Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Credentials

pgvfs finds its credentials the same way DuckDB’s postgres extension does, and so the same way DuckLake’s catalog does. One secret can serve both:

  1. The postgres secret named by SET pgvfs_secret = 'name'. Pair it with ATTACH ... (META_SECRET 'name').
  2. Otherwise the PGVFS_URL environment variable (a URL or key=value string).
  3. Otherwise the unnamed default postgres secret, which is also DuckLake’s default.

Secrets redact the password, and no setting holds one. Options the client does not support (passfile, sslrootcert, service, RDS IAM) are rejected rather than ignored. TLS: remote servers need sslmode=require (certificates are checked against the system CAs, plus PGVFS_DB_CA_FILE), and PGVFS_DB_ALLOW_PLAINTEXT=true allows plaintext on an isolated network.

Roles:

  • Readers: USAGE on schema pgvfs and SELECT on its tables (ALTER DEFAULT PRIVILEGES can grant these ahead of the schema).
  • The writer: CREATE on the database the first time, to install the schema, then ownership of it.