Skip to content
SupaCovedocs

05 / 13

Registering databases

Connection-string rules, per-platform gotchas, roles and TLS modes

Flow

  1. Console → "Add database" → pick a platform (or self-hosted/other).
  2. Paste a postgres:// / postgresql:// string, or fill the fields (special characters in passwords are encoded for you).
  3. A client-side pre-flight flags pooled endpoints, missing TLS modes and unsupported parameters immediately; the server then runs a real connection test before saving.
  4. The string is encrypted with the master secret and never shown again — only a redacted preview.

Platform notes

Use the session pooler (port 5432) or the direct connection (IPv6-only without the IPv4 add-on). Never the transaction pooler (6543): pg_dump cannot run through it. Full walkthrough: Back up a Supabase database.

Other managed PostgreSQL

These platforms run standard PostgreSQL, so pg_dump is expected to work against them. We have not tested them ourselves yet: the notes below come from each platform's own documentation. The console has no dedicated option for them: register with "self-hosted/other", which also means no platform-specific pre-flight hints — check the connection string against this table yourself.

PlatformConnection stringNotes
AivenThe Service URI from the service overview (host ends in .aivencloud.com, default user avnadmin, database defaultdb, ships with sslmode=require)The port is not 5432; use the one in the Service URI
Prisma PostgresThe direct TCP connection string, e.g. postgres://USER:PASSWORD@db.prisma.io:5432/?sslmode=requireBased on PostgreSQL 17; prisma+postgres:// Accelerate strings do not work with pg_dump
TigerData (Timescale)The service connection string, with sslmode=requireRestores need extra steps, see below
MigetThe External URL shown once Public Access is enabledWithout it the database is reachable only inside Miget
RenderThe External Database URL from the database page, with sslmode=requireThe Internal URL resolves only inside Render

Restoring TigerData / TimescaleDB

A backup that contains the TimescaleDB extension must be restored with SELECT timescaledb_pre_restore(); before pg_restore and SELECT timescaledb_post_restore(); after it, and never with parallel restore (-j). The recovery kit does not run these for you: decrypt first, then restore by hand following TigerData's logical backup guide. Embedded restore verification uses PostgreSQL without that extension and does not apply to these databases.

CockroachDB is not PostgreSQL: it supports schema-only dumps in plain format only, not the custom-format data dump SupaCove relies on, so it is not supported.

TLS modes (sslmode)

  • Remote hosts MUST state sslmode explicitly: raw API calls without it are refused; the console fills in your dropdown selection automatically (and drops unsupported query parameters).
  • verify-full with a CA-signed certificate; require to encrypt without verifying; disable only on private networks you trust (password and data travel in cleartext).
  • Loopback addresses default to prefer at backend parse time (not a console completion).

Reading a failed registration

A 422 shows only the fixed message ("connection test failed — verify host, port, credentials and TLS mode"); the driver error is never echoed — that is credential protection. Diagnose from the redacted detail line in the server log.

Last updated

On this page