# PG\_TDE – Transparent Data Encryption (TDE)

**URL:** https://forums.percona.com/c/postgresql/pg-tde-transparent-data-encryption-tde/82.md

[Latest](https://forums.percona.com/latest.md) · [Categories](https://forums.percona.com/categories.md) · [Tags](https://forums.percona.com/tags.md)

---

## [About the PG\_TDE – Transparent Data Encryption (TDE) category](https://forums.percona.com/t/about-the-pg-tde-transparent-data-encryption-tde-category/27996)

<div class="topic-metadata">

**Author:** [@daniil.bazhenov](https://forums.percona.com/u/daniil.bazhenov)\
**Replies:** 0\
**Last updated:** [January 24, 2024, 2:47pm UTC](https://forums.percona.com/t/about-the-pg-tde-transparent-data-encryption-tde-category/27996 "2024-01-24T14:47:05Z")

</div>

pg\_tde is the extension that brings in Transparent Data Encryption (TDE) to PostgreSQL and enables you to keep sensitive data safe and secure. It brings built-in encryption support for PostgreSQL environments that need s…

---

## [Prevent export keys from OpenBao](https://forums.percona.com/t/prevent-export-keys-from-openbao/41313)

<div class="topic-metadata">

**Author:** [@Alexander\_H](https://forums.percona.com/u/Alexander_H)\
**Replies:** 1\
**Last updated:** [October 5, 2026, 2:07pm UTC](https://forums.percona.com/t/prevent-export-keys-from-openbao/41313 "2026-10-05T14:07:41Z")

</div>

When using PG\_TDE with OpenBao, is it possible to prevent access to the key in OpenBao ? I am trying to make a case that the artefacts stored in OpenBao are securely managed and cannot be exported and used to access a TD…

---

## [Pg\_tde\_archive\_decrypt/pg\_tde\_restore\_encrypt limitation in pgbackrest](https://forums.percona.com/t/pg-tde-archive-decrypt-pg-tde-restore-encrypt-limitation-in-pgbackrest/41250)

<div class="topic-metadata">

**Author:** [@grill](https://forums.percona.com/u/grill)\
**Replies:** 4\
**Last updated:** [September 10, 2026, 10:37am UTC](https://forums.percona.com/t/pg-tde-archive-decrypt-pg-tde-restore-encrypt-limitation-in-pgbackrest/41250 "2026-09-10T10:37:59Z")

</div>

Hey, wondering why you added the requirement to decrypt/encrypt the WAL if pgbackrest is used in the limitations documentation. I remember it wasn’t there before. We are currently using pgbackrest without encrypt/decr…

---

## [Adding KMIP Global Key Providers for Standby KMIP Keystores](https://forums.percona.com/t/adding-kmip-global-key-providers-for-standby-kmip-keystores/41020)

<div class="topic-metadata">

**Author:** [@NatashaLR](https://forums.percona.com/u/NatashaLR)\
**Replies:** 5\
**Last updated:** [July 9, 2026, 11:20am UTC](https://forums.percona.com/t/adding-kmip-global-key-providers-for-standby-kmip-keystores/41020 "2026-07-09T11:20:08Z")

</div>

Hi All. Two questions regarding Percona Postgresql V18 pg\_tde:- Can you add more X1 KMIP key provider IP for KMIP redundancy/ standby server tests ? Primary KMIP Keystore IP SELECT pg\_tde\_add\_global\_key\_provider\_kmi…

---

## [Three questions about Percona Postgresql](https://forums.percona.com/t/three-questions-about-percona-postgresql/37766)

<div class="topic-metadata">

**Author:** [@kevin310007](https://forums.percona.com/u/kevin310007)\
**Replies:** 7\
**Last updated:** [June 22, 2026, 5:32pm UTC](https://forums.percona.com/t/three-questions-about-percona-postgresql/37766 "2026-06-22T17:32:45Z")

</div>

Q1: I already install Community PG16.8 at Oracle linux 9.5 and with some tables. I want to use tde\_heap function to encrypt my tables. here are my setup below: Install Percona Postgresql 17.4.1 Use pg\_dump to export my…

---

## [How to properly upgrade pg\_tde from 2.1.1 to 2.1.2 on Patroni cluster with pgbackrest and WAL encryption?](https://forums.percona.com/t/how-to-properly-upgrade-pg-tde-from-2-1-1-to-2-1-2-on-patroni-cluster-with-pgbackrest-and-wal-encryption/40484)

