Skip to main content

PostgresFlexibleServer

resourceType postgresql · provider azure · sharing Private · cleanup Orphan

Provisions a managed Azure Database for PostgreSQL Flexible Server with a single application database. Sized dev→prod: production sets highAvailabilityMode, a larger SKU, geo-redundant backups, longer retention, and a private endpoint; dev takes the Burstable defaults with public access closed.

Request it​

Add this to your PlatformApplication's spec.resourceRequirements (optional parameters are in the table below):

resourceRequirements:
- resourceType: postgresql
provider: azure # selects this backend — the cluster default may differ
resourceName: my-postgresql # your handle — drives the env-var prefix + secret name
parameters:
databaseName: "<value>"

Parameters​

NameTypeRequiredDefaultDescription
databaseNamestringyes—Name of the application database to create on the server.
sharedstringnofalseProvision as THE shared server for the environment ('true'/'false'): deterministic name/FQDN (pgsql-shared-{uniqueSuffix}) plus an emitted provider-sql ProviderConfig. Set by the postgres-shared-server--azure capability; leave false for a dedicated server.
administratorLoginstringnopgadminServer administrator login name (immutable after create).
postgresVersionstringno16PostgreSQL major version.
skuNamestringnoB_Standard_B1msAzure Flexible Server SKU (e.g. B_Standard_B1ms for dev, GP_Standard_D2ds_v5 for prod). ZoneRedundant HA requires a GeneralPurpose/MemoryOptimized SKU.
storageGbstringno32Storage size in GiB (converted to storageMb).
autoGrowstringnotrueEnable storage auto-grow ('true'/'false').
backupRetentionDaysstringno7Backup retention window in days (7-35).
geoRedundantBackupstringnofalseEnable geo-redundant backups for DR ('true'/'false'). Recommended for production.
highAvailabilityModestringno``High-availability mode. Empty/Disabled = single instance.
standbyZonestringno—Availability zone for the standby replica (ZoneRedundant HA only).
zonestringno—Availability zone for the primary instance.
publicNetworkAccessstringnofalseAllow public network access ('true'/'false'). Defaults closed; production should use a private endpoint instead.
allowAzureServicesstringnofalseAllow Azure services (including in-cluster AKS workloads) to reach the server over the public endpoint, by adding a 0.0.0.0 firewall rule ('true'/'false'). Only applied when publicNetworkAccess is true.
firewallRulesstringno[]Explicit firewall rules as a JSON array, e.g. '[{"name":"office","startIpAddress":"203.0.113.4","endIpAddress":"203.0.113.4"}]'. Only applied when publicNetworkAccess is true.
createPrivateEndpointstringnofalseCreate a private endpoint for the server ('true'/'false'). Requires privateEndpointSubnetId.
privateEndpointSubnetIdstringno—Subnet resource ID for the private endpoint.
createPrivateDnsstringnofalseCreate a private DNS zone + VNet link for the server ('true'/'false'). Requires createPrivateEndpoint and privateDnsVnetId.
privateDnsVnetIdstringno—Virtual network resource ID to link the private DNS zone to.
charsetstringnoUTF8Database character set.
collationstringnoen_US.utf8Database collation.

Connection​

On grant, a connection secret is published with these tokens and injected into your workload as {RESOURCENAME}_{TOKEN} (UPPER_SNAKE) — e.g. resourceName: my-postgresql → MY_POSTGRESQL_HOST, MY_POSTGRESQL_PORT, …:

  • host
  • port
  • username
  • password
  • dbname

Status​

FieldDescription
serverNameName of the Azure Flexible Server.
fqdnFully-qualified domain name of the server.
databaseNameName of the application database.

Auto-generated from the PostgresFlexibleServer XRD + postgresql--azure ResourceCapability. Do not edit by hand.