Skip to content

Vault, foreign data wrappers and vectors

Tested with: Databasezy API v1 · zb CLI 0.1

These features run inside your PostgreSQL instance. Enable their extensions on the instance’s Extensions page first (supabase_vault, wrappers, postgres_fdw, vector; automatic embeddings also need pgmq, pg_net and pg_cron). Vault, pg_net and pg_cron restart the database once.

Secrets are encrypted with your instance’s own root key, which lives in its cell and is never stored by the control plane or in backups.

SQL
select vault.create_secret('sk_live_...', 'stripe_key', 'Stripe live key');
select decrypted_secret from vault.decrypted_secrets where name = 'stripe_key';
select vault.update_secret('<id>', 'sk_live_new...');

The Vault page and GET|POST /v1/orgs/{org}/instances/{id}/vault/secrets list, create, rename, replace and delete secrets. The API never returns a value. Only the database owner role can decrypt; to let another role read values:

SQL
grant usage on schema vault to service_role;
grant select on vault.decrypted_secrets to service_role;
grant execute on function vault._crypto_aead_det_decrypt(bytea, bytea, bigint, bytea, bytea) to service_role;

Restoring a backup into the same instance, a branch or a restore of it keeps secrets readable: the key follows the instance’s lineage.

The Wrappers page creates a server for Stripe, Firebase, Amazon S3, ClickHouse, BigQuery, Airtable or another PostgreSQL server, stores its credentials in Vault, and creates foreign tables (or imports a remote schema). Review the generated SQL before it runs. Query the tables like any other:

SQL
select id, email from stripe.customers limit 10;
select * from files.orders_csv;

Outbound connections: HTTPS (443) to public addresses is always allowed. PostgreSQL (5432), ClickHouse (9000 or 9440) and other ports must be opened under Outbound ports (PUT /v1/orgs/{org}/instances/{id}/egress). Private and cloud-metadata addresses are never reachable. Opening a port is recorded in your security events.

The Vector page adds vector(n) or halfvec(n) columns, builds HNSW or IVFFlat indexes (cosine, L2 or inner product) and has a similarity search playground.

SQL
create index on documents using hnsw (embedding vector_cosine_ops);
select id, title, embedding <=> '[...]' as distance from documents order by embedding <=> '[...]' limit 5;

Index builds from the portal stop after 30 seconds; build indexes on large tables from psql with the SQL the portal previews.

Rows you insert or change are queued (pgmq), and a pg_cron job sends them in batches to a project function that computes and stores the embedding. Install it from the Vector page on the project’s primary database, then deploy the embed function from the templates/automatic-embeddings template with your model key. On cells that serve projects on port 8443, open outbound port 8443 for the instance.