AnkraDocs
Console

Concepts

Managed databases

PostgreSQL 17 on a managed VM, reachable only from one private network over TLS, with continuous WAL archiving and point-in-time restores.

A managed database is PostgreSQL 17 on a service VM that Ankra runs for you. It is reachable only from one of your private networks: the firewall admits port 5432 from that network only, and PostgreSQL accepts only the database owner, over TLS with a SCRAM password, to its one database.

Plans#

Plan Cores Memory Price per month Backup retention
db-1c-2g (default) 1 2 GiB €15 7 days
db-2c-4g 2 4 GiB €40 7 days
db-4c-8g 4 8 GiB €80 14 days

Storage is 10 to 1024 GiB (default 20) at €0.12 per GiB-month. GET /v1/databases/plans returns the current list. The database's VM, disks and backups are not billed on their own. An account holds at most 5 databases.

Creating a database#

bash
curl -X POST https://cloud.ankra.app/v1/databases \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{ "zone": "de-fsn1", "name": "orders", "network_id": "<network-id>", "database_name": "orders" }'

The answer carries the database, a database.create operation and the credentials (owner name, password and a connection URI with the password). Show them again with GET /v1/databases/{id}/credentials, or rotate the password with POST /v1/databases/{id}/reset-password; the VM switches within seconds.

database_name and owner_name (default: the database name) are lowercase SQL identifiers.

Connecting with TLS#

Every zone has a database certificate authority, and each database a server certificate from it naming its private address and tls_server_name, renewed automatically. The connection_uri uses sslmode=verify-full: save the zone authority from GET /v1/databases/{id} (ca_certificate) as ~/.postgresql/root.crt, or pass it as sslrootcert. Plain-text connections are refused.

Backups and point-in-time recovery#

PostgreSQL archives every WAL segment (at least every 60 seconds) with pgBackRest to object storage in the zone, encrypted client-side, and takes a full base backup daily around 02:30 UTC plus one right after creation. Backups and WAL are kept for the plan's retention window, which is also how far back a restore reaches.

Restore never overwrites: POST /v1/databases/{id}/restore creates a new database from the source's backups, recovered to target_time or to the latest archived point. Deleting a database takes a final full backup first and keeps its backups for the retention window, so a deleted database stays restorable by its id until then.

Availability#

A database is a single instance. If its VM dies, its host restarts it; if its host dies, the database VM is restarted on another host with the same volumes (see Live migration and HA). Either way clients see an outage of that length. Replicas and automatic promotion are not offered yet.