Skip to content

PostgreSQL PostgreSQL

Description / nameInput element
Container Registry
Container Configuration Root Path
Timezone
User ID
Group ID
PostgreSQL Host Port
PostgreSQL /var/lib/postgresql/data Path

Build Status Last Commit OCI Pulls sysvipc Required

The World's Most Advanced Open Source Relational Database on FreeBSD.

Port 5432
Registry ghcr.io/daemonless/postgres
Daemonless daemonless/postgres
Source www.postgresql.org/
Website www.postgresql.org

Version Tags

Multi-arch manifests — resolve automatically to the right image for your platform.

Tag Description Best For
14 / 14-pkg-latest FreeBSD Latest. Rolling package updates. Staying current.
15 / 15-pkg-latest FreeBSD Latest. Rolling package updates. Staying current.
16 / 16-pkg-latest FreeBSD Latest. Rolling package updates. Staying current.
17 / 17-pkg-latest FreeBSD Latest. Rolling package updates. Staying current.
18 / 18-pkg-latest / latest / pkg / pkg-latest FreeBSD Latest. Rolling package updates. Staying current.
Tag Description Best For
14-amd64 / 14-pkg-latest-amd64 FreeBSD Latest. Rolling package updates. Staying current.
15-amd64 / 15-pkg-latest-amd64 FreeBSD Latest. Rolling package updates. Staying current.
16-amd64 / 16-pkg-latest-amd64 FreeBSD Latest. Rolling package updates. Staying current.
17-amd64 / 17-pkg-latest-amd64 FreeBSD Latest. Rolling package updates. Staying current.
18-amd64 / 18-pkg-latest-amd64 / latest-amd64 / pkg-amd64 / pkg-latest-amd64 FreeBSD Latest. Rolling package updates. Staying current.
Tag Description Best For
14-aarch64 / 14-pkg-latest-aarch64 FreeBSD Latest. Rolling package updates. Staying current.
15-aarch64 / 15-pkg-latest-aarch64 FreeBSD Latest. Rolling package updates. Staying current.
16-aarch64 / 16-pkg-latest-aarch64 FreeBSD Latest. Rolling package updates. Staying current.
17-aarch64 / 17-pkg-latest-aarch64 FreeBSD Latest. Rolling package updates. Staying current.
18-aarch64 / 18-pkg-latest-aarch64 / latest-aarch64 / pkg-aarch64 / pkg-latest-aarch64 FreeBSD Latest. Rolling package updates. Staying current.

Before deploying, ensure your host environment is ready. See the Quick Start Guide for host setup instructions, including the security model for host vs. container privileges.

Deployment

services:
  postgres:
    image: "ghcr.io/daemonless/postgres:latest"
    container_name: postgres
    environment:
      - POSTGRES_USER=postgres  # Database superuser name (default: postgres)
      - POSTGRES_PASSWORD=postgres  # Database superuser password
      - POSTGRES_DB=postgres  # Default database to create (default: same as user)
      - PUID=1000
      - PGID=1000
      - TZ=UTC
      - POSTGRES_INITDB_ARGS=  # Additional arguments for initdb
      - POSTGRES_HOST_AUTH_METHOD=  # Authentication method (default: scram-sha-256)
    volumes:
      - "/containers/postgres:/var/lib/postgresql/data"
    ports:
      - "5432:5432"
    annotations:
      org.freebsd.jail.allow.sysvipc: "true"
    # always (not unless-stopped) so FreeBSD's podman rc.d auto-starts it at boot
    restart: always

Save as compose.yaml, then run podman-compose up -d.

Warning

Exposing ports in AppJail means that your service can be reached from remote hosts. If that is not your intention, do not expose the ports and communicate with the service using the jail's IPv4 address or hostname assigned by the virtual network.

# .env

DIRECTOR_PROJECT=postgres
POSTGRES_USER=postgres
POSTGRES_PASSWORD=postgres
POSTGRES_DB=postgres
PUID=1000
PGID=1000
TZ=UTC
POSTGRES_INITDB_ARGS=
POSTGRES_HOST_AUTH_METHOD=
# appjail-director.yml

options:
  - virtualnet: ':<random> default'
  - nat:
services:
  postgres:
    name: postgres
    options:
      - container: 'args:--pull'
      - expose: '5432:5432 proto:tcp'
      - template: !ENV '${PWD}/template.conf'
    oci:
      user: root
      environment:
        - POSTGRES_USER: !ENV '${POSTGRES_USER}'
        - POSTGRES_PASSWORD: !ENV '${POSTGRES_PASSWORD}'
        - POSTGRES_DB: !ENV '${POSTGRES_DB}'
        - PUID: !ENV '${PUID}'
        - PGID: !ENV '${PGID}'
        - TZ: !ENV '${TZ}'
        - POSTGRES_INITDB_ARGS: !ENV '${POSTGRES_INITDB_ARGS}'
        - POSTGRES_HOST_AUTH_METHOD: !ENV '${POSTGRES_HOST_AUTH_METHOD}'
    volumes:
      - POSTGRES_DATA_PATH: /var/lib/postgresql/data
volumes:
  POSTGRES_DATA_PATH:
    device: '/containers/postgres'
1
2
3
4
5
6
7
# Makejail

ARG tag=latest

OPTION container=boot
OPTION overwrite=force
OPTION from=ghcr.io/daemonless/postgres:${tag}
1
2
3
4
5
6
7
# template.conf

exec.start: "/bin/sh /etc/rc"
exec.stop: "/bin/sh /etc/rc.shutdown jail"
mount.devfs
persist
allow.sysvipc

Save the files above, then run appjail-director up.

Experimental

Bastille's OCI support is experimental. It requires buildah and shares the host network stack (inherit). Mount volumes with --volume HOST JAIL; without it, image-declared volumes are stored under ${bastille_volumesdir}/${jail}.

services:
  postgres:
    name: postgres
    image: "ghcr.io/daemonless/postgres:latest"
    network:
      - mode: host
    environment:
      - POSTGRES_USER=postgres
      - POSTGRES_PASSWORD=postgres
      - POSTGRES_DB=postgres
      - PUID=1000
      - PGID=1000
      - TZ=UTC
      - POSTGRES_INITDB_ARGS=
      - POSTGRES_HOST_AUTH_METHOD=
    volumes:
      - "/containers/postgres:/var/lib/postgresql/data"

Save as bastille-compose.yml, then run bastille up.

Interactive Configuration

Parameters

Environment Variables

Variable Default Description
POSTGRES_USER postgres Database superuser name (default: postgres)
POSTGRES_PASSWORD postgres Database superuser password
POSTGRES_DB postgres Default database to create (default: same as user)
PUID 1000
PGID 1000
TZ UTC
POSTGRES_INITDB_ARGS `` Additional arguments for initdb
POSTGRES_HOST_AUTH_METHOD `` Authentication method (default: scram-sha-256)

Volumes

Path Description
/var/lib/postgresql/data Database data directory

Ports

Port Protocol Description
5432 TCP PostgreSQL port

Implementation Details

  • Architectures: amd64, aarch64
  • User: bsd (UID/GID set via PUID/PGID). Defaults to 1000:1000.
  • Base: Built on ghcr.io/daemonless/base (FreeBSD 15.1).
  • sysvipc: Requires --annotation 'org.freebsd.jail.allow.sysvipc=true' (ocijail 0.5.0+)

Need help? Join our Discord community.