Connecting from a Kubernetes cluster
Tested with: Kubernetes 1.31 · External Secrets Operator 0.10 · cert-manager 1.16 · Cilium 1.16
Your workloads talk to Databasezy over the public endpoint (or PrivateLink on Enterprise); nothing of ours runs in your cluster. The pattern is the same for every engine:
Deployment ──► env from Secret (DATABASE_URL, password) ──► ExternalName Service "pg-prod" ──► pg-7f3k.us-east.databasezy.com:5432 ──► NetworkPolicy allows egress to that FQDN / CIDR only ──► CA bundle mounted from a ConfigMap (drivers that need it)Minimal working example
Section titled “Minimal working example”-
Create the credential Secret. In production this comes from your secret manager through an ExternalSecret; for a first test, create it directly.
shell kubectl create namespace appkubectl -n app create secret generic zb-pg-prod \--from-literal=host=pg-7f3k.us-east.databasezy.com \--from-literal=port=5432 \--from-literal=username=app \--from-literal=password='<password>' \--from-literal=database=app -
Publish the CA bundle as a ConfigMap (needed for libpq-based drivers; see CA bundle).
shell zb api GET /v1/orgs/{org}/ca.pem > databasezy-ca.pemkubectl -n app create configmap databasezy-ca --from-file=ca.crt=databasezy-ca.pem -
Give the host a stable in-cluster name and allow egress to it.
pg-prod-service.yaml apiVersion: v1kind: Servicemetadata:name: pg-prodnamespace: appspec:type: ExternalNameexternalName: pg-7f3k.us-east.databasezy.comports:- name: postgresport: 5432The NetworkPolicy page shows the matching egress rule for Cilium, Calico and vanilla policies.
-
Reference everything from the workload.
deployment.yaml apiVersion: apps/v1kind: Deploymentmetadata:name: apinamespace: appspec:replicas: 2selector: { matchLabels: { app: api } }template:metadata:labels: { app: api }spec:containers:- name: apiimage: ghcr.io/acme/api:1.4.2env:- name: PGHOSTvalueFrom: { secretKeyRef: { name: zb-pg-prod, key: host } }- name: PGPORTvalueFrom: { secretKeyRef: { name: zb-pg-prod, key: port } }- name: PGUSERvalueFrom: { secretKeyRef: { name: zb-pg-prod, key: username } }- name: PGPASSWORDvalueFrom: { secretKeyRef: { name: zb-pg-prod, key: password } }- name: PGDATABASEvalueFrom: { secretKeyRef: { name: zb-pg-prod, key: database } }- name: PGSSLMODEvalue: verify-full- name: PGSSLROOTCERTvalue: /etc/databasezy/ca.crtvolumeMounts:- name: databasezy-camountPath: /etc/databasezyreadOnly: trueresources:requests: { cpu: 100m, memory: 128Mi }limits: { memory: 256Mi }volumes:- name: databasezy-caconfigMap: { name: databasezy-ca } -
Allow the cluster’s egress IPs on the instance. With a NAT gateway that is one CIDR; with per-node public IPs, use the node CIDR or a static egress gateway (Cilium Egress Gateway, GKE Cloud NAT, EKS NAT).
shell zb api PUT /v1/orgs/{org}/instances/pg-7f3k/network -d '{"allow_cidrs": ["198.51.100.0/26"]}'The call replaces the whole list; include any CIDRs you already allow, or use Network → Allow-list in the portal.