Postgres and Open Source Experts

Anytime. Anywhere. Since 1997.

Blog

Two features just left PostgreSQL 19.

Both reverts landed after Robert Haas asked the pgsql-hackers list on August 25 whether any of six heavily patched features should come out before 19 ships. One of the two was on his list. One was not.

PgColumnar 1.0Alpha2 released

Release date: 2026-08-18

Previous release: 1.0-alpha (2026-08-04)

pgColumnar is a columnar table access method for PostgreSQL. This is the second alpha. It adds read-only Apache Iceberg support, reads and writes over S3-compatible object storage, a maintenance daemon, and a broad round of statistics, planner, performance, and security work. The on-disk native format (PGCN v1) is unchanged; existing tables are read and written as before.

This release requires one …

Parquet and Iceberg: An Overview

A pile of containers is not a shipment. A shipment is containers plus a manifest.

Apache Iceberg is the manifest. It is not a file format, it is a table format: a metadata layer that records exactly which Parquet files make up a table at every point in time. That one idea buys you things we used to think required a warehouse. Transactions on object storage, so writers never corrupt …

What If Your Team’s Biggest Burnout Driver Lives in Your Database?

What If Your Team’s Biggest Burnout Driver Lives in Your Database?

Engineering leaders work hard to protect their teams from burnout — improving processes, hiring strong talent, and adjusting on-call rotations. But if your team still looks exhausted, the real issue may not be the rotation at all. It’s often the underlying database and infrastructure quietly triggering the same incidents over and over.

Why You Should Review Your Authentication Strategy

Why You Should Review Your Authentication Strategy

Released in July 2025, NIST SP 800-63 Revision 4 introduced new requirements for authentication strength, identity proofing, and federation security. Many organizations still haven't assessed their systems against these updated standards. Learn what changed, why it matters for compliance, and how to evaluate your current identity controls against the new framework.

Why Growing Teams Are Moving from Aurora to RDS or EC2: Cost and Control Considerations on AWS

Why Growing Teams Are Moving from Aurora to RDS or EC2: Cost and Control Considerations on AWS

Amazon Aurora PostgreSQL can be a powerful starting point for teams adopting PostgreSQL in AWS. But as usage grows, so do the needs for cost transparency, fine-grained tuning, and architectural flexibility. Here's why more teams are choosing Amazon RDS for PostgreSQL or EC2 as they scale.

Lessons from the CISA and USCG Joint Advisory: What “No Breach” Still Reveals

Lessons from the CISA and USCG Joint Advisory: What “No Breach” Still Reveals

The July 31st advisory from CISA and the U.S. Coast Guard (AA25-212A) is less about what happened and more about what could have. A proactive threat hunt at a U.S. critical infrastructure organization revealed no active compromise, but it uncovered systemic weaknesses like insecure credentials, unrestricted remote access, and insufficient monitoring. This is a textbook case of “security theater”: policies and tools on paper, without enforcement in practice. The takeaway …

Lessons From The Road: More Intention, Less Autopilot

Lessons From The Road: More Intention, Less Autopilot

How much of our time is spent on autopilot?

Most people can agree that our internal autopilot systems enable us to be efficient and effective. It allows us to do things like listen to a client while trying to find the bug they are describing in the source code. Or make dinner while holding a conversation. Or even have Spiderman-like reflexes when a child falls out of a chair across …

Service Monitoring via Hazard Analysis White Paper

Service Monitoring via Hazard Analysis White Paper

A modern approach to IT observability inspired by hazard analysis. Learn how to improve system reliability, reduce monitoring complexity, and proactively manage service risks through Critical Control Points.

Critical Security Alert: Immediate Action Required for Self-Hosted SharePoint Servers (CVE-2025-53770)

A critical, newly disclosed, and actively exploited vulnerability, CVE-2025-53770, affects all self-hosted / on-premises Microsoft SharePoint Server versions. This critical issue does not impact SharePoint Online (Microsoft 365).

The exploit enables attackers to:

  • Bypass authentication
  • Install persistent backdoors
  • Launch ransomware
  • Steal sensitive data

Immediate Steps to Take:

  • Patch all on-premises SharePoint servers immediately following Microsoft guidance
  • Disconnect unpatched servers from the Internet immediately
  • For versions older than SharePoint 2016: