---
title: Charmhub | Deploy PgBouncer using Charmhub - The Open Operator Collection
description: Deploy the latest version of PgBouncer on any cloud.
url: https://charmhub.io/pgbouncer/docs/h-enable-encryption
---

# PgBouncer

[Canonical](https://charmhub.io/publisher/data-platform "View all packages from Canonical")

* [Canonical](https://charmhub.io/publisher/data-platform "View all packages from Canonical")
* [Databases](https://charmhub.io/?filter=databases)

Platform:

24.04

22.04

20.04

18.04

16.04

1/stable 1092

```
juju deploy pgbouncer --channel 1/stable
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

---

#### Relevant links

* [Homepage](https://ubuntu.com/data/postgresql)

---

#### Contacts

##### Maintainers

+ [Canonical Data Platform](mailto:data-platform@lists.launchpad.net)

* [Submit a bug](https://github.com/canonical/pgbouncer-operator/issues)

---

Share your thoughts on this charm with the community on discourse.

[Join the discussion](https://discourse.charmhub.io/)

# How to enable encryption

PgBouncer is a [subordinate charm](https://juju.is/docs/sdk/charm-taxonomy#heading--subordinate-charms). When integrated to a host application (principal charm), it serves on localhost, so TLS encryption is not necessary.

If you are using `data-integrator`, PgBouncer will open a port to listen to TCP traffic. In this case, because PgBouncer is exposed, **TLS encryption is recommended.**

## [Enable TLS](https://charmhub.io/pgbouncer/docs/h-enable-encryption#p-28389-enable-tls)

First, deploy the TLS charm:

```
juju deploy self-signed-certificates --config ca-common-name="Tutorial CA"
```

To enable TLS, integrate the two applications:

```
juju integrate self-signed-certificates pgbouncer
```

To enable TLS on PostgreSQL, refer to  [Charmed PostgreSQL | How to enable security](https://charmhub.io/postgresql/docs/t-enable-security).

---
