تخطي إلى المحتوى الرئيسي
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.postgresql-anonymizer-5290acd9-a7ad-4ff8-ac12-a6a4b16bbc28/image2_logolarge.png

PostgreSQL Anonymizer on Ubuntu 24.04 LTS

بواسطة cloudimg

Mask personal data inside PostgreSQL: dynamic masking, static anonymization, synthetic data.

This is a repackaged open source product with additional charges for cloudimg support services.

PostgreSQL Anonymizer by cloudimg

A PostgreSQL database that knows which of its own columns hold personal data and disguises them automatically. This image delivers PostgreSQL 18.4 with the PostgreSQL Anonymizer extension at the pinned upstream release 3.1.3, already installed, preloaded and initialised, with a worked demonstration ready the moment the machine boots.

What It Does

You declare in SQL which columns hold personal data and how each should be disguised. PostgreSQL enforces those rules itself, at query time. Because the masking lives in the engine rather than in an application, it cannot be bypassed by writing a different query, and no second sanitised copy has to be created or kept in sync.

Three modes ship working, and all three are demonstrated on this image:

  • Dynamic masking. A role labelled masked sees anonymized values in real time while the table owner sees the originals, and the stored data is never altered. This is how you give analysts, contractors or support staff access to production shaped data without exposing personal data.
  • Static anonymization. One function call permanently rewrites the stored values, producing a genuinely sanitised dataset for a development or test environment.
  • Synthetic data generation. A masked email is a plausible email and a masked name a plausible name. Column types, row counts and primary keys are preserved, so joins and application code still behave.

Masking functions cover realistic substitution for names, emails and cities, stable hashing for identifiers you still need to join on, partial masking that keeps a prefix, and blanking a column entirely.

What Is Included

  • PostgreSQL 18.4 from the official PostgreSQL PGDG repository, running under systemd
  • PostgreSQL Anonymizer 3.1.3 from the Dalibo Labs repository, upstream's own supported channel, with the signing key pinned by fingerprint and the package verified against a pinned SHA256 before installation
  • The extension already created, preloaded and initialised, with its synthetic data sets loaded and verified
  • A demonstration database of realistic personal data with a full set of masking rules and a pre declared masked role, so the owner and masked views can be compared immediately
  • A second table reserved for the irreversible static demonstration
  • Fully patched base with unattended security upgrades enabled
  • 24/7 cloudimg engineers handling upgrades, tuning and configuration

Secure By Default

Every role in the shipped image has no password at all, and TLS is disabled, so the database cannot be reached from the network in the image itself. On first boot each machine mints unique passwords for the administrative and masked roles plus a unique TLS certificate, into a file only root can read. Two machines never share a secret, and this is proven by launching two and comparing. Remote clients are accepted only over TLS, and no trust rule exists anywhere in the access configuration.

A credential guard runs on every boot. It proves the recorded credential genuinely authenticates, then attempts authentication with published and example values, including those used in the documentation. If any succeeds it stops the database rather than serve a known credential. It authenticates rather than inspects, because the database stores a salted hash and never the password, so an inspection based check could never match and would pass silently forever.

Getting Started

1. Launch the image on Standard_B2s or larger 2. Read the per machine credentials from the root only credentials file 3. Run the same query as the owner and as the masked role, and compare

Licensing and Pricing

PostgreSQL Anonymizer is licensed under The PostgreSQL License and is free; there is no per-seat fee. Its synthetic data sets derive from the MIT licensed Faker library, and attribution ships inside the image. The cloudimg charge of 0.04 US dollars per vCPU hour covers packaging, security patching, image maintenance and 24/7 expert support. Restrict the database port to your application subnet before you put real data on it.

Anonymization reduces risk; it does not by itself make a dataset lawful to process or share. Static anonymization is irreversible, so take a backup first and validate the result before relying on it.

cloudimg Support

24/7 technical support by email covers deployment, upgrades, masking rule design and tuning. Critical issues receive a one-hour average response.

cloudimg is not affiliated with or endorsed by Dalibo or the PostgreSQL Anonymizer project. All product and company names are trademarks of their respective holders.

لمحة سريعة

https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.postgresql-anonymizer-5290acd9-a7ad-4ff8-ac12-a6a4b16bbc28/image7_screenshot01.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.postgresql-anonymizer-5290acd9-a7ad-4ff8-ac12-a6a4b16bbc28/image0_screenshot02.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.postgresql-anonymizer-5290acd9-a7ad-4ff8-ac12-a6a4b16bbc28/image6_screenshot03.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.postgresql-anonymizer-5290acd9-a7ad-4ff8-ac12-a6a4b16bbc28/image4_screenshot04.png
العربية (ليبيا)
أيقونة إلغاء الاشتراك في اختيارات خصوصيتك خيارات خصوصيتك
خصوصية صحة المستهلك خريطة الموقع اتصل بنا الخصوصية وملفات تعريف الارتباط شروط الاستخدام حول إعلاناتنا إدارة ملفات تعريف الارتباط