<div class="topic-metadata">

**Author:** [@Sourcream\_suicide](https://forums.percona.com/u/Sourcream_suicide)\
**Replies:** 1\
**Last updated:** [May 7, 2026, 5:04pm UTC](https://forums.percona.com/t/how-to-properly-upgrade-pg-tde-from-2-1-1-to-2-1-2-on-patroni-cluster-with-pgbackrest-and-wal-encryption/40484 "2026-05-07T17:04:30Z")

</div>

Environment: - PostgreSQL 18 - pg\_tde 2.1.1 - Patroni HA cluster (2 nodes) - pgbackrest for backups (repository on nodeA, backups from leader) - WAL encryption enabled (pg\_tde.wal\_encrypt = on) - File-based key pro…

---

## [Loading keys over wire and evicting keys from cache in pg\_tde](https://forums.percona.com/t/loading-keys-over-wire-and-evicting-keys-from-cache-in-pg-tde/40633)

<div class="topic-metadata">

**Author:** [@WOXX](https://forums.percona.com/u/WOXX)\
**Replies:** 0\
**Last updated:** [April 15, 2026, 4:18am UTC](https://forums.percona.com/t/loading-keys-over-wire-and-evicting-keys-from-cache-in-pg-tde/40633 "2026-04-15T04:18:31Z")

</div>

Hi in pg\_tde, is it possible to set up eviction so keys are evicted from memory after a certain amount of time (or maybe inactivity or no connections) and required to be reloaded to use that db again? Or even not cache k…

---

## [How to verify whether the 256 bit AES encryption option applied? and not using the default 128](https://forums.percona.com/t/how-to-verify-whether-the-256-bit-aes-encryption-option-applied-and-not-using-the-default-128/40410)

<div class="topic-metadata">

**Author:** [@roko](https://forums.percona.com/u/roko)\
**Replies:** 1\
**Last updated:** [March 27, 2026, 4:49am UTC](https://forums.percona.com/t/how-to-verify-whether-the-256-bit-aes-encryption-option-applied-and-not-using-the-default-128/40410 "2026-03-27T04:49:48Z")

</div>

Hi, Using Percona server 18 with TDE Reading the source code 256bit option the default is aes\_128 I added the 256 option to postgresql.conf pg\_tde.cipher = ‘aes\_256’ I would like to know how to verify the encryp…

---

## [Request for guidance: pg\_tde WAL encryption behavior with pgBackRest PITR](https://forums.percona.com/t/request-for-guidance-pg-tde-wal-encryption-behavior-with-pgbackrest-pitr/40115)

<div class="topic-metadata">

**Author:** [@asad121](https://forums.percona.com/u/asad121)\
**Replies:** 4\
**Last updated:** [February 24, 2026, 6:46am UTC](https://forums.percona.com/t/request-for-guidance-pg-tde-wal-encryption-behavior-with-pgbackrest-pitr/40115 "2026-02-24T06:46:52Z")

</div>

Hello team :waving\_hand: We are currently testing pg\_tde with pgBackRest on Percona Distribution for PostgreSQL 18, and we would really appreciate your guidance to better understand the expected and supported behavior a…

---

## [Failed to parse mountpoint with missing type field error](https://forums.percona.com/t/failed-to-parse-mountpoint-with-missing-type-field-error/39939)

<div class="topic-metadata">

**Author:** [@Butterfly](https://forums.percona.com/u/Butterfly)\
**Replies:** 1\
**Last updated:** [December 30, 2025, 2:09pm UTC](https://forums.percona.com/t/failed-to-parse-mountpoint-with-missing-type-field-error/39939 "2025-12-30T14:09:15Z")

</div>

I’m running into errors when trying to create Vault keys and I’m running out of ideas on why this is happening. Does anyone have advice on ways to extract more detailed logs to debug this issue? My Vault policy configur…

---

## [TDE in PostgreSQL in Windows](https://forums.percona.com/t/tde-in-postgresql-in-windows/39683)

<div class="topic-metadata">

**Author:** [@andre\_hass](https://forums.percona.com/u/andre_hass)\
**Replies:** 2\
**Last updated:** [November 5, 2025, 11:50pm UTC](https://forums.percona.com/t/tde-in-postgresql-in-windows/39683 "2025-11-05T23:50:43Z")

