diff --git a/helm/templates/configmap.yaml b/helm/templates/configmap.yaml index f5d8f23..b4d7fba 100644 --- a/helm/templates/configmap.yaml +++ b/helm/templates/configmap.yaml @@ -42,6 +42,8 @@ data: DB_NAME: {{ $postgres.name | quote }} DB_CERT_PATH: /tmp/certs/{{ $postgres.ssl.certFileName }} DB_KEY_PATH: /tmp/certs/{{ $postgres.ssl.keyFileName }} + {{- if $postgres.ssl.caFileName }} DB_CA_PATH: /tmp/certs/{{ $postgres.ssl.caFileName }} + {{- end }} DB_ENABLE_SSL_AUTH: {{ $postgres.ssl.enabled | quote }} {{- end }} diff --git a/src/DAL/connectionOptions.ts b/src/DAL/connectionOptions.ts index 4ad0167..9c637e2 100644 --- a/src/DAL/connectionOptions.ts +++ b/src/DAL/connectionOptions.ts @@ -19,7 +19,7 @@ export const createConnectionOptions = (dbConfig: DbConfig): DataSourceOptions = ssl: { key: readFileSync(sslPaths.key), cert: readFileSync(sslPaths.cert), - ca: readFileSync(sslPaths.ca), + ...(sslPaths.ca !== undefined && sslPaths.ca !== '' ? { ca: readFileSync(sslPaths.ca) } : {}), rejectUnauthorized, }, }; diff --git a/src/common/interfaces.ts b/src/common/interfaces.ts index 9b4bb15..ad5a163 100644 --- a/src/common/interfaces.ts +++ b/src/common/interfaces.ts @@ -20,7 +20,7 @@ export interface DbConfig extends PostgresConnectionOptions { database: string; enableSslAuth?: boolean; sslPaths?: { - ca: string; + ca?: string; cert: string; key: string; };