Answer to the Core Questions
1. Does SQLAlchemy plan a unified SSL‑verification flag?
No official roadmap indicates a cross‑driver, single‑flag solution. SQLAlchemy’s design delegates all SSL handling to the underlying DBAPI; the library itself performs no hostname checks.
2. How to guarantee hostname verification across PostgreSQL and MySQL?
- For PostgreSQL (psycopg2): use
sslmode=verify-full (or verify-ca) in the connection URL or connect_args={'sslmode': 'verify-full'}.
- For MySQL (PyMySQL or mysqlclient): set
ssl_verify_cert=True and ssl_verify_identity=True via connect_args.
- When drivers lack built‑in support (e.g., MySQLdb), employ a TLS proxy (stunnel, HAProxy) or supply a custom
SSLContext that enforces hostname checks.
Because the options have different names and semantics, you cannot avoid rewriting connect_args when switching drivers. The only way to keep a single connection string is to wrap the driver‑specific arguments in a small helper that maps a generic key (e.g., verify_hostname=True) to the appropriate driver flag.
3. Documentation gaps
- The
connect_args section of the SQLAlchemy docs states that arguments are passed verbatim to the DBAPI, but it does not detail how SSL parameters are interpreted by each driver.
- There is no mention that hostname verification is optional and driver‑dependent; developers often assume that a generic
sslmode will work universally.
- Examples in the docs use driver‑specific SSL options without highlighting the need for separate configuration per backend.
Practical Steps for Your Project
- Identify the DBAPI you use for each backend (psycopg2 for PostgreSQL, PyMySQL or mysqlclient for MySQL).
- Define a small mapping function in your code:
def build_connect_args(driver, verify=True):
if driver == 'psycopg2':
return {'sslmode': 'verify-full'} if verify else {}
if driver in ('pymysql', 'mysqlclient'):
return {'ssl_verify_cert': True, 'ssl_verify_identity': True} if verify else {}
raise ValueError('Unsupported driver')
- Pass the result to
create_engine:
engine = create_engine(url, connect_args=build_connect_args(driver))
- Verify at runtime: enable
echo=True to see the full URL with SSL parameters, and attempt a connection to a server with a mismatched hostname; the driver should raise an error if verification is active.
What to Ask Next
Could you confirm which DBAPI versions you are using for PostgreSQL and MySQL? Knowing the exact driver and its OpenSSL support level will help refine the verification strategy and avoid silent failures.