</div>

Hello Ist it possible to use pg\_tde on Windows host for existing prod environment? Br andre

---

## [PG\_TDE in a everest deployment](https://forums.percona.com/t/pg-tde-in-a-everest-deployment/39485)

<div class="topic-metadata">

**Author:** [@masterix](https://forums.percona.com/u/masterix)\
**Replies:** 6\
**Last updated:** [October 7, 2025, 7:42am UTC](https://forums.percona.com/t/pg-tde-in-a-everest-deployment/39485 "2025-10-07T07:42:48Z")

</div>

Hello, As it is explained in https://www.percona.com/blog/encrypt-postgresql-data-at-rest-on-kubernetes/ it is possible to configure pg\_tde using the kubernetes operator. Does anyone know if it is also possible to confi…

---

## [How to specify vault namespace when create key provider?](https://forums.percona.com/t/how-to-specify-vault-namespace-when-create-key-provider/39333)

<div class="topic-metadata">

**Author:** [@Stanley\_Tam](https://forums.percona.com/u/Stanley_Tam)\
**Replies:** 2\
**Last updated:** [September 16, 2025, 3:19pm UTC](https://forums.percona.com/t/how-to-specify-vault-namespace-when-create-key-provider/39333 "2025-09-16T15:19:22Z")

</div>

We are using hvault with a dedicated namespace. How can we specify the namespace when creating TDE key provider and key?

---

## [ How to Rotate Internal Encryption Keys in pg\_tde?](https://forums.percona.com/t/how-to-rotate-internal-encryption-keys-in-pg-tde/39261)

<div class="topic-metadata">

**Author:** [@liebao](https://forums.percona.com/u/liebao)\
**Replies:** 1\
**Last updated:** [September 3, 2025, 6:52am UTC](https://forums.percona.com/t/how-to-rotate-internal-encryption-keys-in-pg-tde/39261 "2025-09-03T06:52:56Z")

</div>

Hi all, If the master key (or “principal key”) is compromised, an attacker could potentially derive the unencrypted internal keys from it. Currently, rotating the master key does not change the internal keys—it only re…

---

## [Pg\_tde – We invite you to contribute to developing a new extension for PostgreSQL](https://forums.percona.com/t/pg-tde-we-invite-you-to-contribute-to-developing-a-new-extension-for-postgresql/28014)

<div class="topic-metadata">

**Author:** [@daniil.bazhenov](https://forums.percona.com/u/daniil.bazhenov)\
**Replies:** 2\
**Last updated:** [September 2, 2025, 7:32am UTC](https://forums.percona.com/t/pg-tde-we-invite-you-to-contribute-to-developing-a-new-extension-for-postgresql/28014 "2025-09-02T07:32:27Z")

</div>

Hi, We invite you to contribute to developing a new extension for PostgreSQL. The Percona team has developed an MVP (Minimum viable product) extension for Transparent Data Encryption (TDE) We will be grateful if you t…

---

## [Pg\_tde in production](https://forums.percona.com/t/pg-tde-in-production/38481)

<div class="topic-metadata">

**Author:** [@did16](https://forums.percona.com/u/did16)\
**Replies:** 12\
**Last updated:** [September 1, 2025, 3:28pm UTC](https://forums.percona.com/t/pg-tde-in-production/38481 "2025-09-01T15:28:48Z")

</div>

Hi My company, EDF, is very interested in Percona’s pg\_tde. Is there a planned date for its production release in 2025?

---

## [Key rotation management](https://forums.percona.com/t/key-rotation-management/39211)

<div class="topic-metadata">

**Author:** [@did16](https://forums.percona.com/u/did16)\
**Replies:** 2\
**Last updated:** [September 1, 2025, 3:25pm UTC](https://forums.percona.com/t/key-rotation-management/39211 "2025-09-01T15:25:38Z")

</div>

Hi How is encryption key rotation managed? TIA Didier

---

## [Pg\_tde and local file provider](https://forums.percona.com/t/pg-tde-and-local-file-provider/39046)

<div class="topic-metadata">

**Author:** [@did16](https://forums.percona.com/u/did16)\
**Replies:** 2\
**Last updated:** [August 12, 2025, 7:38am UTC](https://forums.percona.com/t/pg-tde-and-local-file-provider/39046 "2025-08-12T07:38:12Z")

</div>

Hi After reviewing the documentation, I am unable to use pg\_tde with a “file-keyring” provider and a key stored locally in a file. Could you please provide me with all the commands required to create an encrypted table…

