|
| 1 | +CREATE EXTENSION IF NOT EXISTS pg_tde; |
| 2 | +SELECT pg_tde_add_key_provider_file('file-vault','/tmp/pg_tde_test_keyring.per'); |
| 3 | + pg_tde_add_key_provider_file |
| 4 | +------------------------------ |
| 5 | + 1 |
| 6 | +(1 row) |
| 7 | + |
| 8 | +SELECT pg_tde_set_principal_key('test-db-principal-key','file-vault'); |
| 9 | + pg_tde_set_principal_key |
| 10 | +-------------------------- |
| 11 | + t |
| 12 | +(1 row) |
| 13 | + |
| 14 | +SET default_table_access_method = "tde_heap"; |
| 15 | +CREATE TABLE t1(n integer); |
| 16 | +SELECT pg_tde_is_encrypted('t1'); |
| 17 | + pg_tde_is_encrypted |
| 18 | +--------------------- |
| 19 | + t |
| 20 | +(1 row) |
| 21 | + |
| 22 | +VACUUM FULL t1; |
| 23 | +SELECT pg_tde_is_encrypted('t1'); |
| 24 | + pg_tde_is_encrypted |
| 25 | +--------------------- |
| 26 | + t |
| 27 | +(1 row) |
| 28 | + |
| 29 | +CREATE TABLE test_tab1 AS SELECT generate_series(1,10) a; |
| 30 | +CREATE INDEX test_idx1 ON test_tab1(a); |
| 31 | +SELECT pg_tde_is_encrypted('test_tab1'); |
| 32 | + pg_tde_is_encrypted |
| 33 | +--------------------- |
| 34 | + t |
| 35 | +(1 row) |
| 36 | + |
| 37 | +SELECT pg_tde_is_encrypted('test_idx1'); |
| 38 | + pg_tde_is_encrypted |
| 39 | +--------------------- |
| 40 | + t |
| 41 | +(1 row) |
| 42 | + |
| 43 | +REINDEX index CONCURRENTLY test_idx1; |
| 44 | +SELECT pg_tde_is_encrypted('test_tab1'); |
| 45 | + pg_tde_is_encrypted |
| 46 | +--------------------- |
| 47 | + t |
| 48 | +(1 row) |
| 49 | + |
| 50 | +SELECT pg_tde_is_encrypted('test_idx1'); |
| 51 | + pg_tde_is_encrypted |
| 52 | +--------------------- |
| 53 | + t |
| 54 | +(1 row) |
| 55 | + |
| 56 | +CREATE TABLE mvtest_t (id int NOT NULL PRIMARY KEY, type text NOT NULL, amt numeric NOT NULL); |
| 57 | +INSERT INTO mvtest_t VALUES |
| 58 | + (1, 'x', 2), |
| 59 | + (2, 'x', 3), |
| 60 | + (3, 'y', 5), |
| 61 | + (4, 'y', 7), |
| 62 | + (5, 'z', 11); |
| 63 | +CREATE MATERIALIZED VIEW mvtest_tm AS SELECT type, sum(amt) AS totamt FROM mvtest_t GROUP BY type WITH NO DATA; |
| 64 | +SELECT pg_tde_is_encrypted('mvtest_tm'); |
| 65 | + pg_tde_is_encrypted |
| 66 | +--------------------- |
| 67 | + t |
| 68 | +(1 row) |
| 69 | + |
| 70 | +REFRESH MATERIALIZED VIEW mvtest_tm; |
| 71 | +SELECT pg_tde_is_encrypted('mvtest_tm'); |
| 72 | + pg_tde_is_encrypted |
| 73 | +--------------------- |
| 74 | + t |
| 75 | +(1 row) |
| 76 | + |
| 77 | +CREATE TYPE rewritetype AS (a int); |
| 78 | +CREATE TABLE rewritemetoo1 OF rewritetype; |
| 79 | +CREATE TABLE rewritemetoo2 OF rewritetype; |
| 80 | +SELECT pg_tde_is_encrypted('rewritemetoo1'); |
| 81 | + pg_tde_is_encrypted |
| 82 | +--------------------- |
| 83 | + t |
| 84 | +(1 row) |
| 85 | + |
| 86 | +SELECT pg_tde_is_encrypted('rewritemetoo2'); |
| 87 | + pg_tde_is_encrypted |
| 88 | +--------------------- |
| 89 | + t |
| 90 | +(1 row) |
| 91 | + |
| 92 | +ALTER TYPE rewritetype ALTER ATTRIBUTE a TYPE text cascade; |
| 93 | +SELECT pg_tde_is_encrypted('rewritemetoo1'); |
| 94 | + pg_tde_is_encrypted |
| 95 | +--------------------- |
| 96 | + t |
| 97 | +(1 row) |
| 98 | + |
| 99 | +SELECT pg_tde_is_encrypted('rewritemetoo2'); |
| 100 | + pg_tde_is_encrypted |
| 101 | +--------------------- |
| 102 | + t |
| 103 | +(1 row) |
| 104 | + |
| 105 | +CREATE TABLE encrypted_table ( |
| 106 | + id SERIAL, |
| 107 | + data TEXT, |
| 108 | + created_at DATE NOT NULL, |
| 109 | + PRIMARY KEY (id, created_at) |
| 110 | +) USING tde_heap; |
| 111 | +CREATE INDEX idx_date ON encrypted_table (created_at); |
| 112 | +SELECT pg_tde_is_encrypted('encrypted_table'); |
| 113 | + pg_tde_is_encrypted |
| 114 | +--------------------- |
| 115 | + t |
| 116 | +(1 row) |
| 117 | + |
| 118 | +CLUSTER encrypted_table USING idx_date; |
| 119 | +SELECT pg_tde_is_encrypted('encrypted_table'); |
| 120 | + pg_tde_is_encrypted |
| 121 | +--------------------- |
| 122 | + t |
| 123 | +(1 row) |
| 124 | + |
| 125 | +DROP EXTENSION pg_tde CASCADE; |
| 126 | +NOTICE: drop cascades to 7 other objects |
| 127 | +DETAIL: drop cascades to table t1 |
| 128 | +drop cascades to table test_tab1 |
| 129 | +drop cascades to table mvtest_t |
| 130 | +drop cascades to materialized view mvtest_tm |
| 131 | +drop cascades to table rewritemetoo1 |
| 132 | +drop cascades to table rewritemetoo2 |
| 133 | +drop cascades to table encrypted_table |
| 134 | +RESET default_table_access_method; |
0 commit comments