Skip to content

Latest commit

 

History

46 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Constructive DB

The official Docker image for the Constructive database.

constructive

Lean PostgreSQL 18 image with essential extensions for modern applications.

Extensions

Extension Version Description
pgvector 0.8.2 Vector similarity search for embeddings
PostGIS 3.6.4 (+ security patches) Spatial and geographic data
pg_textsearch 1.3.1 BM25 full-text search
pg_partman 5.4.3 Partition management
pg_stat_statements built-in Query performance statistics

Usage

# Pull the image
docker pull constructiveio/postgres-plus:latest

# Run
docker run -d \
  --name postgres \
  -e POSTGRES_PASSWORD=secret \
  -p 5432:5432 \
  constructiveio/postgres-plus:latest

Enable extensions as needed:

CREATE EXTENSION vector;
CREATE EXTENSION postgis;
CREATE EXTENSION pg_textsearch;
CREATE EXTENSION pg_partman;
CREATE EXTENSION pg_stat_statements;

Configuration

track_io_timing is enabled by default for accurate I/O metrics in pg_stat_statements. This powers the usage metering and query stats collection pipeline.

Build

make build            # Build image
make test             # Build, verify extensions, and run the PostGIS security gate
make verify-security  # Run the security gate against an already-running container
make run              # Run container
make shell            # psql into container
make clean            # Remove image

PostGIS security patches

PostGIS is built from the 3.6.4 tarball with the upstream security fixes in patches/ applied on top — no released tarball carries them yet:

Patch Fixes
0001-flatgeobuf-validate-input-buffers-before-decoding CVE-2026-73515 — out-of-bounds read decoding a FlatGeobuf buffer (ST_FromFlatGeobuf). postgis/stable-3.6 53e273fae, landed after 3.6.4.
0002-address_standardizer-harden-scanner-and-rule-parsing CVE-2026-73514 — equivalent to 423570b in the split-out postgis/address_standardizer repo.
0003-address_standardizer-clean-up-partial-2D-allocations leak/partial-allocation cleanup accompanying the above.
0004-Avoid-out-of-bounds-write-uninitialized-memory the parse_rule() off-by-one write past rule_arr[MAX_RULE_LENGTH] plus an uninitialized RULE_PARAM.

Each is a git format-patch of the upstream commit cherry-picked onto the 3.6.4 tag, so the provenance stays greppable and a patch that stops applying fails the build rather than being silently skipped.

scripts/verify-postgis-security.sh <container> is the gate that keeps a vulnerable build from reaching a tag. It asserts against the installed extension, not the Dockerfile args: release floor, the patch manifest baked into the image, that a truncated FlatGeobuf buffer is rejected with the backend still alive, and that standardize_address() still works. CI runs it on every PR and on the pushed digest before the latest/18 manifests move.

Drop the patches when a PostGIS release contains all four fixes; the gate's POSTGIS_MIN_VERSION floor and manifest check are what to update then.

Building manually

docker buildx build \
  --platform linux/amd64,linux/arm64 \
  -t constructiveio/postgres-plus:18 \
  -t constructiveio/postgres-plus:latest \
  --push .

Releases

Packages

Contributors

Languages