---
title: Charmhub | Deploy PgBouncer K8s using Charmhub - The Open Operator Collection
description: Deploy the latest version of PgBouncer K8s as a Kubernetes Operator on
  any cloud.
url: https://charmhub.io/pgbouncer-k8s/docs/h-enable-encryption
---

# PgBouncer K8s

[Canonical](https://charmhub.io/publisher/data-platform "View all packages from Canonical")

* [Canonical](https://charmhub.io/publisher/data-platform "View all packages from Canonical")
* [Databases](https://charmhub.io/?filter=databases)

Platform:

1/stable 593

```
juju deploy pgbouncer-k8s --channel 1/stable --trust
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

---

#### Relevant links

* [Homepage](https://ubuntu.com/data/postgresql)

---

#### Contacts

##### Maintainers

+ [Canonical Data Platform](mailto:data-platform@lists.launchpad.net)

* [Submit a bug](https://github.com/canonical/pgbouncer-k8s-operator/issues)

---

Share your thoughts on this charm with the community on discourse.

[Join the discussion](https://discourse.charmhub.io/)

# How to enable encryption

PgBouncer will enable encrypted connections by default with self generated certificates. Though also by default, connecting clients can disable encryption by setting the connection ssl-mode as disabled.
When related with the `tls-certificates-operator` the charmed operator for PgBouncer will require that every client connection (new and running connections) use encryption, rendering an error when attempting to establish an unencrypted connection.

> **Note**: The TLS settings here are for self-signed-certificates which are not recommended for production clusters, the `tls-certificates-operator` charm offers a variety of configurations, read more on the TLS charm [here](https://charmhub.io/tls-certificates-operator)

## [Enable TLS](https://charmhub.io/pgbouncer-k8s/docs/h-enable-encryption#p-28306-enable-tls)

```
# deploy the TLS charm
juju deploy tls-certificates-operator --channel legacy/stable

# add the necessary configurations for TLS
juju config tls-certificates-operator generate-self-signed-certificates="true" ca-common-name="Test CA"

# to enable TLS relate the two applications
juju relate tls-certificates-operator pgbouncer-k8s
```

## [Manage keys](https://charmhub.io/pgbouncer-k8s/docs/h-enable-encryption#p-28306-manage-keys)

Updates to private keys for certificate signing requests (CSR) can be made via the `set-tls-private-key` action. Note passing keys to external/internal keys should *only be done with* `base64 -w0` *not* `cat`. With three routers this schema should be followed:

* Generate a shared internal (private) key:

```
openssl genrsa -out internal-key.pem 3072
```

* apply newly generated internal key on each unit:

```
juju run pgbouncer-k8s/0 set-tls-private-key "internal-key=$(base64 -w0 internal-key.pem)"
juju run pgbouncer-k8s/1 set-tls-private-key "internal-key=$(base64 -w0 internal-key.pem)"
juju run pgbouncer-k8s/2 set-tls-private-key "internal-key=$(base64 -w0 internal-key.pem)"
```

* updates can also be done with auto-generated keys with:

```
juju run pgbouncer-k8s/0 set-tls-private-key
juju run pgbouncer-k8s/1 set-tls-private-key
juju run pgbouncer-k8s/2 set-tls-private-key
```

## [Disable TLS](https://charmhub.io/pgbouncer-k8s/docs/h-enable-encryption#p-28306-disable-tls)

To disable TLS, remove the relation:

```
juju remove-relation tls-certificates-operator pgbouncer-k8s
```

---
