↑↓ 选择↵ 打开⌫ 切换范围完整搜索

PG.CENTER 连接 PostgreSQL 文档、百科与生态知识。由 Pigsty 维护。

Wiki / 连接参数

连接参数

版本覆盖矩阵

PostgreSQL 版本定义:18

当前阅读 PG 18·选择有来源记录的版本

51 / 51 条已记录定义实心方块表示该版本有定义;选择方块可阅读对应版本。
  • application_nameSession and protocol10 – 20

    Specifies a value for the application_name configuration parameter.

    此定义以英文显示

  • channel_bindingAuthentication13 – 20

    This option controls the client's use of channel binding. A setting of require means that the connection must employ channel binding, prefer means that the client will choose channel binding if available, and disable prevents the use of channel binding. The default is prefer if PostgreSQL is compiled with SSL support; otherwise the default is disable .

    此定义以英文显示

  • client_encodingSession and protocol10 – 20

    This sets the client_encoding configuration parameter for this connection. In addition to the values accepted by the corresponding server option, you can use auto to determine the right encoding from the current locale in the client ( LC_CTYPE environment variable on Unix systems).

    此定义以英文显示

  • connect_timeoutTimeouts and keepalives10 – 20

    Maximum time to wait while connecting, in seconds (write as a decimal integer, e.g., 10 ). Zero, negative, or not specified means wait indefinitely. This timeout applies separately to each host name or IP address. For example, if you specify two hosts and connect_timeout is 5, each host will time out if no connection is made within 5 seconds, so the total time spent waiting for a connection might be up to 10 seconds.

    此定义以英文显示

  • dbnameConnection destination10 – 20

    The database name. Defaults to be the same as the user name. In certain contexts, the value is checked for extended formats; see Section 32.1.1 for more details on those.

    此定义以英文显示

  • fallback_application_nameSession and protocol10 – 20

    Specifies a fallback value for the application_name configuration parameter. This value will be used if no value has been given for application_name via a connection parameter or the PGAPPNAME environment variable. Specifying a fallback name is useful in generic utility programs that wish to set a default application name but allow it to be overridden by the user.

    此定义以英文显示

  • gssdelegationGSSAPI and Kerberos16 – 20

    Forward (delegate) GSS credentials to the server. The default is 0 which means credentials will not be forwarded to the server. Set this to 1 to have credentials forwarded when possible.

    此定义以英文显示

    1011121314151617181920
  • gssencmodeGSSAPI and Kerberos12 – 20

    This option determines whether or with what priority a secure GSS TCP/IP connection will be negotiated with the server. There are three modes:

    此定义以英文显示

  • gsslibGSSAPI and Kerberos10 – 20

    GSS library to use for GSSAPI authentication. Currently this is disregarded except on Windows builds that include both GSSAPI and SSPI support. In that case, set this to gssapi to cause libpq to use the GSSAPI library for authentication instead of the default SSPI.

    此定义以英文显示

  • hostConnection destination10 – 20

    Name of host to connect to. If a host name looks like an absolute path name, it specifies Unix-domain communication rather than TCP/IP communication; the value is the name of the directory in which the socket file is stored. (On Unix, an absolute path name begins with a slash. On Windows, paths starting with drive letters are also recognized.) If the host name starts with @ , it is taken as a Unix-domain socket in the abstract namespace (currently supported on Linux and Windows). The default behavior when host is not specified, or is empty, is to connect to a Unix-domain socket in /tmp (or whatever socket directory was specified when PostgreSQL was built). On Windows, the default is to connect to localhost .

    此定义以英文显示

  • hostaddrConnection destination10 – 20

    Numeric IP address of host to connect to. This should be in the standard IPv4 address format, e.g., 172.28.40.9 . If your machine supports IPv6, you can also use those addresses. TCP/IP communication is always used when a nonempty string is specified for this parameter. If this parameter is not specified, the value of host will be looked up to find the corresponding IP address — or, if host specifies an IP address, that value will be used directly.

    此定义以英文显示

  • keepalivesTimeouts and keepalives10 – 20

    Controls whether client-side TCP keepalives are used. The default value is 1, meaning on, but you can change this to 0, meaning off, if keepalives are not wanted. This parameter is ignored for connections made via a Unix-domain socket.

