Skip to content

Updated principal-key/features/functions.md based on AA feedback #441

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 4 commits into
base: release-17.5.2
Choose a base branch
from

Conversation

Andriciuc
Copy link
Collaborator

In set-principal-key.md:

  • updated with correct code example using set_server_key_using_global parameter
  • updated note to reflect correct config

In features.md:

  • Removed temporary tables feature to clear confusion, removed logical replication mention, removed WAL encryption as a feature.

In functions.md:

  • Added ON FUNCTION for grant/revoke execution
  • Modified sensitive info bolded paragraph to important note
  • Small modifications to notes display, title cases and text fixes
  • added note to Add or modify Vault providers for keeping the same principal key.
  • Added warning for WAL in pg_tde_create_key_using_global_key_provider

In general:

  • Removed all logical replication mentions except the FAQ and in RC2 release note.

In set-principal-key.md:
* updated with correct code example using set_server_key_using_global parameter
* updated note to reflect correct config

In features.md:
* Removed temporary tables feature to clear confusion, removed logical replication mention, removed WAL encryption as a feature.

In functions.md:
* Added ON FUNCTION for grant/revoke execution
* Modified sensitive info bolded paragraph to important note
* Small modifications to notes display, title cases and text fixes
* added note to Add or modify Vault providers for keeping the same principal key.
* Added warning for WAL in pg_tde_create_key_using_global_key_provider

In general:
* Removed all logical replication mentions except the FAQ and in RC2 release note.
@codecov-commenter
Copy link

codecov-commenter commented Jun 18, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Please upload report for BASE (release-17.5.2@f631496). Learn more about missing BASE report.

Additional details and impacted files
@@                Coverage Diff                @@
##             release-17.5.2     #441   +/-   ##
=================================================
  Coverage                  ?   84.67%           
=================================================
  Files                     ?       21           
  Lines                     ?     2591           
  Branches                  ?      402           
=================================================
  Hits                      ?     2194           
  Misses                    ?      316           
  Partials                  ?       81           
Components Coverage Δ
access 81.11% <0.00%> (?)
catalog 88.22% <0.00%> (?)
common 77.77% <0.00%> (?)
encryption 73.45% <0.00%> (?)
keyring 72.88% <0.00%> (?)
src 91.48% <0.00%> (?)
smgr 94.88% <0.00%> (?)
transam ∅ <0.00%> (?)
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@Andriciuc Andriciuc changed the title initial update from AA feedback Updated principal-key/features/functions.md based on AA feedback Jun 18, 2025
* fixed keyfile to key file and keyfile proviers to key file providers
* updated remote config options to file paths for specific param warning note.
@@ -9,16 +9,13 @@ The following features are available for the extension:
* Data tables
* Index data for encrypted tables
* TOAST tables
* Temporary tables created during database operations
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's fine to leave "Temporary tables" in here since we do encrypt those. It's just that everything here is "created during database operations" so I didn't understand that part :)

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Initially I wanted to write: Temporary tables created during queries on encrypted tables are also encrypted

I am thinking that perhaps this is just a standard PostgreSQL feature, so maybe I should remove it, thoughts?

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Temporary tables is a standard feature that we can encrypt. You're thinking about temporary files created during query execution. those are not (yet) encrypted.

fixed keyfile to key file for title

Removed warning notes regarding remote config options.
restructured and improved paragraphs create key and creates keys
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants