Bottom Line:
In YugabyteDB, ALTER USER postgres WITH NOLOGIN is not a harmless hardening step. In 2024.2.x, it can break internal YSQL operations. In 2025.2 and later, it can lock out all YSQL users. Use HBA rules instead, and keep the postgres role login-capable.