Vault, foreign data wrappers and vectors
Tested with: Databasezy API v1 · zb CLI 0.1
These features run inside your PostgreSQL instance. Enable their extensions on the
instance’s Extensions page first (supabase_vault, wrappers, postgres_fdw,
vector; automatic embeddings also need pgmq, pg_net and pg_cron). Vault, pg_net
and pg_cron restart the database once.
Secrets are encrypted with your instance’s own root key, which lives in its cell and is never stored by the control plane or in backups.
select vault.create_secret('sk_live_...', 'stripe_key', 'Stripe live key');select decrypted_secret from vault.decrypted_secrets where name = 'stripe_key';select vault.update_secret('<id>', 'sk_live_new...');The Vault page and GET|POST /v1/orgs/{org}/instances/{id}/vault/secrets list,
create, rename, replace and delete secrets. The API never returns a value. Only the
database owner role can decrypt; to let another role read values:
grant usage on schema vault to service_role;grant select on vault.decrypted_secrets to service_role;grant execute on function vault._crypto_aead_det_decrypt(bytea, bytea, bigint, bytea, bytea) to service_role;Restoring a backup into the same instance, a branch or a restore of it keeps secrets readable: the key follows the instance’s lineage.
Foreign data wrappers
Section titled “Foreign data wrappers”The Wrappers page creates a server for Stripe, Firebase, Amazon S3, ClickHouse, BigQuery, Airtable or another PostgreSQL server, stores its credentials in Vault, and creates foreign tables (or imports a remote schema). Review the generated SQL before it runs. Query the tables like any other:
select id, email from stripe.customers limit 10;select * from files.orders_csv;Outbound connections: HTTPS (443) to public addresses is always allowed. PostgreSQL
(5432), ClickHouse (9000 or 9440) and other ports must be opened under Outbound ports
(PUT /v1/orgs/{org}/instances/{id}/egress). Private and cloud-metadata addresses are never
reachable. Opening a port is recorded in your security events.
Vectors
Section titled “Vectors”The Vector page adds vector(n) or halfvec(n) columns, builds HNSW or IVFFlat
indexes (cosine, L2 or inner product) and has a similarity search playground.
create index on documents using hnsw (embedding vector_cosine_ops);select id, title, embedding <=> '[...]' as distance from documents order by embedding <=> '[...]' limit 5;Index builds from the portal stop after 30 seconds; build indexes on large tables from
psql with the SQL the portal previews.
Automatic embeddings
Section titled “Automatic embeddings”Rows you insert or change are queued (pgmq), and a pg_cron job sends them in batches to a
project function that computes and stores the embedding. Install it from the Vector page
on the project’s primary database, then deploy the embed function from the
templates/automatic-embeddings template with your model key. On cells that serve
projects on port 8443, open outbound port 8443 for the instance.