# Pg\_tde extension in kubernetes with postgres operator

**URL:** <https://forums.percona.com/t/pg-tde-extension-in-kubernetes-with-postgres-operator/36358>\
**Category:** Percona Operator for PostgreSQL\
**Created:** [January 27, 2025, 10:25am UTC](https://forums.percona.com/t/pg-tde-extension-in-kubernetes-with-postgres-operator/36358 "2025-01-27T10:25:48Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Slavisa\_Milojkovic](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/slavisa_milojkovic/32/7097_2.png) [@Slavisa\_Milojkovic](https://forums.percona.com/u/Slavisa_Milojkovic)\
**Post date:** [January 27, 2025, 10:25am UTC](https://forums.percona.com/t/pg-tde-extension-in-kubernetes-with-postgres-operator/36358/1 "2025-01-27T10:25:48Z")

</div>

Hello, I was wondering if the pg\_tde encryption extension is available in container images for the cluster version. If so, is the installation/config documentation the same as the Linux setup?

And one more question, if I manage to use it in Kubernetes, are database dumps of encrypted tables and data importable to clusters without pg\_tde configured?

What I mean is will I be able to restore the data from the db dump if I lose the vault token/enc key?

I’ll try all of this now on my test cluster, but if you have this info I need please share.

---

<div class="post-metadata">

**Author:** ![Slavisa\_Milojkovic](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/slavisa_milojkovic/32/7097_2.png) [@Slavisa\_Milojkovic](https://forums.percona.com/u/Slavisa_Milojkovic)\
**Post date:** [January 27, 2025, 1:26pm UTC](https://forums.percona.com/t/pg-tde-extension-in-kubernetes-with-postgres-operator/36358/2 "2025-01-27T13:26:43Z")

</div>

Following extension install docs, I did the following on the fresh pg cluster:

1. Add `pg_tde` to `shared_preload_libraries`.

```sql
ALTER SYSTEM SET shared_preload_libraries = 'pg_tde';

```

1. Start or restart the `postgresql` instance to enable `pg_tde`.

I paused and unpaused the cluster (not sure how to restart it other way…), and now I have this error:

```auto
2025-01-27 13:26:09,627 INFO: Lock owner: ; I am pg-cluster-pg-db-instance1-5zff-0

2025-01-27 13:26:09,628 INFO: starting as a secondary

2025-01-27 13:26:10.433 UTC [2215] FATAL: could not access file "pg_tde": No such file or directory

2025-01-27 13:26:10.433 UTC [2215] LOG: database system is shut down

2025-01-27 13:26:10,483 INFO: postmaster pid=2215

```

Does this mean there is no tde support in kubernetes version? Image for pg pod is:

percona/percona-postgresql-operator:2.5.0-ppg16.4-postgres

---

<div class="post-metadata">

**Author:** ![Robert\_Bernier](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/robert_bernier/32/1367_2.png) [@Robert\_Bernier](https://forums.percona.com/u/Robert_Bernier)\
**Post date:** [January 30, 2025, 3:16pm UTC](https://forums.percona.com/t/pg-tde-extension-in-kubernetes-with-postgres-operator/36358/3 "2025-01-30T15:16:11Z")

</div>

Hi,

> … tde support in kubernetes version?

I’ve passed on the question to get you an “official” answer from the pg\_tde development team. All I can tell you right now is that it is going to happen soon.

Hope this helps

---

<div class="post-metadata">

**Author:** ![Robert\_Bernier](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/robert_bernier/32/1367_2.png) [@Robert\_Bernier](https://forums.percona.com/u/Robert_Bernier)\
**Post date:** [January 30, 2025, 3:19pm UTC](https://forums.percona.com/t/pg-tde-extension-in-kubernetes-with-postgres-operator/36358/4 "2025-01-30T15:19:12Z")

</div>

Follow up,

_ **It is there already, and will come with the v2.6.0 release** _

Hope this helps

---

<div class="post-metadata">

**Author:** ![Slavisa\_Milojkovic](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/slavisa_milojkovic/32/7097_2.png) [@Slavisa\_Milojkovic](https://forums.percona.com/u/Slavisa_Milojkovic)\
**Post date:** [January 31, 2025, 2:42pm UTC](https://forums.percona.com/t/pg-tde-extension-in-kubernetes-with-postgres-operator/36358/5 "2025-01-31T14:42:53Z")

</div>

@Robert_Bernier thank you very much! I’ll report my tests here when it becomes available, for others who are interested in encryption with Postgres operator

---

<div class="post-metadata">

**Author:** ![Slava\_Sarzhan](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/slava_sarzhan/32/3196_2.png) [@Slava\_Sarzhan](https://forums.percona.com/u/Slava_Sarzhan)\
**Post date:** [March 19, 2025, 9:09pm UTC](https://forums.percona.com/t/pg-tde-extension-in-kubernetes-with-postgres-operator/36358/6 "2025-03-19T21:09:26Z")

</div>

hi @Slavisa_Milojkovic PGO 2.6.0 was released one day ago.

---

<div class="post-metadata">

**Author:** ![Slavisa\_Milojkovic](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/slavisa_milojkovic/32/7097_2.png) [@Slavisa\_Milojkovic](https://forums.percona.com/u/Slavisa_Milojkovic)\
**Post date:** [March 21, 2025, 12:46pm UTC](https://forums.percona.com/t/pg-tde-extension-in-kubernetes-with-postgres-operator/36358/7 "2025-03-21T12:46:02Z")

</div>

Thank you, I’ll try it as soon as I can
