172 additions & 0 deletions documentation/en/src/tutorials/startup-parameters.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,172 @@
# PostgreSQL startup parameters

Use `startup_parameters` when a pool needs PostgreSQL GUC defaults that
should be set at backend startup, without changing `postgresql.conf`,
`ALTER ROLE`, or `ALTER DATABASE`.

- A hot OLTP pool is affected by a sticky generic plan after the
`plan_cache_mode = auto` heuristic flips. Switching the whole role
to `force_custom_plan` would affect every workload using that role;
setting it on one pool limits the blast radius.
- An application that does not set its own `statement_timeout` or
`idle_in_transaction_session_timeout` and cannot be patched fast
enough. The DBA needs a server-side default that survives the
application's own session resets.
- A single application that should announce a stable
`application_name` regardless of what the connecting driver
negotiates, so `pg_stat_activity` and audit logs stay legible.

## Configuration

The cascade has three levels; the more specific level wins per key:

```toml
[general.startup_parameters]
statement_timeout = "5s"

[pools.checkout.startup_parameters]
plan_cache_mode = "force_custom_plan"
work_mem = "64MB"
```

After `SIGHUP` (or `RELOAD` on the admin console) every new backend
for the `checkout` pool starts with `statement_timeout = 5s`,
`plan_cache_mode = force_custom_plan`, and `work_mem = 64MB`. Other
pools keep `statement_timeout = 5s` from `general` and the PG default
for the rest. Already-open backends are not affected; the change takes
hold as the pool rotates connections.

When `auth_query` runs in passthrough mode (no `server_user`), the
lookup SQL may return an optional `startup_parameters` text column
holding a JSON object. Values from that column override both
`general` and per-pool settings for that user only:

```sql
SELECT
rolpassword AS passwd,
CASE rolname
WHEN 'vip' THEN '{"work_mem":"256MB"}'::text
ELSE NULL::text
END AS startup_parameters
FROM pg_authid
WHERE rolname = $1;
```

The column must serialise as `text`. If the SQL returns `json` or
`jsonb`, add an explicit `::text` cast. pg_doorman reads the column
as `text` and logs a one-time warning per user when the type does
not match.

Dedicated `auth_query` mode (`server_user` set) ignores the per-user
column and logs once per (pool, username): one shared backend serves
many users, so a per-user override cannot apply.

## What pg_doorman does with the values

The merged map is written into the PostgreSQL `StartupMessage` of
every backend pg_doorman opens. PG records each entry as the session
default for that setting (`pg_settings.reset_val` and
`pg_settings.source = 'client'`), so client-side `RESET ALL` and
`DISCARD ALL` restore the operator value rather than discarding it.
Operators get a stable session default without editing
`postgresql.conf` or running `ALTER ROLE`.

The values can be observed from the client:

```text
checkout=> SHOW plan_cache_mode;
plan_cache_mode
-------------------
force_custom_plan

checkout=> SET plan_cache_mode = 'auto'; RESET ALL; SHOW plan_cache_mode;
plan_cache_mode
-------------------
force_custom_plan
```

## Validation

At config load:

- Keys must match PG GUC naming `^[A-Za-z_][A-Za-z0-9_.]*$`. Namespaced
names like `auto_explain.log_min_duration` are accepted; arbitrary
punctuation is not.
- Reserved keys (`user`, `database`, `replication`, `options`, and
anything starting with `_pq_.`) are refused. pg_doorman manages
them itself or PG treats them specially in the StartupMessage.
- Values must not contain null bytes.
- Each level (general or per-pool) must fit within the operator
budget: `MAX_STARTUP_PACKET_LENGTH` (10 000 bytes) minus 512 bytes
reserved for pg_doorman-managed keys.

At every backend spawn pg_doorman re-checks the merged cascade
against the same cap. Two levels that fit individually can together
push past it once `auth_query` adds a third layer; when that happens
pg_doorman drops every operator-supplied key for that one spawn,
logs the byte counts, and starts the backend with PostgreSQL defaults
for those keys.

## What happens when PG rejects a parameter

If PostgreSQL rejects an operator-supplied parameter at backend
startup, pg_doorman forwards the PG `ErrorResponse` to the client
unchanged. The client sees the same sqlstate (`22023`,
`42704`, `42501`, `55P02`, or any other code under the startup family)
and the same message it would have seen connecting to PG directly.

pg_doorman does not retry with the parameter removed and does not keep a
per-pool quarantine. The next client connection sends the same
`StartupMessage`; fix the config before routing traffic back to that
pool.

