1
Run the gateway inside the VPC
Deploy the gateway on EC2, ECS or EKS, in a subnet that reaches the
database (deploy the gateway). In the database’s
security group, allow the gateway’s security group on port 5432.
2
Create a role for the gateway
Connect with This role can only read. To let agents write, see letting agents
write.
Use a password, not IAM authentication: IAM tokens expire after 15
minutes, and the gateway reads its connection string once, at start.
psql as the master user, replace the placeholders, and run:3
Download the RDS certificate bundle
Save the global RDS bundle
in the gateway’s
secrets/ folder as rds-global-bundle.pem.4
Write the gateway's connection string
Use the endpoint from the database’s Connectivity & security tab. For
agents that only read, prefer the Aurora reader endpoint or a read
replica: it refuses writes whatever the policy says.
sslrootcert is the bundle’s path where the gateway runs:
/etc/midplane/secrets/rds-global-bundle.pem in Docker, or the file’s
full path on your machine. Save the line as secrets/<database id>.dsn,
such as secrets/shop.dsn.5
Check that it connects
Start or restart the gateway. Test connection on the Gateways page
shows your database’s id with
ok, such as shop ok, and the policy
editor lists your tables.If it doesn’t work
ETIMEDOUTorTIMEOUT: the security group doesn’t admit the gateway.SELF_SIGNED_CERT_IN_CHAIN:sslrootcertis missing or names the wrong file.28000: the instance requires TLS (rds.force_ssl) and the connection string has nosslmode.