QuestDB
Tested with: QuestDB 10.0 on Databasezy · zb CLI 0.1
QuestDB is an open-source time-series database built for fast ingestion, with SQL extensions for time such as
SAMPLE BY, LATEST ON and ASOF JOIN.
Overview
Section titled “Overview”Each instance runs a single QuestDB server reached through two public endpoints, both behind TLS on the same host: the
PostgreSQL wire protocol for queries on port 5432, and the HTTP API (REST queries, CSV import, InfluxDB line protocol
over HTTP at /write and the web console) on port 443. The line protocol TCP listener is not exposed. The database name on the PostgreSQL wire is always qdb. The PostgreSQL wire and the HTTP API use the same
generated user and password.
| Status | Available |
|---|---|
| Category | Time-series |
| Versions | 10.0, 9.4 (newest is the default) |
| Protocol and port | PostgreSQL wire protocol on 5432; also http on 443 |
| Runtime | Single-node engine (questdb/questdb) |
| Backups | CHECKPOINT + data directory copy |
| Point-in-time recovery | No |
| Pause | Scale to zero |
| Free plan | No, paid plans only |
| Licence | Apache-2.0 |
When to use it
Section titled “When to use it”- Market data, sensor streams and telemetry with high write rates.
- Queries that bucket, downsample or take the latest row per series.
Pick TimescaleDB when you also need full PostgreSQL (joins with relational data, ORMs, extensions), and InfluxDB 3 when your agents already speak InfluxDB’s APIs.
Create an instance
Section titled “Create an instance”- Open the portal and choose New instance.
- Pick QuestDB and a version (10.0, 9.4).
- Choose a size and region. Secure placement is listed only after your organization has signed the BAA.
- Check the hourly price and monthly estimate, then confirm. The Connect tab fills in when the instance is ready.
zb instances create --engine questdb --engine-version 10.0 \ --size s1 --region us-east --name questdb-demo --wait
# Reveal the credentials once and store them in your secret managerzb instances credentials reveal questdb-democurl -sS https://api.databasezy.com/v1/orgs/$ZB_ORG/projects/$ZB_PROJECT/instances \ -H "Authorization: Bearer $ZB_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "engine": "questdb", "engine_version": "10.0", "size": "s1", "region": "us-east", "name": "questdb-demo"}'
The response is 201 with the instance in status requested, or 202 when a
team approval policy applies. See the REST API reference.
Connect
Section titled “Connect”Endpoint and credentials
Section titled “Endpoint and credentials”| Host | questdb-<id>.<region>.databasezy.com, for example questdb-7f3k.us-east.databasezy.com |
|---|---|
Port 5432 | PostgreSQL wire protocol for queries, database qdb |
Port 443 | REST API (/exec), ILP over HTTP (/write) and the web console |
| Single-IP regions |
Single-IP regions use 8443 for HTTP engines instead of 443. The
portal Connect page always shows the right port.
|
| TLS | Required on every port; plaintext is refused. Verify the server: sslmode=verify-full with the CA bundle. |
| Credentials | Username admin and a generated password, presented as PostgreSQL password on the wire port, HTTP Basic on the HTTP port. Shown once at creation; reveal or rotate it from the Connect tab. |
Query with any PostgreSQL driver using sslmode=verify-full, database qdb and the generated user. Ingest with a
QuestDB client using InfluxDB line protocol over HTTPS (port 443): it authenticates with the same user and password
and reports write errors back. Line protocol over TCP is not reachable from outside the cell; configure clients with
the https:: transport, not tcp::.
Drivers and clients
Section titled “Drivers and clients”QuestDB listens on port 5432 (PostgreSQL wire protocol for queries, database qdb); port 443 (REST API (/exec), ILP over HTTP (/write) and the web console). Versions: 10.0, 9.4. Replace the example host with the one on your instance's Connect tab; credentials are shown once at creation.
