Managed databases
Provision PostgreSQL, connect from your app, rotate credentials, and manage access.
Provision
From a project → Databases, create a PostgreSQL instance for the active deployment environment (use the project switcher when staging/production both exist). The control plane enqueues work; the provisioner creates cluster resources and credentials. Only the provisioner holds admin Postgres credentials.
Connect from your app
Prefer the internal URL from web/worker/cron services so traffic stays on the private network (db-<id>.internal.bytstack-style hosts).
Typical flow:
- Create the database.
- Copy the internal connection string into service Variables as
DATABASE_URL(or your ORM's name). - Redeploy so pods pick up the new env.
Storage and retention
The database price is a count. Storage, backup retention, PITR, and the external connection cap are included in that price:
| Plan | Storage | Backup retention | PITR | External connections |
|---|---|---|---|---|
| Free | 256 Mi | none | no | 10 |
| Starter | 1 Gi | 7 days | no | 25 |
| Pro | 4 Gi | 30 days | yes | 100 |
External access
Optional external endpoints use TLS (for example *.postgres.bytstack.app) and an IP allowlist. Use them for local psql, migrations from CI, or break-glass access — not for app-to-db traffic in production.
bytstack db connection <databaseId>
bytstack db psql <databaseId>Snapshots and point-in-time restore
Starter and Pro keep daily snapshots (7 days and 30 days). Restore a snapshot from the database page or:
bytstack db backups <databaseId>
bytstack db restore <databaseId> --backup <backupId>Point-in-time restore is Pro only. Free snapshot and PITR requests return HTTP 402.
bytstack db restore <databaseId> --target-time <iso>Rotate, backups, allowlist
From the database detail page you can:
- Rotate credentials (then update env and redeploy consumers)
- Manage backups / restore
- Edit the external IP allowlist
Managed cache and queues are a separate product: Redis.
Previews
PR previews must not share production databases or secret values. Prefer a non-production preview-base; see Preview deployments.