Skip to main content
This guide connects the gateway to an RDS or Aurora Postgres database that stays private in its VPC. You need a Midplane project with the database named in it (get started, step 2).
1

Run the gateway inside the VPC

Deploy the gateway on EC2, ECS or EKS, in a subnet that reaches the database (deploy the gateway). In the database’s security group, allow the gateway’s security group on port 5432.
2

Create a role for the gateway

Connect with psql as the master user, replace the placeholders, and run:
This role can only read. To let agents write, see letting agents write. Use a password, not IAM authentication: IAM tokens expire after 15 minutes, and the gateway reads its connection string once, at start.
3

Download the RDS certificate bundle

Save the global RDS bundle in the gateway’s secrets/ folder as rds-global-bundle.pem.
4

Write the gateway's connection string

Use the endpoint from the database’s Connectivity & security tab. For agents that only read, prefer the Aurora reader endpoint or a read replica: it refuses writes whatever the policy says.
sslrootcert is the bundle’s path where the gateway runs: /etc/midplane/secrets/rds-global-bundle.pem in Docker, or the file’s full path on your machine. Save the line as secrets/<database id>.dsn, such as secrets/shop.dsn.
5

Check that it connects

Start or restart the gateway. Test connection on the Gateways page shows your database’s id with ok, such as shop ok, and the policy editor lists your tables.

If it doesn’t work

  • ETIMEDOUT or TIMEOUT: the security group doesn’t admit the gateway.
  • SELF_SIGNED_CERT_IN_CHAIN: sslrootcert is missing or names the wrong file.
  • 28000: the instance requires TLS (rds.force_ssl) and the connection string has no sslmode.