select open change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

CONFIGURATION / FILE LOCATIONS

Specifies the configuration file for host-based authentication (customarily called pg_hba.conf).

Type
string
Context
postmaster
Measured default
Not specified
Unit
Metadata snapshot
18

Definition PG 18 manual

Specifies the configuration file for host-based authentication (customarily called pg_hba.conf). This parameter can only be set at server start.

Measured default history
Version intervalDefault
9.0 – 19Not specified
Analysis & operational context

Authored guidance from the GUC source snapshot; the version-specific manual above is the definition reference. View source ↗

How it works

Sets the server's "hba" configuration file. The value is fixed when the server starts, so changing it requires a restart.

This path selects pg_hba.conf. The path setting is fixed at startup, while edits to the selected file take effect after reload and should be checked with pg_hba_file_rules before relying on them.

Monitor and change hba_file together with allow_alter_system, config_file, data_directory. Validate on the relevant server role and real workload, then use its postmaster context to choose session change, reload, or restart; a historical boot default is not the current effective value.

Operational considerations

Missing directory traversal, read, or write permission for the service account.

Confusing restart requirements for a path with reload behavior of the selected file contents.

Omitting the path on a failover node or from backup inventory.

Using a relative path that depends on an unstable working directory.

Workload guidance

OLAP: Follow the OLTP rule, and for separate mounts also verify boot ordering, backup coverage, and path consistency on failover nodes.

OLTP: hba_file is deployment topology, not workload tuning. Use an absolute path, least privilege, and atomic configuration rollout; verify access as the postgres service account before restart/reload.

SMALL: The default co-located layout is simplest. Split paths only for a concrete backup, packaging, or permission-isolation benefit.

Related entries

Further reading

Definition snapshot: english-manuals:703db3faa46be5866680c54230c… · English manual source