<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Addons on pgcli</title>
    <link>https://pgcli.pages.dev/docs/addon/</link>
    <description>Recent content in Addons on pgcli</description>
    <generator>Hugo</generator>
    <language>en-US</language>
    
    
    
      <lastBuildDate>Fri, 25 Sep 2026 11:29:56 +0800</lastBuildDate>
    
    
      <atom:link href="https://pgcli.pages.dev/docs/addon/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
        <title>PgBouncer</title>
        <link>https://pgcli.pages.dev/docs/addon/pgbouncer/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://pgcli.pages.dev/docs/addon/pgbouncer/</guid>
        <description>&lt;p&gt;PgBouncer is a lightweight connection pooler for PostgreSQL. As a pgcli addon&#xA;it runs as a container in front of one or more PostgreSQL instances, reusing&#xA;server connections across many short-lived client sessions — transaction-level&#xA;pooling by default.&lt;/p&gt;&#xA;&lt;p&gt;PgBouncer supports two deployment modes:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Local:&lt;/strong&gt; &lt;code&gt;pg addon install pgbouncer -i &amp;lt;instance&amp;gt;&lt;/code&gt; — stored under&#xA;&lt;code&gt;instances.&amp;lt;name&amp;gt;.addons&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Remote:&lt;/strong&gt; &lt;code&gt;pg addon install pgbouncer --dsn &amp;lt;dsn&amp;gt; --pg-name &amp;lt;name&amp;gt;&lt;/code&gt; —&#xA;stored in top-level &lt;code&gt;addons.pgbouncer&lt;/code&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;platform-support&#34;&gt;Platform support&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;PgBouncer works on &lt;strong&gt;Linux&lt;/strong&gt; (host networking, including cross-host pools) and&#xA;on &lt;strong&gt;macOS&lt;/strong&gt; for &lt;strong&gt;single-host dev/test&lt;/strong&gt; (the container joins the &lt;code&gt;pgcli-net&lt;/code&gt;&#xA;bridge and publishes its port, the same way a PG instance does under podman&#xA;machine). On macOS:&lt;/p&gt;</description>
      </item>
    <item>
        <title>Etcd</title>
        <link>https://pgcli.pages.dev/docs/addon/etcd/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://pgcli.pages.dev/docs/addon/etcd/</guid>
        <description>&lt;p&gt;etcd is a distributed key-value store. pgcli can run one or more etcd members&#xA;as a &lt;strong&gt;standalone, top-level addon&lt;/strong&gt; — shared infrastructure rather than a&#xA;per-instance sidecar. This is useful as the DCS (Distributed Concurrent Store)&#xA;backing a PostgreSQL HA stack, or as a general config/lock service.&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;&lt;strong&gt;Security caveat:&lt;/strong&gt; pgcli-managed etcd members currently run &lt;strong&gt;without&lt;/strong&gt;&#xA;TLS/CA certificates and &lt;strong&gt;without&lt;/strong&gt; authentication/RBAC — any client that can&#xA;reach a client port has full read/write access. Plan a deployment around&#xA;network isolation (loopback binds by default; keep advertised ports inside a&#xA;trusted network). CA/TLS and auth/RBAC support is on the roadmap for a later&#xA;release.&lt;/p&gt;</description>
      </item>
    <item>
        <title>PgDog</title>
        <link>https://pgcli.pages.dev/docs/addon/pgdog/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://pgcli.pages.dev/docs/addon/pgdog/</guid>
        <description>&lt;p&gt;&lt;a href=&#34;https://pgdog.dev&#34;&gt;PgDog&lt;/a&gt; is a high-performance Postgres proxy written in Rust&#xA;(the successor to PgCat). It provides connection pooling, read/write load&#xA;balancing across replicas, and horizontal sharding — in front of one or more&#xA;PostgreSQL backends. pgcli can run PgDog as a &lt;strong&gt;standalone, top-level addon&lt;/strong&gt;:&#xA;shared infrastructure rather than a per-instance sidecar.&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;&lt;strong&gt;Security caveat:&lt;/strong&gt; PgDog authenticates clients against &lt;strong&gt;plaintext&lt;/strong&gt;&#xA;passwords stored in &lt;code&gt;users.toml&lt;/code&gt;. pgcli writes that file mode &lt;code&gt;0600&lt;/code&gt; and&#xA;mounts it read-only into the container, but the passwords still sit in clear&#xA;text on disk and in &lt;code&gt;pg.yaml&lt;/code&gt;. Keep the listen port on loopback (the default)&#xA;or inside a trusted network, and treat the config file as a secret.&lt;/p&gt;</description>
