by default, it should be blocked with a random password or something like that (limited to unix socket connections for example) if exposed with a configured password, we have to be sure that it is ready to use (with extension loaded...)