PostgreSQL audits & health check
Not sure where your PostgreSQL environment stands? A structured audit is the fastest way to find out & the right starting point before any migration, upgrade or compliance initiative.
Kangaroot delivers 6 focused audit tracks. Each results in a written findings report & a concrete recommendations roadmap. No generic scorecards; actionable output your team can work from.
-
Health check
The broadest starting point. A health check gives you a full baseline across your PostgreSQL environment:
- Configuration review (postgresql.conf, pg_hba.conf)
- Extension inventory & risk assessment
- Security posture overview
- Performance baseline
- Operational maturity assessment
- Upgrade & update recommendations roadmap
Most organisations start here; then follow up with a focused audit on the areas that need attention.
-
Security audit
A deep review of your database security posture, mapped against GDPR, NIS2 & ISO27001:
- Authentication & authorisation (SCRAM, LDAP, pg_hba.conf)
- Encryption in transit (TLS) & at rest
- Row-level security policies
- Audit logging (pgaudit, log_connections)
- Extension review & network posture
- Compliance gap analysis & action plan
-
Performance audit
A systematic review of where performance is lost & how to get it back:
- Query analysis (EXPLAIN / EXPLAIN ANALYZE)
- Index strategy (multi-column, partial, covering, GIN/GiST)
- Vacuum & autovacuum tuning, bloat detection
- Memory configuration (work_mem, shared_buffers, effective_cache_size)
- Storage & I/O analysis
- Connection pooling review (pgBouncer, pgPool)
- Workload profiling
-
HA & DR Audit
A review of your high availability & disaster recovery architecture:
- Replication setup & streaming replication health
- Failover strategy (Patroni, RepMgr, EFM)
- Backup tooling (BaRMAN, pgBackRest) & retention policies
- RTO/RPO validation against business requirements
- Disaster recovery testing readiness
- Multi-site or multi-cloud design review
-
Backup & recovery audit
Focused specifically on your backup posture & recovery readiness:
- Backup tooling review (BaRMAN, pgBackRest, pg_dump)
- Retention policies & storage performance
- Point-in-time recovery (PITR) validation
- Restore testing "Do your backups actually work?"
- Operational readiness & runbook review
-
Architecture & cloud readiness assessment
For organisations considering a move to cloud, containers or a new architecture:
- Current architecture review against target platform (OpenShift, Kubernetes, cloud VMs)
- Gap analysis & migration risk assessment
- Optimisation opportunities pre-migration
- Recommendations for cloud-native PostgreSQL deployment
Frequently Asked Questions
-
Where do I start?
A health check. It gives you a broad baseline & tells you which focused audits are worth doing next.
-
How long does an audit take?
A health check typically takes one to 2 days. Focused audits range from 2 to 5 days depending on environment complexity.
-
Do you fix what you find?
The audit delivers findings & recommendations. Kangaroot can then implement the remediations as a follow-on engagement or Kangarun takes over ongoing operations.
-
Can an audit help us prepare for NIS2 or ISO27001?
Yes. The Security Audit specifically maps your database controls against GDPR, NIS2 & ISO27001 requirements.