Database connections
Connect applications to PostgreSQL, MySQL, and Key Value with private addresses and managed references.
Managed databases are private services. Place the application and database in the same Openstead environment and connect with the values shown in the database's Connections page.
Prefer connection references
A connection reference maps an environment variable on an application to a field on a database. Openstead resolves it when creating a release, so the variable listing does not need to expose the database password.
Open the application's Environment page and find Connected Services → Connect service. Choose the database from the available sources, enter the variable name, and select its connection field. Then deploy the application.
| Database | Suggested variable | Field |
|---|---|---|
| PostgreSQL | DATABASE_URL | Connection URL |
| MySQL | DB_URL, or individual DB_* variables | Connection URL, or individual fields |
| Key Value | REDIS_URL | Connection URL |
Use the variable names your framework actually reads. Laravel commonly uses separate MySQL values; see MySQL.
An ordinary environment variable or linked environment-group variable cannot use the same name as a connection reference. Remove or rename the conflicting variable first.
What is available
| Field | PostgreSQL | MySQL | Key Value |
|---|---|---|---|
| Host | Private hostname | Private hostname | Private hostname |
| Port | 5432 | 3306 | 6379 |
| Username | Yes | Yes | Not a separate field |
| Password | Yes | Yes | Yes |
| Database name | Yes | Yes | Use the database index in the URL |
| Connection URL | Yes | Yes | Yes |
The source database must be running and its restore must have completed. Openstead blocks a dependent deployment if its reference cannot be resolved safely.
Reveal credentials when necessary
Authorised members can select Reveal connection credentials on the database's Connections page. Copy only the fields required by the client and keep them in a secrets manager.
Do not commit connection URLs, place them in public frontend variables, paste them into support messages, or print them in build logs. A URL contains credentials even if it looks like a normal address.
Use the supplied URL rather than manually concatenating a password into a URL. Special characters must be URL-encoded correctly; the generated URL handles this.
When changes take effect
Connection values are saved into each release's environment. Adding or removing a reference changes future deployments; it does not rewrite an already running process.
After changing a reference, switching to a restored database, or changing an address, redeploy every affected web service and worker. Existing releases retain their previous configuration until replaced.
Moving a database or application to another environment can make a reference invalid. Keep dependent services together or create an appropriate database in the destination environment.
Access from your computer
The private hostnames do not resolve as public database endpoints. Desktop tools cannot connect directly over the internet. MySQL's phpMyAdmin provides authenticated browser access without publishing port 3306.
For a command-line operation, use a suitable client installed in an authorised application in the same environment, where shell access is supported. Managed database services themselves do not provide an interactive shell or arbitrary one-off commands.
Connection troubleshooting
Check the environment first, then the service's live state and credentials. If those are correct, inspect client driver compatibility, connection-pool limits, and the application's actual environment after deployment. A build process should not assume it can contact a runtime-only private database; run schema changes at the appropriate deployment or runtime stage.