{"Entry":{"collection":"guc","key":"hosts_file","name":"hosts_file","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"File Locations","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"18","status":"added","to":"19"}],"content_hash":"ca082057afe4b6a577172bc5c91f55bb2b8e850af7524b7af8a6ff6653a089e3","context":"","default_changed_in":[],"default_history":[{"from":"19","to":"19","value":"Not specified"}],"editorial":{"advice":{"olap":"Apply the same security policy to batch drivers and long-lived ETL connections. Test clients that omit SNI, credential-expiry automation, reload behavior, and certificate-chain compatibility.","oltp":"Roll out through staged clients, validate certificate selection and expiry warnings, and monitor authentication failures. Keep a tested fallback and treat file permissions and secret rotation as part of the same change.","small":"Prefer a simple, documented TLS and credential policy. Do not enable multi-certificate routing without a test for every hostname and fallback path, and never weaken verification to hide configuration mistakes."},"mechanism":["PostgreSQL describes hosts_file as follows: “Sets the server's \"hosts\" configuration file.” The value is fixed when the server starts, so changing it requires a controlled restart. The atlas measures it in PG19 Beta 3; boot_val is the compiled or initialized baseline, not proof of a running cluster's effective setting.","The path identifies pg_hosts.conf, the server-side SNI mapping file introduced in PostgreSQL 19. When ssl_sni is enabled, hostname, /no_sni/, and wildcard entries select certificate, key, optional CA, and optional passphrase commands; an empty or missing file falls back to the ordinary postgresql.conf TLS files.","Read it together with ssl_sni, ssl_cert_file, ssl_key_file, ssl_ca_file. Check SHOW and pg_settings on the target server, verify the source and pending_restart fields, and compare workload, logs, and resource metrics before and after any change."],"pitfalls":["Treating the measured boot_val for hosts_file as proof of the effective value on an initialized or managed cluster.","Applying a change as though it were immediate while pg_settings reports postmaster context.","Changing this setting in isolation without checking the linked limits, observability, and rollback path.","Depending on beta behavior in production without retesting the PostgreSQL 19 final release."],"references":[{"title":"PostgreSQL 19 Beta 4: hosts_file","url":"https://www.postgresql.org/docs/19/runtime-config-file-locations.html#GUC-HOSTS-FILE"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["ssl_sni","ssl_cert_file","ssl_key_file","ssl_ca_file","hba_file"],"summary":"hosts_file — Sets the server's \"hosts\" configuration file. Observed in PG19 Beta 4; its last measured boot default is not set in PG19 Beta 4, with postmaster context. This is a beta-snapshot fact and can change before PostgreSQL 19 GA."},"enumvals":[],"first_version":"19","group":"File Locations","group_slug":"file-locations","imported_at":"2026-09-27T17:57:31.348079+08:00","intro_commit":{"authored_at":"2026-03-18T12:37:11+01:00","discussion":["https://postgr.es/m/1C81CD0D-407E-44F9-833A-DD0331C202E5@yesql.se"],"hash":"4f433025f666fa4a6209f0e847715767fb1c7ace","subject":"ssl: Serverside SNI support for libpq","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=4f433025f666fa4a6209f0e847715767fb1c7ace"},"key":"hosts_file","last_version":"20","max_val":"","min_val":"","name":"hosts_file","position":165,"present_in":["19","20"],"short_desc":"Specifies the configuration file for host-based SSL configuration (customarily called pg_hosts.conf).","short_desc_zh":"","source_rev":"english-manuals:794f7b43120fca58b58eddd53d2158a13c0927ea99959dc85c2f3f7d7c09fc8d","unit":"","vartype":"string"}},"Definition":{"Collection":"guc","Key":"hosts_file","SourceDatabase":"center","Version":"20","SourceTable":"guc","SourceKey":"hosts_file","SourceRevision":"english-manuals:794f7b43120fca58b58eddd53d2158a13c0927ea99959dc85c2f3f7d7c09fc8d","Facts":{"boot_val":null,"category":"File Locations","context":"","description":"Specifies the configuration file for host-based SSL configuration (customarily called pg_hosts.conf). This parameter can only be set at server start. See also Section 18.9.6.","doc":{"anchor":"GUC-HOSTS-FILE","file":"runtime-config-file-locations.html","lang":"en","sha256":"a6901f017a83b4df0017f021e68862993f824868a406022be0d9ba1fa9a40d06","slug":"devel"},"documented":true,"enumvals":[],"extra_desc":"","lang":"en","max_val":null,"metadata_version":"","min_val":null,"name":"hosts_file","short_desc":"","source":"english-manual","unit":"","vartype":"string"},"ManualEvidence":{"doc":{"anchor":"GUC-HOSTS-FILE","file":"runtime-config-file-locations.html","lang":"en","sha256":"a6901f017a83b4df0017f021e68862993f824868a406022be0d9ba1fa9a40d06","slug":"devel"}},"MeasuredEvidence":{"metadata_version":""}},"Text":{"Collection":"guc","Key":"hosts_file","SourceDatabase":"pgweb","Version":"20","Locale":"zh-Hans","Title":"hosts_file","Summary":"","BodyHTML":"\u003cp\u003e指定基于主机的 SSL 配置文件（通常称为 \u003ccode\u003epg_hosts.conf\u003c/code\u003e）。此参数只能在服务器启动时设置。另请参见\u003ca href=\"/docs/devel/ssl-tcp.html#SSL-SNI\" rel=\"nofollow\"\u003e第 18.9.6 节\u003c/a\u003e。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"52877cba008a5b0bf74397dbd1320dfd909c95b59745437e4d531efa8259ca49","Payload":{"carried_from":"19","carry_reason":"手册不含 pg_settings 事实，沿用 19","doc_html":"\u003cp\u003e指定基于主机的 SSL 配置文件（通常称为 \u003ccode class=\"filename\"\u003epg_hosts.conf\u003c/code\u003e）。此参数只能在服务器启动时设置。另请参见\u003ca href=\"/docs/devel/ssl-tcp.html#SSL-SNI\" title=\"18.9.6. SNI 配置\"\u003e第 18.9.6 节\u003c/a\u003e。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["19","20"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
