1. Clients connect only to the API
Do not embed permanent MySQL / PostgreSQL passwords in Flutter, React Native or web clients. App packages and web code can be inspected. The API verifies sessions and executes authorized queries server-side. Exposing the SQL port to the internet is not inherently required.
2. Authorize access to each record
A valid session is not permission to every record. Evaluate organization membership, role and ownership in the relevant query. Do not trust project_id or organization_id from a client without checking it. Individual reads, updates and deletes need the same boundary as lists.
3. Limit the SQL account
Grant only the permissions required by application queries. Plan schema migrations and management work under separate operator permissions. Routine application connections do not need a database superuser account. Prepare a credential rotation plan that considers running connections.
4. Verify the TLS certificate
Encryption and server identity verification are different controls. PostgreSQL libpq verify-full checks the certificate trust chain and host name. Configure trusted CA information according to provider instructions. Driver options vary; do not hide connection errors by disabling TLS verification.
postgresql://app_user:<secret>@db.internal:5432/app?sslmode=verify-full
# Illustrative only. Real host, secret and CA information comes from your provider.5. Size connection pools deliberately
Use pooling rather than opening a connection for each HTTP request. Consider web processes and worker counts when calculating limits. Monitor connection timeouts, idle connections and query durations. Closing unused connections also matters during releases.
6. Check backups and restoration separately
Creating a backup file does not prove restoration works. Define retention, access and recovery steps. Test restoration in a separate environment and check application consistency. Uygulama Cloud does not currently offer customer database backup or restore services.
7. Investigate connection failures safely
Inspect network access, DNS, ports, permissions and TLS separately. Keep passwords and full connection strings out of issue reports. A resource definition cannot supply working database credentials when no live provider is connected.