    此定义以英文显示

  • keepalives_countTimeouts and keepalives10 – 20

    Controls the number of TCP keepalives that can be lost before the client's connection to the server is considered dead. A value of zero uses the system default. This parameter is ignored for connections made via a Unix-domain socket, or if keepalives are disabled. It is only supported on systems where TCP_KEEPCNT or an equivalent socket option is available; on other systems, it has no effect.

    此定义以英文显示

  • keepalives_idleTimeouts and keepalives10 – 20

    Controls the number of seconds of inactivity after which TCP should send a keepalive message to the server. A value of zero uses the system default. This parameter is ignored for connections made via a Unix-domain socket, or if keepalives are disabled. It is only supported on systems where TCP_KEEPIDLE or an equivalent socket option is available, and on Windows; on other systems, it has no effect.

    此定义以英文显示

  • keepalives_intervalTimeouts and keepalives10 – 20

    Controls the number of seconds after which a TCP keepalive message that is not acknowledged by the server should be retransmitted. A value of zero uses the system default. This parameter is ignored for connections made via a Unix-domain socket, or if keepalives are disabled. It is only supported on systems where TCP_KEEPINTVL or an equivalent socket option is available, and on Windows; on other systems, it has no effect.

    此定义以英文显示

  • krbsrvnameGSSAPI and Kerberos10 – 20

    Kerberos service name to use when authenticating with GSSAPI. This must match the service name specified in the server configuration for Kerberos authentication to succeed. (See also Section 20.6 .) The default value is normally postgres , but that can be changed when building PostgreSQL via the --with-krb-srvnam option of configure . In most environments, this parameter never needs to be changed. Some Kerberos implementations might require a different service name, such as Microsoft Active Directory which requires the service name to be in upper case ( POSTGRES ).

    此定义以英文显示

  • load_balance_hostsConnection destination16 – 20

    Controls the order in which the client tries to connect to the available hosts and addresses. Once a connection attempt is successful no other hosts and addresses will be tried. This parameter is typically used in combination with multiple host names or a DNS record that returns multiple IPs. This parameter can be used in combination with target_session_attrs to, for example, load balance over standby servers only. Once successfully connected, subsequent queries on the returned connection will all be sent to the same server. There are currently two modes:

    此定义以英文显示

    1011121314151617181920
  • max_protocol_versionSession and protocol18 – 20

    Specifies the protocol version to request from the server. The default is to use version 3.0 of the PostgreSQL protocol, unless the connection string specifies a feature that relies on a higher protocol version, in which case the latest version supported by libpq is used. If the server does not support the protocol version requested by the client, the connection is automatically downgraded to a lower minor protocol version that the server supports. After the connection attempt has completed you can use PQfullProtocolVersion to find out which exact protocol version was negotiated.

    此定义以英文显示

    1011121314151617181920
  • min_protocol_versionSession and protocol18 – 20

    Specifies the minimum protocol version to allow for the connection. The default is to allow any version of the PostgreSQL protocol supported by libpq, which currently means 3.0 . If the server does not support at least this protocol version the connection will be closed.

    此定义以英文显示

    1011121314151617181920
  • oauth_client_idAuthentication18 – 20

    An OAuth 2.0 client identifier, as issued by the authorization server. If the PostgreSQL server requests an OAuth token for the connection (and if no custom OAuth hook is installed to provide one), then this parameter must be set; otherwise, the connection will fail.

    此定义以英文显示

    1011121314151617181920
  • oauth_client_secretAuthentication18 – 20

    The client password, if any, to use when contacting the OAuth authorization server. Whether this parameter is required or not is determined by the OAuth provider; "public" clients generally do not use a secret, whereas "confidential" clients generally do.

    此定义以英文显示

    1011121314151617181920
  • oauth_issuerAuthentication18 – 20

    The HTTPS URL of a trusted issuer to contact if the server requests an OAuth token for the connection. This parameter is required for all OAuth connections; it should exactly match the issuer setting in the server's HBA configuration .

    此定义以英文显示

    1011121314151617181920
  • oauth_scopeAuthentication18 – 20

    The scope of the access request sent to the authorization server, specified as a (possibly empty) space-separated list of OAuth scope identifiers. This parameter is optional and intended for advanced usage.