      </item>
    <item>
        <title>PostgREST</title>
        <link>https://pgcli.pages.dev/docs/addon/postgrest/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://pgcli.pages.dev/docs/addon/postgrest/</guid>
        <description>&lt;p&gt;PostgREST is a single-process, stateless web server that turns a PostgreSQL&#xA;schema into a RESTful API. As a pgcli addon it runs as one container in front&#xA;of any PG endpoint — no data directory, no rendered config file, everything&#xA;configured through &lt;code&gt;PGRST_*&lt;/code&gt; environment variables.&lt;/p&gt;&#xA;&lt;p&gt;PostgREST is a &lt;strong&gt;proxy-type&lt;/strong&gt; addon like &lt;a href=&#34;../pgbouncer/&#34;&gt;PgBouncer&lt;/a&gt; and&#xA;&lt;a href=&#34;../pgdog/&#34;&gt;PgDog&lt;/a&gt;: it holds no state of its own. &lt;strong&gt;Two deployment modes&lt;/strong&gt;&#xA;mirror PgBouncer&amp;rsquo;s:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Local:&lt;/strong&gt; &lt;code&gt;pg addon install postgrest -i &amp;lt;instance&amp;gt;&lt;/code&gt; — stored as a sidecar&#xA;under &lt;code&gt;instances.&amp;lt;name&amp;gt;.addons.postgrest&lt;/code&gt;, DSN built from the instance.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Remote:&lt;/strong&gt; &lt;code&gt;pg addon install postgrest --dsn &amp;lt;dsn&amp;gt; --pg-name &amp;lt;name&amp;gt;&lt;/code&gt; —&#xA;stored in top-level &lt;code&gt;addons.postgrest&lt;/code&gt;.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The &lt;code&gt;--dsn&lt;/code&gt; in either mode is passed verbatim into the container&amp;rsquo;s&#xA;&lt;code&gt;PGRST_DB_URI&lt;/code&gt;, so it works against &lt;strong&gt;any&lt;/strong&gt; PG endpoint: a direct managed&#xA;instance, a &lt;a href=&#34;../pgbouncer/&#34;&gt;PgBouncer&lt;/a&gt; pool, or a Patroni cluster behind its&#xA;&lt;a href=&#34;../haproxy/&#34;&gt;HAProxy&lt;/a&gt; listener.&lt;/p&gt;</description>
      </item>
    <item>
        <title>RustFS</title>
        <link>https://pgcli.pages.dev/docs/addon/rustfs/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://pgcli.pages.dev/docs/addon/rustfs/</guid>
        <description>&lt;p&gt;&lt;a href=&#34;https://github.com/rustfs/rustfs&#34;&gt;rustfs&lt;/a&gt; is a Rust reimplementation of&#xA;S3-compatible object storage: the same S3 API, a web console, erasure-coded&#xA;multi-drive and multi-node layouts — and a completely different runtime model&#xA;from MinIO/silo. pgcli runs it as a &lt;strong&gt;standalone, top-level addon&lt;/strong&gt; with the&#xA;same CLI surface as &lt;a href=&#34;../minio/&#34;&gt;&lt;code&gt;minio&lt;/code&gt;&lt;/a&gt; and &lt;a href=&#34;../silo/&#34;&gt;&lt;code&gt;silo&lt;/code&gt;&lt;/a&gt; (install, TLS,&#xA;BYO certs, drives, logs, autostart), sharing the one port pool, but with three&#xA;differences that shape this page:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;strong&gt;A fixed container user.&lt;/strong&gt; Upstream rustfs bakes &lt;code&gt;User=rustfs&lt;/code&gt; (uid/gid&#xA;10001) into the image. pgcli works around this entirely &lt;strong&gt;inside its own&#xA;wrapper image&lt;/strong&gt; — see &lt;a href=&#34;https://pgcli.pages.dev/docs/addon/rustfs/#privileges-and-ownership&#34;&gt;Privileges and ownership&lt;/a&gt;&#xA;below — so a rustfs store needs no host-side ownership dance.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Three topologies, no multi-node single-drive.&lt;/strong&gt; rustfs speaks SNSD / SNMD&#xA;/ MNMD only — see &lt;a href=&#34;https://pgcli.pages.dev/docs/addon/rustfs/#deployment-modes&#34;&gt;Deployment modes&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Its own TLS filenames.&lt;/strong&gt; rustfs reads &lt;code&gt;rustfs_cert.pem&lt;/code&gt; / &lt;code&gt;rustfs_key.pem&lt;/code&gt;&#xA;from &lt;code&gt;RUSTFS_TLS_PATH&lt;/code&gt;, not MinIO&amp;rsquo;s &lt;code&gt;public.crt&lt;/code&gt; / &lt;code&gt;private.key&lt;/code&gt;.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Pick rustfs when you want a lean, Rust-native S3 endpoint; it can coexist with&#xA;minio and silo on one host (all three draw from the same port pool).&lt;/p&gt;</description>
