How to Install PostgreSQL on Rocky Linux

On Rocky Linux, you can install PostgreSQL using the postgresql-server package from the default repository. After installation, you need to initialize the database cluster and enable the service, and for remote access, you must configure listen_addresses, pg_hba.conf, the firewall, and TLS together.

The major version of PostgreSQL and the service name provided may vary depending on the Rocky Linux version and the active repositories. Check the available packages and the version required by your application before installation.

Checking which PostgreSQL versions are available

cat /etc/rocky-release
dnf info postgresql-server
dnf module list postgresql

dnf module may not be available depending on the Rocky Linux and DNF version. If a specific major version of PostgreSQL is required, first decide whether to use the Rocky default repository’s lifecycle or the PGDG repository provided by the PostgreSQL project, and do not mix server packages from different repositories.

Installing and initializing PostgreSQL

Installing server and client

sudo dnf install postgresql-server postgresql

Verify the installed version and packages.

psql --version
rpm -q postgresql-server postgresql

Initialize the database cluster

In the Rocky default package, the following tools are generally used.

sudo postgresql-setup --initdb

Initialization is performed only once on an empty data directory. If you reinitialize on a server with existing data, a separate cluster may be created or there is a risk of data corruption, so check the data directory and backups first.

sudo postgresql-setup --help

Service start and automatic execution

sudo systemctl enable --now postgresql
systemctl status postgresql

Version-specific packages in the PGDG repository may have different service names and initialization commands, such as postgresql-16. Check the official instructions for the installed package and the result of systemctl list-unit-files 'postgresql*'.

Local access and basic security settings

Connect as the postgres operating system account

sudo -iu postgres psql

Initial local authentication may use the peer method, which links the operating system account to the database role. The PostgreSQL postgres role password and the Linux postgres account password are different.

Set passwords securely

Using \password within psql allows you to avoid leaving the password in SQL statements and shell history.

\password postgres

Do not use administrative roles in applications; create purpose-specific roles and databases instead.

CREATE ROLE appuser LOGIN;
\password appuser
CREATE DATABASE appdb OWNER appuser;

Check the actual location of the configuration file.

SHOW config_file;
SHOW hba_file;
SHOW data_directory;

Since the path may vary depending on the package and version, do not just assume the path from online documents; use the value reported by the server.

Allow remote connections securely.

Restrict receiving addresses.

It is recommended to limit listen_addresses in postgresql.conf to a specific private IP of the server.

listen_addresses = '192.0.2.20'

192.0.2.20 is an example for documentation. Replace it with the actual server address. * means all interfaces, which is convenient but may expose it to unnecessary networks. The default for PostgreSQL is local loopback access. For more details, see the official PostgreSQL connection settings documentation.

Restricting Clients and Authentication in pg_hba.conf

For example, if you want only a specific application server to connect to appdb as appuser, you can review the following records.

hostssl  appdb  appuser  192.0.2.10/32  scram-sha-256

pg_hba.conf is checked from top to bottom, and only the first matching rule is used. If you place broad allowance rules at the top, subsequent restriction rules will not apply. For detailed fields and order, refer to the official PostgreSQL pg_hba.conf documentation.

Restrict Source Addresses with Firewall

sudo firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="192.0.2.10/32" port port="5432" protocol="tcp" accept'

After testing new client connections, make the rules permanent.

sudo firewall-cmd --runtime-to-permanent

Do not expose database ports directly to the entire internet. Use private networks, VPNs, security groups, and firewalls together.

Applying and Verifying Settings

Reload authentication rules

Settings that can be reloaded, like pg_hba.conf, can be re-read as follows.

sudo -iu postgres psql -c 'SELECT pg_reload_conf();'

The rule syntax can be checked in the system view.

sudo -iu postgres psql -c 'SELECT line_number, type, database, user_name, address, auth_method, error FROM pg_hba_file_rules;'

Applying settings that require a restart

Settings that are applied at server start, like listen_addresses, require a restart.

sudo systemctl restart postgresql
sudo systemctl status postgresql

Testing listening ports and connections

ss -lntp | grep 5432
psql 'host=192.0.2.20 dbname=appdb user=appuser sslmode=verify-full'

To use verify-full, the client must have a trusted CA and a certificate matching the server name. If you only set up password authentication and skip TLS, it may not be sufficient against network threats.