    此定义以英文显示

    1011121314151617181920
  • optionsSession and protocol10 – 20

    Specifies command-line options to send to the server at connection start. For example, setting this to -c geqo=off or --geqo=off sets the session's value of the geqo parameter to off . Spaces within this string are considered to separate command-line arguments, unless escaped with a backslash ( \ ); write \\ to represent a literal backslash. For a detailed discussion of the available options, consult Chapter 19 .

    此定义以英文显示

  • passfileAuthentication10 – 20

    Specifies the name of the file used to store passwords (see Section 32.16 ). Defaults to ~/.pgpass , or %APPDATA%\postgresql\pgpass.conf on Microsoft Windows. (No error is reported if this file does not exist.)

    此定义以英文显示

  • passwordAuthentication10 – 20

    Password to be used if the server demands password authentication.

    此定义以英文显示

  • portConnection destination10 – 20

    Port number to connect to at the server host, or socket file name extension for Unix-domain connections. If multiple hosts were given in the host or hostaddr parameters, this parameter may specify a comma-separated list of ports of the same length as the host list, or it may specify a single port number to be used for all hosts. An empty string, or an empty item in a comma-separated list, specifies the default port number established when PostgreSQL was built.

    此定义以英文显示

  • replicationSession and protocol10 – 20

    This option determines whether the connection should use the replication protocol instead of the normal protocol. This is what PostgreSQL replication connections as well as tools such as pg_basebackup use internally, but it can also be used by third-party applications. For a description of the replication protocol, consult Section 54.4 .

    此定义以英文显示

  • require_authAuthentication16 – 20

    Specifies the authentication method that the client requires from the server. If the server does not use the required method to authenticate the client, or if the authentication handshake is not fully completed by the server, the connection will fail. A comma-separated list of methods may also be provided, of which the server must use exactly one in order for the connection to succeed. By default, any authentication method is accepted, and the server is free to skip authentication altogether.

    此定义以英文显示

    1011121314151617181920
  • requirepeerAuthentication10 – 20

    This parameter specifies the operating-system user name of the server, for example requirepeer=postgres . When making a Unix-domain socket connection, if this parameter is set, the client checks at the beginning of the connection that the server process is running under the specified user name; if it is not, the connection is aborted with an error. This parameter can be used to provide server authentication similar to that available with SSL certificates on TCP/IP connections. (Note that if the Unix-domain socket is in /tmp or another publicly writable location, any user could start a server listening there. Use this parameter to ensure that you are connected to a server run by a trusted user.) This option is only supported on platforms for which the peer authentication method is implemented; see Section 20.9 .

    此定义以英文显示

  • requiresslTLS10 – 20

    This option is deprecated in favor of the sslmode setting.

    此定义以英文显示

  • scram_client_keyAuthentication18 – 20

    The base64-encoded SCRAM client key. This can be used by foreign-data wrappers or similar middleware to enable pass-through SCRAM authentication. See Section F.38.1.10 for one such implementation. It is not meant to be specified directly by users or client applications.

    此定义以英文显示

    1011121314151617181920
  • scram_server_keyAuthentication18 – 20

    The base64-encoded SCRAM server key. This can be used by foreign-data wrappers or similar middleware to enable pass-through SCRAM authentication. See Section F.38.1.10 for one such implementation. It is not meant to be specified directly by users or client applications.

    此定义以英文显示

    1011121314151617181920
  • serviceConnection destination10 – 20

    Service name to use for additional parameters. It specifies a service name in pg_service.conf that holds additional connection parameters. This allows applications to specify only a service name so connection parameters can be centrally maintained. See Section 32.17 .

    此定义以英文显示

  • This parameter specifies the maximum SSL/TLS protocol version to allow for the connection. Valid values are TLSv1 , TLSv1.1 , TLSv1.2 and TLSv1.3 . The supported protocols depend on the version of OpenSSL used, older versions not supporting the most modern protocol versions. If not set, this parameter is ignored and the connection will use the maximum bound defined by the backend, if set. Setting the maximum protocol version is mainly useful for testing or if some component has issues working with a newer protocol.

    此定义以英文显示

  • This parameter specifies the minimum SSL/TLS protocol version to allow for the connection. Valid values are TLSv1 , TLSv1.1 , TLSv1.2 and TLSv1.3 . The supported protocols depend on the version of OpenSSL used, older versions not supporting the most modern protocol versions. If not specified, the default is TLSv1.2 , which satisfies industry best practices as of this writing.

