Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 21 additions & 0 deletions docs/guides/administration/configuring-database.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,25 @@ The same is not necessarily true for platforms based on heavily modified Postgre
such as [CockroachDB] or [YugabyteDB]. Such solutions make certain trade-offs to achieve higher levels of scalability,
which might impact functionality that Dependency-Track relies on.

#### Google Cloud SQL

To connect through the [Cloud SQL socket factory][cloud-sql-jdbc], for example to use IAM database authentication,
add the socket factory to the API server. The container image doesn't include it.

1. [Build the socket factory JAR with its dependencies][cloud-sql-build].
2. Mount it into `/opt/owasp/dependency-track/lib-external/`. The API server loads every JAR in that directory.
3. Set the data source URL to your instance:

```yaml linenums="1" title="docker-compose.yaml"
services:
apiserver:
image: dependencytrack/apiserver
environment:
DT_DATASOURCE_URL: "jdbc:postgresql:///dtrack?cloudSqlInstance=<INSTANCE_CONNECTION_NAME>&socketFactory=com.google.cloud.sql.postgres.SocketFactory"
volumes:
- "./postgres-socket-factory-jar-with-dependencies.jar:/opt/owasp/dependency-track/lib-external/postgres-socket-factory.jar:ro"
```

### Self-hosting

#### Bare Metal / Docker
Expand Down Expand Up @@ -247,6 +266,8 @@ services:

[Autovacuum]: https://www.postgresql.org/docs/current/routine-vacuuming.html
[CockroachDB]: https://www.cockroachlabs.com/
[cloud-sql-build]: https://github.com/GoogleCloudPlatform/cloud-sql-jdbc-socket-factory#building-the-drivers
[cloud-sql-jdbc]: https://github.com/GoogleCloudPlatform/cloud-sql-jdbc-socket-factory/blob/main/docs/jdbc.md
[Neon]: https://neon.tech/
[PGTune]: https://pgtune.leopard.in.ua/
[PgBouncer]: https://www.pgbouncer.org/
Expand Down
14 changes: 14 additions & 0 deletions docs/guides/upgrading/v5.2.0.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,9 +48,23 @@
and [`dt.vex-upload.max-size-bytes`][max-upload-size-vex]. Both properties default to 100 MiB. Increase them if
your instances process documents larger than that.

* **The API server container image no longer includes `curl`**. The image's health check now uses `wget`.
If you override the health check or run `curl` in an `exec` probe, switch to `wget`:

```shell
wget -q -Y off -T 3 -O /dev/null http://127.0.0.1:9000/health
```

In Kubernetes, an `httpGet` probe against port `9000` needs no tool in the image at all.

* **The API server container image no longer includes the Google Cloud SQL socket factory**. If your database URL sets
`socketFactory=com.google.cloud.sql.postgres.SocketFactory`, the API server fails to connect after the upgrade.
Add the socket factory as described in [Google Cloud SQL][cloud-sql].

[access-control-svc]: ../../concepts/access-control.md#service-accounts
[allowed-destinations]: ../../reference/configuration/properties.md#dtoutboundallowed-destinations
[cargo-alt-reg]: https://doc.rust-lang.org/cargo/reference/registries.html#using-an-alternate-registry
[cargo-idx]: https://doc.rust-lang.org/cargo/reference/registry-index.html#sparse-protocol
[cloud-sql]: ../administration/configuring-database.md#google-cloud-sql
[max-upload-size-bom]: ../../reference/configuration/properties.md#dtbom-uploadmax-size-bytes
[max-upload-size-vex]: ../../reference/configuration/properties.md#dtvex-uploadmax-size-bytes
Loading