Transparent Data Encryption

Transparent data encryption (TDE) is an optional feature supported by EDB Postgres Advanced Server and EDB Postgres Extended Server from version 15.

It encrypts any user data stored in the database system. This encryption is transparent to the user. User data includes the actual data stored in tables and other objects as well as system catalog data such as the names of objects.

Architecture diagram

How does TDE affect performance?

The performance impact of TDE is low. For details, see the Transparent Data Encryption Impacts on EDB Postgres Advanced Server 15 blog.

Overview

About TDE

Learn about TDE, how it works, what it encrypts, and why to use it.

TDE compatibility

You can deploy TDE-enabled servers on several supported database distributions and technologies.

Administering

Overview

Understand how to initialize a TDE-encrypted cluster.

Securing the data encryption key

Learn how to secure your data with an encryption key.

Using TDE initialization options

Learn which initdb options to use to enable TDE.

Working with encrypted files

How to work with files in an encrypted environment.

Upgrading

Learn how you can use pg_upgrade to upgrade or migrate TDE databases.

Tutorials

Review some examples of how to create a TDE-enabled database server.

Reference

Commands affected by TDE

How TDE changes the behavior of some commands when enabled.

initdb TDE options

Learn about the initdb options required to initialize a TDE-encrypted database.

Limitations

Learn about TDE limitations.


Could this page be better? Report a problem or suggest an addition!