Skip to content

Provisioning PostgreSQL#

This tutorial creates an Ametnes-managed PostgreSQL database: a private, TLS-only data service you reach over an Ametnes network access endpoint.

Prerequisites#

  1. A service location (see Service Location).

Networking is automatic by default

Creating a network access resource is optional. If you do not create one, Ametnes manages network access for the location — a shared load balancer publishes the endpoints for the services deployed there, scoped to the location or project — and your service attaches to it automatically. Create your own only if you want to control exposure (see Network Access Resources).

Create the PostgreSQL service#

Select a kind (service/postgres:<version>), a tier, storage and node count. PostgreSQL offers 14.0, 15.9, 16.0 and 17.6.

  1. Navigate to Services and click New Service.
  2. Name it (for example PostgresService).
  3. Kind: PostgreSQL 17.6 Service.
  4. Location: your data service location. Leave Network unset to let Ametnes manage it.
  5. Architecture: Starter for evaluation, Small+ for production.
  6. Set the Admin Password for the postgres user (see disaster recovery if you plan replication).
  7. Click Create Service and wait for status ready.
service.tf
resource "ametnes_service" "postgres" {
  name        = "PostgresService"
  project     = ametnes_project.project.id
  location    = data.ametnes_location.location.id
  kind        = "service/postgres:17.6"
  nodes       = 1
  capacity {
    storage = 10
  }
  config = {
    "architecture"   = "Starter"
    "admin.password" = "change-me"
  }
}

output "connections" { value = ametnes_service.postgres.connections }

Connect#

Use the connections returned by the service (or the console's connection panel). PostgreSQL is reached over TLS on the primary port; the host is the service's DNS name on your zone.

psql "postgresql://postgres:<password>@<host>:<port>/postgres?sslmode=require"

Notes:

  • The admin user is always postgres; the password comes from spec.secret when you do not set one.
  • sslmode=require validates the server certificate (issued by Let's Encrypt for your zone).
  • The connection endpoint and its TLS certificate are published automatically. To manage exposure yourself, attach your own network access resource (see Network Access Resources).

Next#

  • Disaster recovery — run a streaming standby and fail over to it.
  • Scaling — change tier, nodes, storage and version.