PostgreSQL Server (EL)

PostgreSQL server with guarded initdb, SCRAM-SHA-256 auth, managed conf.d drop-in, templated pg_hba, and app database + owner provisioning. Original, live-tested (Molecule/podman) role.

ansibleDatabases

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-06-10 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o ansible-postgresql-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/ansible-postgresql/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle ansible-postgresql-1.0.0.sigstore.json \
  ansible-postgresql-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "d4f9cf63291177c67c3da04af7b71e9eba4a9ed4a7c565e495f853dae8cec13c  ansible-postgresql-1.0.0.tar.gz" | sha256sum -c

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-postgresql/badge)](https://www.iac-bazaar.com/catalog/ansible-postgresql?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [PostgreSQL Server (EL)](https://www.iac-bazaar.com/catalog/ansible-postgresql?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# PostgreSQL Server (EL): https://www.iac-bazaar.com/catalog/ansible-postgresql (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

postgresql-server

PostgreSQL server for Enterprise Linux as an idempotent Ansible role: package install, guarded initdb, SCRAM-SHA-256 authentication, a managed conf.d configuration drop-in, a templated pg_hba.conf, and provisioning of one application database + owner. Original work — not derived from a third-party role. Rocky/EL 10 ships PostgreSQL 16.

Live-tested with Molecule + podman (converge + idempotence + functional verify) on a systemd-enabled Rocky Linux 10 image.

What it does:

  • Installs postgresql-server + python3-psycopg2 via dnf.
  • Runs postgresql-setup --initdb exactly once (guarded by PG_VERSION in the data directory).
  • Enables include_dir = 'conf.d' and drops in a managed config: password_encryption = scram-sha-256, configurable listen_addresses (default localhost) and port.
  • Templates pg_hba.conf: local peer for postgres, SCRAM over loopback, plus your own extra rules (postgresql_server_hba_extra_rules).
  • Enables + starts the postgresql systemd service; restarts on config change.
  • Creates one application database and its owner role with a password (via the community.postgresql collection — see requirements.yml).

Requirements

  • EL 9/10 target with systemd (tested on Rocky Linux 10 / PostgreSQL 16).
  • The community.postgresql collection on the controller: ansible-galaxy collection install -r requirements.yml

License

Commercial — IaC Bazaar EULA. © IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-clickhouse

ClickHouse on EL 10 from the upstream LTS release (sha512-verified), as a hardened systemd service on loopback with the default user behind a password; the live test creates a MergeTree table, inserts a row and selects it back over HTTP; a query without credentials is refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-dragonfly

Dragonfly on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback behind a password kept in a flagfile; the live test speaks RESP itself: an unauthenticated PING and a wrong password are refused, AUTH + SET + GET round-trip. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-influxdb3

InfluxDB 3 Core on EL 10 from the vendor's release (checksum-verified), as a hardened systemd service on loopback with file object storage; the binary runs from its release directory (it links the Python it ships); the live test writes a point in line protocol and reads it back with SQL. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-mariadb-server

MariaDB bound to loopback (the package listens everywhere), with the mariadb-secure-installation steps applied by the role: anonymous users, the test database and remote root gone, LOAD DATA LOCAL off, reverse DNS off. Provisions an application database and a user that can see nothing else. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-meilisearch

Meilisearch on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback in production mode behind a master key; the live test creates an index and documents, waits for the indexing task, searches and finds the one match, and sees a keyless request refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-opensearch

OpenSearch 3 (sha512-verified min distribution, bundled JDK), one node on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test reads the root document, indexes one document with a refresh, finds it by a search, deletes the index and checks the keystore belongs to the service; the release tree stays read-only. Original role, live-tested on Rocky Linux 10.

View module