## Observability

The admin SQL console exposes the per-pool effective cascade:

```text
admin> SHOW STARTUP_PARAMETERS;
user | database | parameter | value | source
-------+----------+------------------+-------------------+-----------
shop | checkout | plan_cache_mode | force_custom_plan | pool
shop | reports | statement_timeout| 10s | general
```

The Web UI's pool detail page shows the same view in the "Startup
parameters (operator-injected)" section.

Prometheus exports one counter for PG-side rejections:

- `pg_doorman_backend_startup_parameter_errors_total{pool, sqlstate}`
counts every backend startup PostgreSQL rejected because of an
operator-supplied parameter. The failing parameter name and
username are written to the warning log line, not to metric labels.

Alert on a non-zero
`pg_doorman_backend_startup_parameter_errors_total` rate for the same
pool over several minutes. That usually means new backend startups for
the pool are failing on the same operator GUC.

## When not to use this

- The application already sets the parameter on every connection.
Duplicating the value in `startup_parameters` adds another config path
without changing behavior.
- Per-transaction tuning (`SET LOCAL`). `startup_parameters` is for
session defaults; transaction-scoped tuning belongs in the
application.
- Anything that needs to depend on which query the application is
running. Startup parameters apply to every transaction on every
backend for the lifetime of that backend; there is no
per-statement variant.

## Reference

- [General Settings](../reference/general.md): `startup_parameters`.
- [Pool Settings](../reference/pool.md):
`pools.<name>.startup_parameters`.
- [auth_query](../authentication/auth-query.md): passthrough vs
dedicated modes, where the `startup_parameters` column is read.
- [Admin Commands](../observability/admin-commands.md):
`SHOW STARTUP_PARAMETERS`.
- [Prometheus](../reference/prometheus.md): full metric list.
1 change: 1 addition & 0 deletions documentation/ru/src/SUMMARY.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@
- [Режимы пула](concepts/pool-modes.md)
- [Координатор пулов](concepts/pool-coordinator.md)
- [Кеш Parse для анонимных prepared statements](tutorials/prepared-statements.md)
- [Параметры запуска PostgreSQL](tutorials/startup-parameters.md)
- [Пул под нагрузкой (продвинутое)](tutorials/pool-pressure.md)

# Высокая доступность
Expand Down
7 changes: 6 additions & 1 deletion documentation/ru/src/authentication/auth-query.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,12 @@ pools:
cache_failure_ttl: "30s"
```

Запрос должен возвращать колонку с именем `passwd` или `password`, содержащую хеш MD5 или SCRAM. Дополнительные колонки игнорируются.
Запрос должен возвращать колонку с именем `passwd` или `password`,
содержащую хеш MD5 или SCRAM. Дополнительные колонки игнорируются, кроме
необязательной `startup_parameters`. В passthrough-режиме pg_doorman
читает её как JSON-объект в `text` с пользовательскими параметрами
запуска PostgreSQL. Dedicated-режим игнорирует её и пишет
предупреждение.

`user` и `password` — это учётные данные, под которыми pg_doorman выполняет lookup-запрос. У них должно быть право читать колонку с учётными данными. Либо выдайте доступ к специально созданному представлению (рекомендуется), либо используйте пользователя из группы `pg_read_server_files`.

Expand Down
1 change: 1 addition & 0 deletions documentation/ru/src/comparison.md
Original file line number Diff line number Diff line change
Expand Up @@ -77,6 +77,7 @@ PgCat намеренно опущен: у него центр тяжести —
| LISTEN / NOTIFY pinning в transaction mode | Нет | Нет | Экспериментально |
| Cross-rule connection cap (`shared_pool`) | Нет | Нет | Да (с 1.5.1) |
| Команды администратора `PAUSE` / `RESUME` / `RECONNECT` | Да | Да | Да (с 1.4.1) |
| GUC PostgreSQL, заданные оператором и переданные в `StartupMessage` бэкенда на уровне пула | Да (`startup_parameters`, трёхуровневый каскад `general` → пул → `auth_query` passthrough; значения переживают клиентские `RESET ALL` / `DISCARD ALL`; если PG отвергает параметр, `ErrorResponse` пробрасывается клиенту без изменений — никаких скрытых повторов) | Нет эквивалентного каскада с таким контрактом сброса; отдельные клиентские startup-параметры можно отслеживать или игнорировать, но не задавать оператором на уровне пула | Нет (`maintain_params` сохраняет параметры клиента при rebind, операторского задания GUC нет) |

См. [Координатор пулов](concepts/pool-coordinator.md), [Пул под нагрузкой](tutorials/pool-pressure.md).

Expand Down
Loading
Loading