---
title: "Configure network access to PostgreSQL PGVector cluster"
sidebar_label: "Configure network access to cluster"
description: "How to specify a list of allowed IP addresses, basic information about security groups in a PostgreSQL PGVector database cluster, and how to assign a security group"
sidebar_position: 18
---

import Formbricks from '@theme/MDXComponents/Formbricks'
import PlusIcon from '@selectel/docux/icons/plus'
import ShieldOkIcon from '@selectel/docux/icons/shield-ok'
import CheckIcon from '@selectel/docux/icons/check'

# Configure network access to PostgreSQL PGVector cluster

By default, in clusters with a public subnet, connections are allowed from all IP addresses if a login and password are provided.

Connections to a cluster in a private subnet are allowed from the cluster subnet and from subnets connected to the cluster subnet via a cloud router.

You can [specify a list of allowed IP addresses](#define-allowed-ip-addresses-list) from which access to the Managed Databases cluster will be allowed.

To restrict access to a Managed Databases cluster, you can also use [security groups](#security-groups-in-managed-databases).

Any changes to network access settings are the customer's responsibility.

## Specify a list of allowed IP addresses \{#define-allowed-ip-addresses-list}

When restoring a cluster from a backup, the list of allowed IP addresses is not preserved — you will need to specify allowed IP addresses again for the new cluster.

1. In the [Control panel](https://my.selectel.ru/vpc/default/dbaas/), in the top menu, click **Products** and select **Managed Databases**.
2. Open the tab **Active**.
3. Open the database cluster page → tab **Settings**.
4. In the **Network access management** section, click the field **Allowed addresses and subnet CIDRs**.
5. At the bottom of the drop-down list, enter the subnet CIDR or IP address from which access to the cluster should be allowed. Only IPv4 addressing is supported.
6. Click <PlusIcon />.
7. Repeat steps 5 and 6 for all allowed IP addresses.
8. Click **Save**. Connections from all IP addresses except those specified in the allowed list will be blocked.

## Security groups in a Managed Databases cluster \{#security-groups-in-managed-databases}

A security group in a Managed Databases cluster is a set of rules for filtering incoming and outgoing cluster traffic. For security groups to work, the network must have enabled [traffic filtering (port security](/cloud-servers/cloud-networks/about-networks.mdx#traffic-filtering-port-security)).

If filtering is enabled on the network, all [ports](/cloud-servers/cloud-networks/ports.mdx) in this network are assigned the [default security group](/cloud-servers/security-groups/about-security-groups.mdx#default-security-group), which allows all traffic through the ports. You can assign a different security group when [creating a cluster](/managed-databases/pgvector/create-cluster.mdx) or in an [existing cluster](#assign-security-group-in-existing-cluster).

In addition to the security groups you select when creating a cluster, a service security group is automatically assigned to the network ports of the Managed Databases cluster. This group ensures the operation of the cluster and cannot be modified or deleted. The service group is displayed only in the OpenStack CLI and Terraform.

Learn more about security groups in [Security groups](/cloud-servers/security-groups/).

### Assign a security group in an existing cluster \{#assign-security-group-in-existing-cluster}

:::warning

After assigning the group, all active sessions that do not match the group rules will be terminated.

:::

1. Make sure that [traffic filtering (port security](/cloud-servers/cloud-networks/about-networks.mdx#traffic-filtering-port-security)) is enabled on the cluster network. To do this, in the [Control panel](https://my.selectel.ru/vpc/default/networks), in the top menu, click **Products** → **Cloud Servers** → **Network** → the tab **Private networks** or **Public networks**. A network with filtering enabled is marked with <ShieldOkIcon />.

   If filtering is disabled, to use security groups, create a new cluster in a new subnet or in a subnet with traffic filtering enabled and migrate the data using [logical replication](/managed-databases/pgvector/database-migration.mdx#logical-replication) or a [logical dump](/managed-databases/pgvector/database-migration.mdx#logical-dump).

2. In the [Control panel](https://my.selectel.ru/vpc/default/dbaas/), in the top menu, click **Products** and select **Managed Databases**.

3. Open the tab **Active**.

4. Open the database cluster page → tab **Settings**.

5. In the **Security** section, click **Edit**.

6. Select the security group that you want to assign to all [ports](/cloud-servers/cloud-networks/ports.mdx) in the cluster network.

7. Click <CheckIcon />.

<Formbricks />