Items to prepare before operation

  • Regular logical and physical backups and actual recovery tests
  • Plan for Applying Supported Minor Updates
  • Minimum privilege roles and password rotation per application
  • TLS certificate verification and use of private network or VPN
  • Monitoring disk usage, connection count, latency, checkpoints, and error logs
  • Compatibility review and preparation of separate procedures before major version upgrade

PostgreSQL major version upgrades are different from simple package updates. Plan the official upgrade path according to the version, such as pg_upgrade, logical replication, or dump and restore.

Frequently Asked Questions

Cannot find postgresql-setup command

Check the installed repository and package names. The initialization tools and service names may differ between Rocky default packages and PGDG version-specific packages.

External connections keep being refused

Check listen_addresses, the first matching rule in pg_hba.conf, the service listening port, firewalld, and cloud security groups in order.

Is it okay to allow 0.0.0.0/0 in pg_hba.conf?

It matches the entire Internet, so it is generally best to avoid it. Restrict to the fixed address of the actual application server or private subnet, and use TLS and minimal privileges.

After changing the configuration files, should I use reload or restart?

It depends on the item. pg_hba.conf can be reloaded, but listen_addresses requires a restart. Check pg_settings.pending_restart and the context in the official documentation.

Summary

On Rocky Linux, PostgreSQL is prepared in the order of package installation, cluster initialization, and service activation. For remote connections, apply specific listening addresses, narrow pg_hba.conf rules, firewall source restrictions, and TLS together.

Since configuration paths and service names can vary depending on the installation source and version, it is safe to work based on the paths reported directly by PostgreSQL and the documentation of the installed package.

More in This Category
How to Change the System Language and Locale on Rocky Linux

How to Change the System Language and Locale on Rocky Linux

Learn how to check and change the system-wide language and locale on Rocky Linux with localectl and glibc language packs. This guide also explains session-only changes, LANG and LC_* precedence, and troubleshooting for broken Korean characters.

How to Configure a Static IP Address on Rocky Linux

How to Configure a Static IP Address on Rocky Linux

Configure and verify a static IPv4 address on Rocky Linux with NetworkManager, including the gateway, DNS servers, connection profile, and safe remote-change checks.

How to List Installed Packages on Rocky Linux

How to List Installed Packages on Rocky Linux

Use DNF and RPM to list, search, count, and inspect installed packages on Rocky Linux and identify which package owns a file.

How to Install a GUI and Remote Desktop on Rocky Linux

How to Install a GUI and Remote Desktop on Rocky Linux

Install a graphical desktop on Rocky Linux, select the graphical boot target, configure remote access, and review firewall and security considerations.

How to Manage firewalld on Rocky Linux: Zones, Services, and Ports

How to Manage firewalld on Rocky Linux: Zones, Services, and Ports

Learn how to manage firewalld on Rocky Linux with firewall-cmd, including active zones, services, custom ports, runtime and permanent rules, rich rules, and NetworkManager integration. The guide emphasizes a safe workflow for remote SSH servers.

How to Change the Hostname on Rocky Linux

How to Change the Hostname on Rocky Linux

Learn how to change a Rocky Linux hostname with hostnamectl, verify the persistent setting, and check name resolution and services afterward.

How to Install PostgreSQL on Rocky Linux

How to Install PostgreSQL on Rocky Linux

Install PostgreSQL on Rocky Linux, initialize the database cluster, enable the service, create a database and user, and review network and authentication settings.

How to Configure Root SSH Login on Rocky Linux Safely

How to Configure Root SSH Login on Rocky Linux Safely

Review how root SSH login is controlled on Rocky Linux, why direct root access is risky, and how to change and verify sshd settings without losing remote access.

How to Install MariaDB on Rocky Linux

How to Install MariaDB on Rocky Linux

Install MariaDB on Rocky Linux, enable the database service, complete the initial security setup, create a database and account, and verify access.

Rocky Linux Administration Memo: Essential Commands and Configuration Notes

Rocky Linux Administration Memo: Essential Commands and Configuration Notes

A practical Rocky Linux administration reference covering packages, services, networking, storage, security controls, logs, and frequently used maintenance commands.