      </item>
    <item>
        <title>HAProxy</title>
        <link>https://pgcli.pages.dev/docs/addon/haproxy/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://pgcli.pages.dev/docs/addon/haproxy/</guid>
        <description>&lt;p&gt;&lt;a href=&#34;https://www.haproxy.org&#34;&gt;HAProxy&lt;/a&gt; is the load balancer the Patroni docs&#xA;recommend putting in front of a cluster: clients connect to one stable address,&#xA;HAProxy health-checks each member&amp;rsquo;s REST API, and routes writes to the current&#xA;leader (and, in read/write-split mode, reads to the replicas). pgcli runs it as&#xA;a &lt;strong&gt;standalone, top-level addon&lt;/strong&gt; — shared routing infrastructure, not a&#xA;per-instance sidecar — pinned to the official &lt;code&gt;haproxy:3.2.23-alpine&lt;/code&gt; image.&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;&lt;strong&gt;Platform support:&lt;/strong&gt; the HAProxy addon is &lt;strong&gt;Linux-only&lt;/strong&gt; for now. It reaches&#xA;Patroni members over the host network, which the macOS &lt;code&gt;podman machine&lt;/code&gt; does&#xA;not expose to containers. On macOS &lt;code&gt;NewHAProxyManager&lt;/code&gt; fails fast with a&#xA;clear message; &lt;code&gt;pg addon list&lt;/code&gt; still shows installed instances without live&#xA;status.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Silo</title>
        <link>https://pgcli.pages.dev/docs/addon/silo/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://pgcli.pages.dev/docs/addon/silo/</guid>
        <description>&lt;p&gt;&lt;a href=&#34;https://silo.pgsty.com&#34;&gt;silo&lt;/a&gt; is Pigsty&amp;rsquo;s maintained fork of MinIO: S3-compatible&#xA;object storage with the web console bundled in, keeping MinIO&amp;rsquo;s wire contract&#xA;end to end — the S3 API, the &lt;code&gt;MINIO_*&lt;/code&gt; environment variables, the&#xA;&lt;code&gt;server /data --address :9000 --console-address :9001&lt;/code&gt; command line, the&#xA;&lt;code&gt;--certs-dir&lt;/code&gt; layout, and erasure-coded cluster mode. pgcli runs it as a&#xA;&lt;strong&gt;standalone, top-level addon&lt;/strong&gt; with exactly the same surface as the&#xA;&lt;a href=&#34;../minio/&#34;&gt;&lt;code&gt;minio&lt;/code&gt; addon&lt;/a&gt; — install, TLS, BYO certs, distributed mode, logs,&#xA;autostart. Pick silo over MinIO if you follow Pigsty&amp;rsquo;s releases; the two can&#xA;coexist on one host (they share one port pool, assigned without collision).&lt;/p&gt;</description>
      </item>
    <item>
        <title>MinIO</title>
        <link>https://pgcli.pages.dev/docs/addon/minio/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://pgcli.pages.dev/docs/addon/minio/</guid>
        <description>&lt;p&gt;&lt;a href=&#34;https://min.io&#34;&gt;MinIO&lt;/a&gt; is S3-compatible object storage. pgcli runs it as a&#xA;&lt;strong&gt;standalone, top-level addon&lt;/strong&gt; — shared infrastructure, not a per-instance&#xA;sidecar — with the web console included. It defaults to &lt;strong&gt;single-node&lt;/strong&gt; mode and&#xA;supports a genuinely distributed &lt;strong&gt;cluster mode&lt;/strong&gt; across hosts&#xA;(&lt;a href=&#34;https://pgcli.pages.dev/docs/addon/minio/#distributed--cluster-mode&#34;&gt;see below&lt;/a&gt;). Either way it is a general-purpose&#xA;object store. &lt;a href=&#34;../silo/&#34;&gt;silo&lt;/a&gt; — Pigsty&amp;rsquo;s MinIO fork, kept wire-compatible —&#xA;is available as a sibling addon with the identical feature surface; the two&#xA;share one port pool and can coexist on a host.&lt;/p&gt;</description>
      </item>
    
  </channel>
</rss>
