Skip to content

Remote database access

Out of the box, PostgreSQL and MySQL only listen on localhost. Falak opens them to the network only on dedicated database servers (type db), and the server firewall still decides who can connect.

When a user that may connect remotely exists on a db server, the agent:

Engine Change
PostgreSQL Adds conf.d/90-falak-network.conf with listen_addresses = '*' (restart) and a managed, password-authenticated block in pg_hba.conf per remote user
MySQL / MariaDB Adds a drop-in with bind-address = 0.0.0.0

Remote users are every PostgreSQL user, and MySQL/MariaDB users whose host is not localhost, 127.0.0.1 or ::1.

On app servers nothing is exposed to the network: the engine serves that server only, its native sites on localhost and its containers through the Docker bridge (see Containers and databases on the same server).

The database port is not open by default. Allow only the servers that need it.

  1. Optional but recommended: put the app servers and the database server in a private network. References then use the private address.

  2. On the database server page → Firewall → Add rule:

    Field Value
    Action allow
    Protocol tcp
    Port 5432 (PostgreSQL) or 3306 (MySQL/MariaDB)
    Source The app server’s address, for example 10.90.0.2/32
  3. Repeat per app server (or use the private network’s CIDR).

Use an SSH tunnel instead of opening the port:

Terminal window
falak ssh db-1 -- -N -L 5432:127.0.0.1:5432
# then connect your client to 127.0.0.1:5432 with the credentials from the panel

Change the engine’s port under the database panel → Settings (1–65535). Update your firewall rule to match. References pick up the new port on the next deployment.