    此定义以英文显示

  • sslcertTLS10 – 20

    This parameter specifies the file name of the client SSL certificate, replacing the default ~/.postgresql/postgresql.crt . This parameter is ignored if an SSL connection is not made.

    此定义以英文显示

  • sslcertmodeTLS16 – 20

    This option determines whether a client certificate may be sent to the server, and whether the server is required to request one. There are three modes:

    此定义以英文显示

    1011121314151617181920
  • sslcompressionTLS10 – 20

    If set to 1, data sent over SSL connections will be compressed. If set to 0, compression will be disabled. The default is 0. This parameter is ignored if a connection without SSL is made.

    此定义以英文显示

  • sslcrlTLS10 – 20

    This parameter specifies the file name of the SSL server certificate revocation list (CRL). Certificates listed in this file, if it exists, will be rejected while attempting to authenticate the server's certificate. If neither sslcrl nor sslcrldir is set, this setting is taken as ~/.postgresql/root.crl .

    此定义以英文显示

  • sslcrldirTLS14 – 20

    This parameter specifies the directory name of the SSL server certificate revocation list (CRL). Certificates listed in the files in this directory, if it exists, will be rejected while attempting to authenticate the server's certificate.

    此定义以英文显示

  • sslkeyTLS10 – 20

    This parameter specifies the location for the secret key used for the client certificate. It can either specify a file name that will be used instead of the default ~/.postgresql/postgresql.key , or it can specify a key obtained from an external “ engine ” (engines are OpenSSL loadable modules). An external engine specification should consist of a colon-separated engine name and an engine-specific key identifier. This parameter is ignored if an SSL connection is not made.

    此定义以英文显示

  • sslkeylogfileTLS18 – 20

    This parameter specifies the location where libpq will log keys used in this SSL context. This is useful for debugging PostgreSQL protocol interactions or client connections using network inspection tools like Wireshark . This parameter is ignored if an SSL connection is not made, or if LibreSSL is used ( LibreSSL does not support key logging). Keys are logged using the NSS format.

    此定义以英文显示

    1011121314151617181920
  • sslmodeTLS10 – 20

    This option determines whether or with what priority a secure SSL TCP/IP connection will be negotiated with the server. There are six modes:

    此定义以英文显示

  • sslnegotiationTLS17 – 20

    This option controls how SSL encryption is negotiated with the server, if SSL is used. In the default postgres mode, the client first asks the server if SSL is supported. In direct mode, the client starts the standard SSL handshake directly after establishing the TCP/IP connection. Traditional PostgreSQL protocol negotiation is the most flexible with different server configurations. If the server is known to support direct SSL connections then the latter requires one fewer round trip reducing connection latency and also allows the use of protocol agnostic SSL network tools. The direct SSL option was introduced in PostgreSQL version 17.

    此定义以英文显示

    1011121314151617181920
  • sslpasswordTLS13 – 20

    This parameter specifies the password for the secret key specified in sslkey , allowing client certificate private keys to be stored in encrypted form on disk even when interactive passphrase input is not practical.

    此定义以英文显示

  • sslrootcertTLS10 – 20

    This parameter specifies the name of a file containing SSL certificate authority ( CA ) certificate(s). If the file exists, the server's certificate will be verified to be signed by one of these authorities. The default is ~/.postgresql/root.crt .

    此定义以英文显示

  • sslsniTLS14 – 20

    If set to 1 (default), libpq sets the TLS extension “ Server Name Indication ” ( SNI ) on SSL-enabled connections. By setting this parameter to 0, this is turned off.

    此定义以英文显示

  • target_session_attrsConnection destination10 – 20

    This option determines whether the session must have certain properties to be acceptable. It's typically used in combination with multiple host names to select the first acceptable alternative among several hosts. There are six modes:

    此定义以英文显示

  • tcp_user_timeoutTimeouts and keepalives12 – 20

    Controls the number of milliseconds that transmitted data may remain unacknowledged before a connection is forcibly closed. A value of zero uses the system default. This parameter is ignored for connections made via a Unix-domain socket. It is only supported on systems where TCP_USER_TIMEOUT is available; on other systems, it has no effect.

    此定义以英文显示

  • userAuthentication10 – 20

    PostgreSQL user name to connect as. Defaults to be the same as the operating system name of the user running the application.

    此定义以英文显示