postgresql://admin:<password>@questdb-7f3k.us-east.databasezy.com:5432/qdb?sslmode=verify-full&sslrootcert=databasezy-ca.pemimport osimport psycopgfrom questdb.ingress import Sender, TimestampNanos
pw = os.environ["ZB_PASSWORD"]
# Ingest with InfluxDB line protocol over HTTPS (authenticated, errors reported back)conf = f"https::addr=questdb-7f3k.us-east.databasezy.com:443;username=admin;password={pw};"with Sender.from_conf(conf) as sender: sender.row("trades", symbols={"symbol": "BTC-USD"}, columns={"price": 61842.1}, at=TimestampNanos.now())
# Query over the PostgreSQL wire protocolwith psycopg.connect( host="questdb-7f3k.us-east.databasezy.com", port=5432, dbname="qdb", user="admin", password=pw, sslmode="verify-full", sslrootcert="databasezy-ca.pem",) as conn: print(conn.execute("select * from trades latest on timestamp partition by symbol").fetchall())Tested with: QuestDB 10.0 · questdb 2.x (ILP over HTTPS) · psycopg 3.2
import { readFileSync } from "node:fs";import { Sender } from "@questdb/nodejs-client";import pg from "pg";
const pw = process.env.ZB_PASSWORD;const sender = await Sender.fromConfig( `https::addr=questdb-7f3k.us-east.databasezy.com:443;username=admin;password=${pw};`,);await sender.table("trades").symbol("symbol", "BTC-USD").floatColumn("price", 61842.1).atNow();await sender.flush();await sender.close();
const client = new pg.Client({ host: "questdb-7f3k.us-east.databasezy.com", port: 5432, database: "qdb", user: "admin", password: pw, ssl: { ca: readFileSync("databasezy-ca.pem", "utf8"), servername: "questdb-7f3k.us-east.databasezy.com" },});await client.connect();console.log((await client.query("select count() from trades")).rows);await client.end();Tested with: QuestDB 10.0 · @questdb/nodejs-client 4.x · node-postgres (pg) 8.13
# REST API over HTTPS on port 443 (same credentials, HTTP Basic)curl -sS -G -u admin:$ZB_PASSWORD "https://questdb-7f3k.us-east.databasezy.com:443/exec" \ --data-urlencode "query=select count() from trades"Tested with: QuestDB 10.0 · psql 17
QuestDB implements the PostgreSQL wire protocol, not all of PostgreSQL. Drivers, psql and BI tools work for queries;
ORM schema migrations and PostgreSQL-specific DDL usually do not. Official ingestion clients exist for Python, Java,
Go, Rust, Node.js, .NET and C/C++.
See Connecting to Databasezy for the CA bundle, the IP allow-list and credential rotation, which work the same for every engine.
Migrate in
Section titled “Migrate in”| Source | How | Continuous sync | Guide status |
|---|---|---|---|
| Self-hosted server | Connection string, Local tools (zb migrate --from local) | No | Available |
| Local files and dumps | File upload, Local tools (zb migrate --from local) | No | Available |
| Another Databasezy instance | Instance to instance | No | Coming soon · phase 2 |
From another QuestDB server or from CSV files, load data with the HTTP API’s CSV import or by re-ingesting rows over line protocol. CSV import creates the table and detects the designated timestamp:
curl -sS -u admin:$ZB_PASSWORD \-F [email protected] "https://questdb-7f3k.us-east.databasezy.com:443/imp?name=trades×tamp=timestamp&partitionBy=DAY"How migrations work explains preflight, verification and cutover, and engine conversions covers moves between compatible engines.
Backups and restore
Section titled “Backups and restore”Backups run CHECKPOINT CREATE, copy the data directory to object storage and then CHECKPOINT RELEASE, so the copied
files are consistent without stopping ingestion for long.
QuestDB backups use CHECKPOINT + data directory copy. They run inside the instance's namespace, stream straight to the cell's object storage and are checksummed on upload. How often they run and how long they are kept follows your plan's backup policy. A backup is always taken before a resize or a version upgrade.
Point-in-time recovery is not available for QuestDB. A restore returns the data as of a scheduled or manual backup. Restores create a new instance by default and leave the original untouched; an in-place restore asks you to type the instance name and takes a pre-change backup first.
zb backups create questdb-demo --label before-release # manual snapshotzb backups list questdb-demozb backups restore questdb-demo <backup-id> --name questdb-demo-restorePause and scale to zero
Section titled “Pause and scale to zero”QuestDB can scale to zero. A paused instance has no running pods and bills no compute; its storage and backups are kept and billed as usual. Connections are refused until you resume it.
zb instances pause questdb-demozb instances resume questdb-demoSee Pause and resume for schedules, wake times and billing while paused.
