Index: iknow-api/Program.cs
===================================================================
--- iknow-api/Program.cs	(revision 1b20b226a74790f84dc06dc488f4f761b510a3f2)
+++ iknow-api/Program.cs	(revision 002cf5f9fe36565e030e882d63222c760d638995)
@@ -66,5 +66,9 @@
 // Postgres type by name; PgEnumLabels covers the members whose label is not
 // simply the lowercased member name.
-builder.Services.AddDbContext<AppDbContext>(options =>
+// AddDbContextPool reuses the DbContext instances themselves; the connections
+// underneath them are pooled separately by Npgsql, sized in the connection
+// string. Both matter here because every physical connection is one more
+// channel through the SSH tunnel.
+builder.Services.AddDbContextPool<AppDbContext>(options =>
     options.UseNpgsql(
         builder.Configuration.GetConnectionString("DefaultConnection"),
Index: iknow-api/Services/Implementations/EnrollmentService.cs
===================================================================
--- iknow-api/Services/Implementations/EnrollmentService.cs	(revision 1b20b226a74790f84dc06dc488f4f761b510a3f2)
+++ iknow-api/Services/Implementations/EnrollmentService.cs	(revision 002cf5f9fe36565e030e882d63222c760d638995)
@@ -3,4 +3,5 @@
 using iknow_api.Models;
 using Microsoft.EntityFrameworkCore;
+using Npgsql;
 
 namespace iknow_api.Services
@@ -220,4 +221,14 @@
                 };
             }
+            catch (DbUpdateException ex) when (IsUniqueViolation(ex))
+            {
+                // Two enrolments for the same semester sent at the same time both
+                // pass the check above, because each transaction reads the state
+                // from before the other one wrote. UNIQUE (user_id, semester_id)
+                // is what actually settles it, so the loser gets the same
+                // sentence as if the check had caught it.
+                await transaction.RollbackAsync();
+                return Fail("You are already enrolled in that semester.");
+            }
             catch
             {
@@ -226,4 +237,8 @@
             }
         }
+
+        /// <summary>23505 is unique_violation.</summary>
+        private static bool IsUniqueViolation(DbUpdateException ex) =>
+            ex.InnerException is PostgresException { SqlState: "23505" };
 
         private static EnrollSemesterResultDto Fail(string message) =>
Index: iknow-api/appsettings.Development.json.example
===================================================================
--- iknow-api/appsettings.Development.json.example	(revision 1b20b226a74790f84dc06dc488f4f761b510a3f2)
+++ iknow-api/appsettings.Development.json.example	(revision 002cf5f9fe36565e030e882d63222c760d638995)
@@ -7,5 +7,5 @@
   },
   "ConnectionStrings": {
-    "DefaultConnection": "Host=localhost;Port=9999;Database=db_202526z_va_prj_know2026;Username=db_202526z_va_prj_iknow2026_owner;Password=YOUR_DB_PASSWORD_HERE;Search Path=project;Include Error Detail=true"
+    "DefaultConnection": "Host=localhost;Port=9999;Database=db_202526z_va_prj_know2026;Username=db_202526z_va_prj_iknow2026_owner;Password=YOUR_DB_PASSWORD_HERE;Search Path=project;Include Error Detail=true;Maximum Pool Size=10;Minimum Pool Size=1;Connection Idle Lifetime=300;Timeout=15"
   },
   "Jwt": {
