Before you connect
Network access — Supaboard connects from a fixed set of egress IPs. Add them to your database firewall allow-list before attempting a connection. The current IP list is shown inside the connector form under Whitelist IPs. Database user permissions — The user you provide needs at minimum:CONNECTon the databaseUSAGEon the target schema(s)SELECTon the tables you want to expose
Connection fields
SSH Tunnel fields
Shown when the SSH Tunnel toggle is enabled.Finding your connection details
Amazon RDS for PostgreSQL
- Open the RDS Console and select your instance.
- Under Connectivity & security, copy the Endpoint — this is your Host.
- The default Port is
5432. - Your Database name was set when the instance was created (visible in the Configuration tab).
- Ensure the RDS security group allows inbound TCP on port 5432 from Supaboard’s egress IPs, or use an SSH tunnel.
Amazon Aurora (PostgreSQL-compatible)
- In the RDS Console, open your Aurora cluster.
- Use the Writer endpoint as your Host for read/write access; use a Reader endpoint for read-only.
- Port is
5432by default. - Add Supaboard IPs to the cluster’s VPC security group.
Google Cloud SQL for PostgreSQL
- Open the Cloud SQL Console and select your instance.
- Under Connect to this instance, copy the Public IP address as your Host.
- Under Connections → Authorized networks, add each Supaboard egress IP.
- Alternatively, use the Cloud SQL Auth Proxy via an SSH tunnel.
Azure Database for PostgreSQL
- Open your server in the Azure Portal.
- On the Overview page, copy Server name — this is your Host (format:
server.postgres.database.azure.com). - Under Settings → Connection security, add a firewall rule for each Supaboard egress IP.
- SSL enforcement is enabled by default on Azure — enable the SSL toggle in Supaboard.
SSL
Enable the SSL toggle when your database requires encrypted connections (recommended for all cloud-hosted instances).- SSL Certificate — paste the server’s CA certificate in PEM format if your database uses a self-signed or private CA certificate. Leave blank for certificates signed by a public CA.
SSH Tunnel
An SSH tunnel routes the database connection through a bastion host, keeping your database off the public internet entirely. When to use it:- Your database has no public IP
- You want to avoid adding Supaboard IPs to your database firewall
- Your security policy requires all external connections to go through a jump server
- The bastion server can reach the database host on port 5432
- Supaboard’s egress IPs are allowed on the bastion server’s SSH port (default 22)
- The SSH user has permission to forward connections (no
no-port-forwardinginauthorized_keys) - If using a private key, it is in PEM format (OpenSSH format may need conversion with
ssh-keygen -p -m PEM)
Recommended database user permissions
public with each schema you want to expose. Run the GRANT USAGE and GRANT SELECT blocks for each schema.

