diff --git a/api/index.js b/api/index.js index 1577081..46083f7 100644 --- a/api/index.js +++ b/api/index.js @@ -7,24 +7,13 @@ const app = express(); app.use(cors()); app.use(express.json()); -const poolConfig = { +const pool = new Pool({ user: process.env.DB_USER || 'admin', host: process.env.DB_HOST || 'localhost', database: process.env.DB_NAME || 'sop_monitoring', password: process.env.DB_PASS || 'password', port: process.env.DB_PORT || 5432, -}; - -// If DB_SSL is true, or if we are connecting to an external host that likely requires SSL -if (process.env.DB_SSL === 'true' || (process.env.DB_HOST && process.env.DB_HOST !== 'db' && process.env.DB_HOST !== 'localhost')) { - poolConfig.ssl = { rejectUnauthorized: false }; -} else { - // Try adding SSL unconditionally if it's rejecting without encryption - // Since we saw "pg_hba.conf rejects connection for host ... no encryption", it requires SSL. - poolConfig.ssl = { rejectUnauthorized: false }; -} - -const pool = new Pool(poolConfig); +}); app.get('/api/changeovers', async (req, res) => { try { diff --git a/docker-compose.yaml b/docker-compose.yaml index acd9639..f130d08 100644 --- a/docker-compose.yaml +++ b/docker-compose.yaml @@ -11,6 +11,15 @@ services: volumes: - ./db:/docker-entrypoint-initdb.d - pgdata:/var/lib/postgresql/data + command: > + bash -c " + if [ -f /var/lib/postgresql/data/pg_hba.conf ]; then + sed -i 's/hostssl/host/g' /var/lib/postgresql/data/pg_hba.conf + echo 'host all all all md5' >> /var/lib/postgresql/data/pg_hba.conf + echo 'host all all all scram-sha-256' >> /var/lib/postgresql/data/pg_hba.conf + fi + exec docker-entrypoint.sh postgres + " api: build: ./api