{"repo":"neondatabase/elephantshark","free":true,"listed":false,"github":"https://github.com/neondatabase/elephantshark","clone":"git clone https://github.com/neondatabase/elephantshark.git","description":"Postgres network traffic monitor","language":"Ruby","stars":138,"topics":["postgres","postgresql","protocol","ssl","sslkeylogfile","tls","wireshark","psql"],"license":"Apache-2.0","category":"databases-storage","readme_excerpt":"Elephantshark Elephantshark helps monitor, understand and troubleshoot Postgres network traffic: Postgres clients, drivers and ORMs talking to Postgres servers, proxies and poolers (also: standby servers talking to their primaries and subscriber servers talking to their publishers). Elephantshark sits between the two parties in a PostgreSQL-protocol exchange, forwarding messages in both directions while parsing and logging them. Why not just use Wireshark? Ordinarily Wireshark is great for this kind of thing, but using Wireshark is difficult if a connection is SSL/TLS-encrypted. SSLKEYLOGFILE support was recently merged into libpq, but it won’t be available in a release version for some time. And not all Postgres connections use libpq. To get round this, Elephantshark decrypts and re-encrypts a Postgres connection. It then logs and annotates the messages passing through. Or if you prefer to use Wireshark, Elephantshark can enable that by writing keys to an SSLKEYLOGFILE instead. Postgres and MITM attacks If your connection goes over a public network and you can use Elephantshark without changing any connection security options, you have an urgent security problem: you’re vulnerable to MITM attacks. Elephantshark isn’t the cause of the problem, but it can help show it up. A fully-secure Postgres connection requires at least one of these parameters on the client: channel binding=require , sslrootcert=system , sslmode=verify-full , or (when issuing certificates via your own cert","default_branch":null,"files":null,"tree":[],"storefront":"/r/neondatabase","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/neondatabase/elephantshark/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}