---

## [Encrypting an existing database using pg\_tde](https://forums.percona.com/t/encrypting-an-existing-database-using-pg-tde/39040)

<div class="topic-metadata">

**Author:** [@kashif\_javed](https://forums.percona.com/u/kashif_javed)\
**Replies:** 1\
**Last updated:** [August 9, 2025, 5:10pm UTC](https://forums.percona.com/t/encrypting-an-existing-database-using-pg-tde/39040 "2025-08-09T17:10:20Z")

</div>

I’ve gone through the documentation and understand that pg\_tde allows encryption at the table level . However, I have an existing PostgreSQL database (needs to be migrated to Percona Server for PostgreSQL) and would lik…

---

## [Pg\_tde and linux RHEL](https://forums.percona.com/t/pg-tde-and-linux-rhel/38482)

<div class="topic-metadata">

**Author:** [@did16](https://forums.percona.com/u/did16)\
**Replies:** 3\
**Last updated:** [August 4, 2025, 3:57pm UTC](https://forums.percona.com/t/pg-tde-and-linux-rhel/38482 "2025-08-04T15:57:06Z")

</div>

HI Is the pg\_tde extension available on RHEL Linux?

---

## [Pg\_tde and community editions of postgresql](https://forums.percona.com/t/pg-tde-and-community-editions-of-postgresql/38483)

<div class="topic-metadata">

**Author:** [@did16](https://forums.percona.com/u/did16)\
**Replies:** 3\
**Last updated:** [August 4, 2025, 3:50pm UTC](https://forums.percona.com/t/pg-tde-and-community-editions-of-postgresql/38483 "2025-08-04T15:50:29Z")

</div>

Hi Is the Percona pg\_tde extension usable with the community editions of PostgreSQL?

---

## [After enabling TDE and creating encrypted table still unencrypted data visible in DB file](https://forums.percona.com/t/after-enabling-tde-and-creating-encrypted-table-still-unencrypted-data-visible-in-db-file/38834)

<div class="topic-metadata">

**Author:** [@fborden](https://forums.percona.com/u/fborden)\
**Replies:** 3\
**Last updated:** [July 25, 2025, 3:51pm UTC](https://forums.percona.com/t/after-enabling-tde-and-creating-encrypted-table-still-unencrypted-data-visible-in-db-file/38834 "2025-07-25T15:51:32Z")

</div>

Hello all, I have enabled PG\_TDE and stored the key in Oracle Key Vault. Next I created a table ENC\_TEST with access method TDE\_HEAP. test=# SELECT pg\_tde\_is\_encrypted(‘enc\_test’) encrypted; encrypted t (1 row) This…

---

## [Oracle Key Vault as KMIP server for pg\_tde](https://forums.percona.com/t/oracle-key-vault-as-kmip-server-for-pg-tde/38794)

<div class="topic-metadata">

**Author:** [@fborden](https://forums.percona.com/u/fborden)\
**Replies:** 4\
**Last updated:** [July 25, 2025, 3:42pm UTC](https://forums.percona.com/t/oracle-key-vault-as-kmip-server-for-pg-tde/38794 "2025-07-25T15:42:23Z")

</div>

Hi all, I am in the process to setup Oracle Key Vault (KMIP 1.1 compliant) as KMS for pg\_tde The documentation at KMIP configuration - Percona Transparent Data Encryption for PostgreSQL has an error in the sequence of …

---

## [Index key encryption by default?](https://forums.percona.com/t/index-key-encryption-by-default/38636)

<div class="topic-metadata">

**Author:** [@jonesofarc](https://forums.percona.com/u/jonesofarc)\
**Replies:** 7\
**Last updated:** [July 18, 2025, 8:11am UTC](https://forums.percona.com/t/index-key-encryption-by-default/38636 "2025-07-18T08:11:35Z")

</div>

Hi there, I have successfully enabled encryption on postgres. I have in postgres.conf: pg\_tde.enforce\_encryption = on default\_table\_access\_method = ‘tde\_heap’ Everything works well. Everything is encrypted by defau…

---

## [ERROR: Listing secrets of "https://vault.local:8200" at mountpoint "pg-tde" failed](https://forums.percona.com/t/error-listing-secrets-of-https-vault-local-8200-at-mountpoint-pg-tde-failed/38695)

