PostgreSQL fails to start when configured to listen on 0.0.0.0 instead of 127.0.0.1
0 reputation · 28 Feb 2025, 01:49 UTC
0 reputation · 28 Feb 2025, 01:49 UTC
When deploying the PostgreSQL service on Kali Linux, the objective is to restrict its network interface to the localhost address only, thereby preventing unintended exposure to external networks. The service’s configuration includes a setting that determines the IP addresses on which it accepts connections.
Because the default value for this setting can differ between package versions and may be overridden during manual tuning, there is uncertainty about whether the instance remains bound solely to 127.0.0.1 after adjustments. Administrators need to be certain that no external interface is inadvertently opened.
27525 reputation · 28 Feb 2025, 05:04 UTC
The configuration directive that controls the listening address for PostgreSQL is listen_addresses located within the postgresql.conf file. Setting this to '127.0.0.1' or 'localhost' restricts the service to the loopback interface, while '0.0.0.0' instructs PostgreSQL to bind to all available IPv4 interfaces.
If listen_addresses='0.0.0.0' is configured but the service fails to start, it usually results in a bind error. Common causes include:
To confirm the service is not listening on any external address, use the following methods:
sudo -u postgres psql -c "SHOW listen_addresses";
sudo tail -n 20 /var/log/postgresql/postgresql-*.log
sudo ss -tlnp | grep 5432 # OR sudo netstat -tlnp | grep 5432If the output shows
0.0.0.0:5432 or *:5432, the service is exposed to all interfaces. If it shows 127.0.0.1:5432, it is properly restricted.
sudo lsof -i :5432
sudo nano /etc/postgresql/14/main/postgresql.conf
listen_addresses directive:
listen_addresses = '127.0.0.1'
sudo systemctl restart postgresql
Are you attempting to run this within a containerized environment or a bare-metal Kali installation? Knowing this helps determine if the failure is due to network namespace limitations or standard port conflicts.
Use comments to ask for clarification. Post a solution as an answer.
27,525 reputation · 28 Feb 2025, 06:06 UTC
It is important to clarify that changing listen_addresses to '0.0.0.0' only controls the network interface binding; it does not automatically grant remote users access to the database.
Even if the service starts successfully on all interfaces, PostgreSQL will still reject remote connections unless the pg_hba.conf (Host-Based Authentication) file is explicitly updated. To allow external traffic, you must add a record specifying the allowed client IP range, the database, and the authentication method:
# Example: Allow a specific subnet to connect via md5 password
host all all 192.168.1.0/24 md5
Without this corresponding entry in pg_hba.conf, the server will listen on the port but return a "no pg_hba.conf entry" error to any remote client, maintaining a layer of security even if the binding is wide open.