Guides

Managed databases

Provision PostgreSQL, connect from your app, rotate credentials, and manage access.

Provision

From a project → Databases, create a PostgreSQL instance for the active deployment environment (use the project switcher when staging/production both exist). The control plane enqueues work; the provisioner creates cluster resources and credentials. Only the provisioner holds admin Postgres credentials.

Connect from your app

Prefer the internal URL from web/worker/cron services so traffic stays on the private network (db-<id>.internal.bytstack-style hosts).

Typical flow:

  1. Create the database.
  2. Copy the internal connection string into service Variables as DATABASE_URL (or your ORM's name).
  3. Redeploy so pods pick up the new env.

Storage and retention

The database price is a count. Storage, backup retention, PITR, and the external connection cap are included in that price:

PlanStorageBackup retentionPITRExternal connections
Free256 Minoneno10
Starter1 Gi7 daysno25
Pro4 Gi30 daysyes100

External access

Optional external endpoints use TLS (for example *.postgres.bytstack.app) and an IP allowlist. Use them for local psql, migrations from CI, or break-glass access — not for app-to-db traffic in production.

bytstack db connection <databaseId>
bytstack db psql <databaseId>

Snapshots and point-in-time restore

Starter and Pro keep daily snapshots (7 days and 30 days). Restore a snapshot from the database page or:

bytstack db backups <databaseId>
bytstack db restore <databaseId> --backup <backupId>

Point-in-time restore is Pro only. Free snapshot and PITR requests return HTTP 402.

bytstack db restore <databaseId> --target-time <iso>

Rotate, backups, allowlist

From the database detail page you can:

  • Rotate credentials (then update env and redeploy consumers)
  • Manage backups / restore
  • Edit the external IP allowlist

Managed cache and queues are a separate product: Redis.

Previews

PR previews must not share production databases or secret values. Prefer a non-production preview-base; see Preview deployments.