Remote database access
Out of the box, PostgreSQL and MySQL only listen on localhost. Falak opens them to the network only on dedicated database servers (type db), and the server firewall still decides who can connect.
How Falak exposes a database server
Section titled “How Falak exposes a database server”When a user that may connect remotely exists on a db server, the agent:
| Engine | Change |
|---|---|
| PostgreSQL | Adds conf.d/90-falak-network.conf with listen_addresses = '*' (restart) and a managed, password-authenticated block in pg_hba.conf per remote user |
| MySQL / MariaDB | Adds a drop-in with bind-address = 0.0.0.0 |
Remote users are every PostgreSQL user, and MySQL/MariaDB users whose host is not localhost, 127.0.0.1 or ::1.
On app servers nothing is exposed to the network: the engine serves that server only, its native sites on localhost and its containers through the Docker bridge (see Containers and databases on the same server).
Open the firewall
Section titled “Open the firewall”The database port is not open by default. Allow only the servers that need it.
-
Optional but recommended: put the app servers and the database server in a private network. References then use the private address.
-
On the database server page → Firewall → Add rule:
Field Value Action allow Protocol tcp Port 5432(PostgreSQL) or3306(MySQL/MariaDB)Source The app server’s address, for example 10.90.0.2/32 -
Repeat per app server (or use the private network’s CIDR).
Connect from your computer
Section titled “Connect from your computer”Use an SSH tunnel instead of opening the port:
falak ssh db-1 -- -N -L 5432:127.0.0.1:5432# then connect your client to 127.0.0.1:5432 with the credentials from the panelChange the port
Section titled “Change the port”Change the engine’s port under the database panel → Settings (1–65535). Update your firewall rule to match. References pick up the new port on the next deployment.