Limits, versions and lifecycle
Section titled “Limits, versions and lifecycle”Versions and lifecycle
Section titled “Versions and lifecycle”- Supported versions:
10.0,9.4. New instances default to10.0; pick another at creation with --engine-version or in the portal. - Minor and patch releases are applied for you in the maintenance window, always after a pre-change backup.
- New majors are added within 60 days of the upstream release. A major reaches end of life on Databasezy six months after upstream ends support, with notices 90, 30 and 7 days ahead.
- Moving between majors is a new instance plus an instance-to-instance migration, so you can test the new version before cutting over.
Sizes and limits
Section titled “Sizes and limits”QuestDB is not offered on the Free plan; it runs on the paid sizes below. The size sets the CPU, memory, storage ceiling and connection limit; the gateway refuses connections over the limit with a protocol error. Storage grows in steps up to the ceiling, and you can resize at any time.
| Size | vCPU | Memory | Max storage | Max connections | ≈ $ / month |
|---|---|---|---|---|---|
s0 | 0.25 | 1 GiB | 20 GB | 60 | $10 |
s1 | 0.5 | 2 GiB | 50 GB | 100 | $15 |
s2 | 1 | 4 GiB | 200 GB | 200 | $60 |
m2 | 2 | 8 GiB | 500 GB | 400 | $110 |
m4 | 4 | 16 GiB | 1 TB | 800 | $210 |
l8 | 8 | 32 GiB | 4 TB | 1,500 | $410 |
l16 | 16 | 64 GiB | 8 TB | 3,000 | $960 |
xl32 | 32 | 128 GiB | 16 TB | 5,000 | $1,870 |
Full details, including hourly prices and burst CPU, are in the size catalogue; plan quotas are in limits and quotas.
Tables with a designated timestamp and time partitioning get the best ingest and query performance; out-of-order
writes are supported but cost more. UPDATE is supported but slow on large tables, and there are no secondary
indexes beyond symbol indexes, so model data as append-only where you can.
Licence
Section titled “Licence”Databasezy runs QuestDB under the Apache-2.0 licence, as listed in the engine catalogue. Your data and schemas are yours whatever the server's licence; the licence governs the server software we run.
QuestDB open source is Apache-2.0. QuestDB Enterprise features (role-based access control, replication, TLS inside the server, cold storage) are not included; TLS is provided by the Databasezy gateway.
Security
Section titled “Security”- TLS on every connection. TLS 1.2 is the minimum and TLS 1.3 is preferred; plaintext is never
offered. Verify the server, not just the encryption: use
sslmode=verify-full. See TLS and the CA bundle. - IP allow-list. The gateway checks the client address before authentication, on every plan.
Manage it under Network → Allow-list in the portal or with
PUT /v1/orgs/{org}/instances/{id}/network. - Credentials. Generated inside the cell, shown once, never stored by the control plane. Rotate them with an overlap window so nothing breaks.
- Secure hosting. Secure placement (HIPAA-ready) is a per-instance option once your organization has signed the BAA: dedicated nodes, customer-managed keys and immutable backups. See Secure hosting and the BAA.
- Staff access. Databasezy staff cannot read your data without a grant you issue. See data confidentiality.
Can I use my PostgreSQL ORM?
Section titled “Can I use my PostgreSQL ORM?”For queries, often yes. QuestDB implements the PostgreSQL wire protocol but not all of PostgreSQL’s SQL, so schema migrations from ORMs usually do not work.
How should I ingest data?
Section titled “How should I ingest data?”Use a QuestDB client with line protocol over HTTPS for high-volume writes, and the PostgreSQL wire or REST for queries.
Which QuestDB versions can I run?
Section titled “Which QuestDB versions can I run?”QuestDB 10.0 (the default) and 9.4, the two latest majors. 10.0 changes some SQL results: an overflowing INT
expression wraps around instead of widening, a UNION of SYMBOL columns returns SYMBOL (so REST JSON reports
SYMBOL where 9.4 reported STRING), and EXPLAIN output is plain text. Test your queries before you move. A 9.4
instance moves to 10.0 by migrating into a new 10.0 instance.
Is QuestDB on the Free plan?
Section titled “Is QuestDB on the Free plan?”No. It is a paid-plan engine.