Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    ProGet 2026/PostgreSQL (Embedded) Group Managed Service Account Support

    Scheduled Pinned Locked Moved Support
    4 Posts 3 Posters 15 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mhelp_5176
      last edited by

      Re: Running Proget using GMSA

      Does ProGet 2026 with the embedded PostgreSQL support group managed service accounts (gMSAs) like previous versions of ProGet? If it doesn't, will that be an option soon?

      I realize that a user account and password will work, but if we aren't using a group managed service account at my company, then the account password has to be changed every 90 days. The group managed service account has automatic password rotation, so it's much more manageable for this kind of thing.

      Using NetworkService or similar account is not an option for us for security reasons.

      atrippA 1 Reply Last reply Reply Quote 0
      • atrippA Offline
        atripp inedo-engineer @mhelp_5176
        last edited by

        Hi @mhelp_5176 ,

        Provided you provided appropriate permissions, there shouldn't be an issue configuring the service to run as a gSMA.

        Thanks,
        Alana

        1 Reply Last reply Reply Quote 0
        • M Offline
          mhelp_5176
          last edited by

          Can a group managed service account be used in the PostgreSQL embedded database connection string so the password is rotated, the password rotation is handled automatically by the gMSA, and there's no visible password in the connection string?

          The answer appears to be no based on Steve's reply in this other ticket, https://forums.inedo.com/post/19611, but I wanted to provide the additional context in case it's something you may consider supporting.

          stevedennisS 1 Reply Last reply Reply Quote 0
          • stevedennisS Offline
            stevedennis inedo-engineer @mhelp_5176
            last edited by

            Hi @mhelp_5176,

            Connecting to the embedded database requires local access to the ProGet server. Once an attacker has that, then they already have full access to the database, as it's stored as files on disk... basically it's the equivalent of storing the safe key inside of the safe :)

            As such. it doesn't make sense for us to add complexity to the product to support changing a password that's already secured.

            Thanks,
            Steve

            1 Reply Last reply Reply Quote 0

            Hello! It looks like you're interested in this conversation, but you don't have an account yet.

            Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

            With your input, this post could be even better 💗

            Register Login
            • 1 / 1
            • First post
              Last post
            Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation