Skip to content

Spring Boot

Tested with: Spring Boot 3.4 · PostgreSQL JDBC 42.7 · MySQL Connector/J 9.1 · Lettuce 6.5 · Flyway 10 · Java 21

application.yaml
spring:
datasource:
url: jdbc:postgresql://pg-7f3k.us-east.databasezy.com:5432/app?sslmode=verify-full&sslrootcert=${ZB_CA:databasezy-ca.pem}
username: app
password: ${ZB_PASSWORD}
hikari:
maximum-pool-size: 10
connection-timeout: 10000
keepalive-time: 300000
flyway:
enabled: true # runs migrations at startup against the same datasource
application.yaml
spring:
data:
redis:
host: valkey-7f3k.us-east.databasezy.com
port: 6379
username: app
password: ${ZB_VALKEY_PASSWORD}
ssl:
enabled: true

Lettuce verifies the certificate against the JVM truststore; add the Databasezy CA to it with keytool (or the JAVA_TOOL_OPTIONS truststore properties) if your base image’s cacerts lacks the public root.

Flyway at startup is fine for a single replica. With several replicas, run migrations once from CI or a Kubernetes Job and set spring.flyway.enabled=false in the app to avoid lock contention at rollout.