PostgreSQL SSL/TLS Add-on for PaaS
The PostgreSQL SSL/TLS add-on enforces encrypted client connections on a PostgreSQL node or cluster on MassiveGRID PaaS. It generates a certificate authority and server and client certificates, installs them in the certificate folder, configures PostgreSQL to require SSL and provides the client files for your applications.
Both buttons open the MassiveGRID PaaS dashboard with PostgreSQL SSL/TLS pre-selected. The trial needs no credit card.
PostgreSQL SSL/TLS Package Facts
| Attribute | Value |
|---|---|
| Package | Postgres SSL/TLS Encrypted Connection |
| Type | Add-on (attaches to an existing environment) |
| Category | Add-ons & Utilities |
| Software vendor / project | Jelastic / Virtuozzo (package) |
| Licence | Open-source add-on |
| Runtime / stack | Add-on for PostgreSQL standalone nodes and clusters |
| Regions | New York, London, Frankfurt, Singapore |
| Billing | Free add-on; the host environment is billed per use from $2.46/month |
| Free trial | 14 days, no credit card |
| Uptime SLA | 100% |
What is PostgreSQL SSL/TLS?
PostgreSQL supports TLS natively, but enabling it correctly means generating certificates, placing them with the right permissions, editing postgresql.conf and pg_hba.conf to require hostssl connections, and repeating the process on every standby. Miss a step and either connections fail or unencrypted access remains possible.
The add-on performs the whole procedure across the layer in one click and keeps newly added nodes consistent. Certificates are placed in /var/lib/jelastic/keys/SSL-TLS and the server is reloaded gracefully. It supports standalone PostgreSQL and the Primary-Secondary and Multi-Region clusters, encrypting both client connections and, where configured, replication traffic.
What PostgreSQL SSL/TLS Changes in Your Environment
Add-ons run against an environment you already have. Nothing is rebuilt, and the change can be removed from the same dashboard.
- Certificate authority and certificates: A CA plus server and client certificates generated for the PostgreSQL layer.
- Server configuration: ssl enabled in postgresql.conf and hostssl rules in pg_hba.conf so plain connections are refused, applied with a graceful reload.
- Client bundle: Client certificate, key and CA for applications to connect with verify-ca or verify-full.
- Scaling support: New standbys receive certificates and configuration automatically.
Why Teams Choose PostgreSQL SSL/TLS
Encryption enforced
Only SSL connections are accepted after the add-on is applied.
Covers replication
Streaming replication between primary and standbys can run over TLS too, important for multi-region clusters.
Compliance ready
Satisfies encryption-in-transit requirements in PCI DSS, HIPAA and GDPR-aligned policies.
Reversible and replaceable
Swap in your own CA-issued certificates or remove the add-on at any time.
How to Add PostgreSQL SSL/TLS on MassiveGRID PaaS
Attaching the add-on takes three steps and a few minutes of waiting. No servers to provision, no configuration files to edit.
Open the installer
Click Install with free trial or Install to my account. The MassiveGRID PaaS dashboard opens with the PostgreSQL SSL/TLS add-on pre-selected, so nothing has to be copied or pasted.
Sign up or sign in
New to the platform? Sign up for the free 14-day trial, which needs no credit card. Existing customers sign in with their usual dashboard credentials.
Pick the target environment
Choose the environment, and where relevant the node layer, that PostgreSQL SSL/TLS should attach to, then confirm. The add-on configures itself on the running nodes without a redeploy.
Who Runs PostgreSQL SSL/TLS on PaaS
Regulated workloads
Odoo, Cyclos, Django and other PostgreSQL-backed systems handling sensitive data.
Cross-region replication
Encrypting replication traffic between MassiveGRID regions.
Security baselines
Organisations requiring TLS on every internal service.
Why Run PostgreSQL SSL/TLS on MassiveGRID PaaS
Built for uptime. PostgreSQL SSL/TLS runs on MassiveGRID's high-availability platform, where every environment is covered by a 100% uptime SLA. Nodes live on redundant hosts, storage is replicated, and failed containers are restarted or migrated automatically.
Pay for what you use. Billing is hourly and per cloudlet (128 MiB RAM plus 400 MHz CPU). Vertical auto-scaling adds and removes cloudlets as load changes, so a quiet PostgreSQL SSL/TLS environment costs a few dollars a month and a busy one grows without a migration. Full details are on the PaaS page.
Your choice of jurisdiction. Deploy in New York, London, Frankfurt or Singapore and keep data inside the region your users or regulators require. MassiveGRID is ISO 9001 certified and GDPR compliant, and has run hosting infrastructure since 2003.
No lock-in. The package is a standard Jelastic Packaging Standard (JPS) manifest. You keep root-level access to the containers, can export the manifest, and can move the workload to any other Jelastic-compatible platform or to your own servers at any time.
Related on massivegrid.com: Security Overview.
PostgreSQL SSL/TLS Questions
More from the Marketplace
Packages that are often deployed alongside PostgreSQL SSL/TLS, or that solve the same problem a different way. Browse all 84 packages.
Deploy PostgreSQL SSL/TLS Today
Start the free 14-day trial and have PostgreSQL SSL/TLS running in minutes. No credit card required.