Cloudflare Workers
Tested with: wrangler 3.90 · Workers runtime 2025-09 · Hyperdrive · @libsql/client 0.14 · pg 8.13
Workers have no long-lived process, so connection reuse is the whole story. Two good options:
Hyperdrive keeps a warm pool near the origin and speaks TLS to Databasezy.
-
Create the Hyperdrive config with the direct endpoint (Hyperdrive is the pooler).
shell npx wrangler hyperdrive create zb-pg-prod \--connection-string="postgresql://app:<password>@pg-7f3k.us-east.databasezy.com:5432/app?sslmode=verify-full" -
Bind it and use
pgwith the binding’s connection string.wrangler.toml [[hyperdrive]]binding = "DB"id = "<hyperdrive id>"src/index.ts import { Client } from "pg";export default {async fetch(_req: Request, env: { DB: Hyperdrive }) {const client = new Client({ connectionString: env.DB.connectionString });await client.connect();const { rows } = await client.query("select now()");await client.end();return Response.json(rows[0]);},}; -
Allow Cloudflare’s egress on the instance: Hyperdrive connects from Cloudflare’s published IP ranges (
https://www.cloudflare.com/ips-v4), which you can add as CIDRs.
No sockets needed; the Worker calls the Hrana HTTP endpoint directly.
npx wrangler secret put ZB_TOKENimport { createClient } from "@libsql/client/web";
export default { async fetch(_req: Request, env: { ZB_TOKEN: string }) { const db = createClient({ url: "https://libsql-7f3k.us-east.databasezy.com", authToken: env.ZB_TOKEN }); const rs = await db.execute("select datetime('now') as now"); return Response.json(rs.rows[0]); },};Cloudflare’s egress ranges go on the allow-list the same way.
Valkey and FerretDB
Section titled “Valkey and FerretDB”Use connect() from cloudflare:sockets with secureTransport: "on"; ioredis and the MongoDB driver do not run on
Workers. For caching, Workers KV or a Node-runtime service in front of Valkey is usually simpler.