Spring Boot
Tested with: Spring Boot 3.4 · PostgreSQL JDBC 42.7 · MySQL Connector/J 9.1 · Lettuce 6.5 · Flyway 10 · Java 21
spring: datasource: url: jdbc:postgresql://pg-7f3k.us-east.databasezy.com:5432/app?sslmode=verify-full&sslrootcert=${ZB_CA:databasezy-ca.pem} username: app password: ${ZB_PASSWORD} hikari: maximum-pool-size: 10 connection-timeout: 10000 keepalive-time: 300000 flyway: enabled: true # runs migrations at startup against the same datasourcespring: datasource: url: jdbc:mysql://mysql-7f3k.us-east.databasezy.com:3306/app?sslMode=VERIFY_IDENTITY&trustCertificateKeyStoreUrl=file:${ZB_TRUSTSTORE:databasezy-truststore.p12}&trustCertificateKeyStoreType=PKCS12&trustCertificateKeyStorePassword=changeit username: app password: ${ZB_PASSWORD} hikari: maximum-pool-size: 10Build the truststore once (or in an init container, see Mounting the CA bundle):
keytool -importcert -noprompt -alias databasezy -file databasezy-ca.pem -keystore databasezy-truststore.p12 -storetype PKCS12 -storepass changeit.
Spring Data Redis on Valkey
Section titled “Spring Data Redis on Valkey”spring: data: redis: host: valkey-7f3k.us-east.databasezy.com port: 6379 username: app password: ${ZB_VALKEY_PASSWORD} ssl: enabled: trueLettuce verifies the certificate against the JVM truststore; add the Databasezy CA to it with keytool (or the
JAVA_TOOL_OPTIONS truststore properties) if your base image’s cacerts lacks the public root.
Migrations at startup vs in CI
Section titled “Migrations at startup vs in CI”Flyway at startup is fine for a single replica. With several replicas, run migrations once from CI or a
Kubernetes Job and set spring.flyway.enabled=false in the app to avoid lock
contention at rollout.