Credentials
pgvfs finds its credentials the same way DuckDB’s postgres extension does,
and so the same way DuckLake’s catalog does. One secret can serve both:
- The
postgressecret named bySET pgvfs_secret = 'name'. Pair it withATTACH ... (META_SECRET 'name'). - Otherwise the
PGVFS_URLenvironment variable (a URL orkey=valuestring). - Otherwise the unnamed default
postgressecret, which is also DuckLake’s default.
Secrets redact the password, and no setting holds one. Options the client
does not support (passfile, sslrootcert, service, RDS IAM) are rejected
rather than ignored. TLS: remote servers need sslmode=require (certificates
are checked against the system CAs, plus PGVFS_DB_CA_FILE), and
PGVFS_DB_ALLOW_PLAINTEXT=true allows plaintext on an isolated network.
Roles:
- Readers:
USAGEon schemapgvfsandSELECTon its tables (ALTER DEFAULT PRIVILEGEScan grant these ahead of the schema). - The writer:
CREATEon the database the first time, to install the schema, then ownership of it.