# Remote database access

> Let app servers and your own tools reach a Falak database server — how the engine is exposed, firewall rules, private networks, SSH tunnels and the port.

Source: https://falak.sh/docs/databases/remote-access/

Out of the box, PostgreSQL and MySQL only listen on `localhost`. Falak opens them to the network **only on dedicated database servers** (type `db`), and the server firewall still decides who can connect.

## How Falak exposes a database server

When a user that may connect remotely exists on a `db` server, the agent:

| Engine | Change |
|---|---|
| PostgreSQL | Adds `conf.d/90-falak-network.conf` with `listen_addresses = '*'` (restart) and a managed, password-authenticated block in `pg_hba.conf` per remote user |
| MySQL / MariaDB | Adds a drop-in with `bind-address = 0.0.0.0` |

Remote users are every PostgreSQL user, and MySQL/MariaDB users whose host is not `localhost`, `127.0.0.1` or `::1`.

On **app** servers nothing is exposed to the network: the engine serves that server only, its native sites on localhost and its containers through the Docker bridge (see [Containers and databases on the same server](/docs/databases/create-databases/#containers-and-databases-on-the-same-server)).

## Open the firewall

The database port is **not** open by default. Allow only the servers that need it.

1. Optional but recommended: put the app servers and the database server in a [private network](/docs/servers/firewall-and-networking/#private-networks-wireguard). References then use the private address.
2. On the database server page → **Firewall** → **Add rule**:

   | Field | Value |
   |---|---|
   | Action | allow |
   | Protocol | tcp |
   | Port | `5432` (PostgreSQL) or `3306` (MySQL/MariaDB) |
   | Source | The app server's address, for example `10.90.0.2/32` |

3. Repeat per app server (or use the private network's CIDR).

Leaving **Source** empty allows every IP address on the internet to try your database password. Restrict it to your servers' addresses.

## Connect from your computer

Use an SSH tunnel instead of opening the port:

```bash
falak ssh db-1 -- -N -L 5432:127.0.0.1:5432
# then connect your client to 127.0.0.1:5432 with the credentials from the panel
```

## Change the port

Change the engine's port under the database panel → **Settings** (1–65535). Update your firewall rule to match. References pick up the new port on the next deployment.

## Next steps
