Configure network access to PostgreSQL PGVector cluster
By default, in clusters with a public subnet, connections are allowed from all IP addresses if a login and password are provided.
Connections to a cluster in a private subnet are allowed from the cluster subnet and from subnets connected to the cluster subnet via a cloud router.
You can specify a list of allowed IP addresses from which access to the Managed Databases cluster will be allowed.
To restrict access to a Managed Databases cluster, you can also use security groups.
Any changes to network access settings are the customer's responsibility.
Specify a list of allowed IP addresses
When restoring a cluster from a backup, the list of allowed IP addresses is not preserved — you will need to specify allowed IP addresses again for the new cluster.
- In the Control panel, in the top menu, click Products and select Managed Databases.
- Open the tab Active.
- Open the database cluster page → tab Settings.
- In the Network access management section, click the field Allowed addresses and subnet CIDRs.
- At the bottom of the drop-down list, enter the subnet CIDR or IP address from which access to the cluster should be allowed. Only IPv4 addressing is supported.
- Click .
- Repeat steps 5 and 6 for all allowed IP addresses.
- Click Save. Connections from all IP addresses except those specified in the allowed list will be blocked.
Security groups in a Managed Databases cluster
A security group in a Managed Databases cluster is a set of rules for filtering incoming and outgoing cluster traffic. For security groups to work, the network must have enabled traffic filtering (port security).
If filtering is enabled on the network, all ports in this network are assigned the default security group, which allows all traffic through the ports. You can assign a different security group when creating a cluster or in an existing cluster.
In addition to the security groups you select when creating a cluster, a service security group is automatically assigned to the network ports of the Managed Databases cluster. This group ensures the operation of the cluster and cannot be modified or deleted. The service group is displayed only in the OpenStack CLI and Terraform.
Learn more about security groups in Security groups.
Assign a security group in an existing cluster
After assigning the group, all active sessions that do not match the group rules will be terminated.
-
Make sure that traffic filtering (port security) is enabled on the cluster network. To do this, in the Control panel, in the top menu, click Products → Cloud Servers → Network → the tab Private networks or Public networks. A network with filtering enabled is marked with .
If filtering is disabled, to use security groups, create a new cluster in a new subnet or in a subnet with traffic filtering enabled and migrate the data using logical replication or a logical dump.
-
In the Control panel, in the top menu, click Products and select Managed Databases.
-
Open the tab Active.
-
Open the database cluster page → tab Settings.
-
In the Security section, click Edit.
-
Select the security group that you want to assign to all ports in the cluster network.
-
Click .