<div class="topic-metadata">

**Author:** [@typewriter](https://forums.percona.com/u/typewriter)\
**Replies:** 4\
**Last updated:** [July 16, 2025, 11:49am UTC](https://forums.percona.com/t/error-listing-secrets-of-https-vault-local-8200-at-mountpoint-pg-tde-failed/38695 "2025-07-16T11:49:55Z")

</div>

Greetings! I have been following the instructions listed in Configure pg\_tde and Vault Configuration to get my PostgreSQL 17 database encrypted using the Percona pg\_tde extension. However, for some reason I’m unable to …

---

## [Key Management Servers for Pg\_tde](https://forums.percona.com/t/key-management-servers-for-pg-tde/38557)

<div class="topic-metadata">

**Author:** [@John\_G](https://forums.percona.com/u/John_G)\
**Replies:** 1\
**Last updated:** [July 7, 2025, 1:41pm UTC](https://forums.percona.com/t/key-management-servers-for-pg-tde/38557 "2025-07-07T13:41:50Z")

</div>

I note there are a few limited KMS that Pg\_tde supports including KMIP interface. Any plans to support AWS KMS or Google KMS in the future? It seems that would be a low cost way to manage masterkeys for Pg\_tde

---

## [Is it possible to automate the steps to enable pg\_tde for all new databases?](https://forums.percona.com/t/is-it-possible-to-automate-the-steps-to-enable-pg-tde-for-all-new-databases/38236)

<div class="topic-metadata">

**Author:** [@Robinyo](https://forums.percona.com/u/Robinyo)\
**Replies:** 1\
**Last updated:** [June 9, 2025, 1:48pm UTC](https://forums.percona.com/t/is-it-possible-to-automate-the-steps-to-enable-pg-tde-for-all-new-databases/38236 "2025-06-09T13:48:37Z")

</div>

Something like: BEGIN; \\c template1 CREATE EXTENSION pg\_tde; SELECT pg\_tde\_add\_database\_key\_provider\_file('file-vault', '/tmp/pg\_tde\_test\_001\_basic.per'); SELECT pg\_tde\_set\_key\_using\_database\_key\_provider('test-db-ke…

---

## [Enable encryption](https://forums.percona.com/t/enable-encryption/38179)

<div class="topic-metadata">

**Author:** [@Robinyo](https://forums.percona.com/u/Robinyo)\
**Replies:** 4\
**Last updated:** [June 3, 2025, 9:04pm UTC](https://forums.percona.com/t/enable-encryption/38179 "2025-06-03T21:04:04Z")

</div>

I am following the steps in the latest docs to use the pg\_tde extension to provide data encryption. See: Run in Docker - Percona Distribution for PostgreSQL I am using the Docker Image and I have created a Docker Compo…

---

## [Question about pg\_tde use HashiCorp Vault to achieve rotate key](https://forums.percona.com/t/question-about-pg-tde-use-hashicorp-vault-to-achieve-rotate-key/37827)

<div class="topic-metadata">

**Author:** [@kevin310007](https://forums.percona.com/u/kevin310007)\
**Replies:** 2\
**Last updated:** [May 8, 2025, 4:00pm UTC](https://forums.percona.com/t/question-about-pg-tde-use-hashicorp-vault-to-achieve-rotate-key/37827 "2025-05-08T16:00:20Z")

</div>

Hi, I’m trying to use pg\_tde and HashiCorp Vault to achieve rotate key. Here are my steps below: I start the HashiCorp Vault: Set the environment variable Check the vault service is running ok. Stor…

---

## [Error using KMIP key provider](https://forums.percona.com/t/error-using-kmip-key-provider/37336)

<div class="topic-metadata">

**Author:** [@fborden](https://forums.percona.com/u/fborden)\
**Replies:** 1\
**Last updated:** [March 25, 2025, 5:54pm UTC](https://forums.percona.com/t/error-using-kmip-key-provider/37336 "2025-03-25T17:54:23Z")

</div>

Hello all, I am trying to setup PG\_TDE with KMIP. For this I ran this query: SELECT pg\_tde\_add\_key\_provider\_kmip(‘kmip’, ‘10.0.0.59’, 5696, ‘/home/postgres/okvssl/CA.pem’, ‘/home/postgres/okvssl/priv.pem’); This retur…

[Next page](https://forums.percona.com/c/postgresql/pg-tde-transparent-data-encryption-tde/82.md?page=1)
