Skip to main content

Configure network access to a PostgreSQL cluster

By default, in clusters with a public subnet, connections are allowed from all IP addresses if a login and password are provided.

Connections to a cluster in a private subnet are allowed from the cluster subnet and from subnets connected to the cluster subnet via a cloud router.

You can define a list of allowed IP addresses from which access to the Managed Databases cluster will be allowed.

You can also use security groups to restrict access to the Managed Databases cluster.

Any changes to network access settings are the customer's responsibility.

Define a list of allowed IP addresses

When restoring a cluster from a backup, the list of allowed IP addresses will not be preserved — for the new cluster, you will need to specify the allowed IP addresses again.

  1. In the Control panel, in the top menu, click Products and select Managed Databases.
  2. Open the tab Active.
  3. Open the database cluster page → tab Settings.
  4. In the Network access management section, click the field Allowed addresses and subnet CIDRs.
  5. At the bottom of the drop-down list, enter the subnet CIDR or IP address from which access to the cluster should be allowed. Only IPv4 addressing is supported.
  6. Click .
  7. Repeat steps 5 and 6 for all allowed IP addresses.
  8. Click Save. Connection will be denied for all IP addresses except those specified in the allowed list.

Security groups in a Managed Databases cluster

A security group in a cloud database cluster is a set of rules for filtering inbound and outbound cluster traffic. For security groups to work, traffic filtering (port security) must be enabled in the network.

If filtering is enabled in the network, all ports in this network are assigned the default security group, which allows all traffic through the ports. You can assign a different security group when creating a cluster or in an existing cluster.

In addition to the security groups you select when creating a cluster, a service security group is automatically assigned to the ports of the cloud database cluster network. This group ensures cluster operation and cannot be modified or deleted. The service group is only displayed in OpenStack CLI and Terraform.

Learn more about security groups in the Security groups section.

Assign a security group in an existing cluster

warning

After assigning the group, all active sessions that do not match the group rules will be terminated.

  1. Make sure that traffic filtering (port security) is enabled in the cluster network. To do this, in the control panel, in the top menu, click Products → Cloud Servers → Network → tab Private networks or Public networks. A network with filtering enabled is marked with .

    If filtering is disabled, to use security groups, create a new cluster in a new subnet or in a subnet with traffic filtering enabled and transfer data using logical replication or a logical dump.

  2. In the control panel, in the top menu, click Products and select Cloud Databases.

  3. Open the tab Active.

  4. Open the database cluster page → tab Settings.

  5. In the Security block, click Edit.

  6. Select the security group you want to assign to all ports in the cluster network.

  7. Click .