AWS RDS for PostgreSQL
- POST
- /workspaces
- /:workspace
- /targets
Create a new AWS RDS for PostgreSQL deployment target
Request
REQUIRED SCOPES
TARGET_WRITE
URL PARAMETERS
workspacerequiredstring
The human-readable ID of the workspaceExample: "my-company"
BODY PARAMETERS
typestring
The type of the targetValue: RDS_POSTGRESQL
idstring
The ID of the targetidentifierrequiredstring
A human-readable ID. Alphanumeric characters, underscores, and hyphens (hyphens cannot appear at the start or end).namestring
The name of the targetprojectShortProjectView
Short representation of a projectpipelineShortPipelineView
Short representation of a pipelineenvironmentShortEnvironmentView
permissionsPermissionsView
Access permissions configurationpipelines_access_levelstring enum
Pipelines access level for this targetAllowed enum:
DENIED,READ_ONLY,USE_ONLY,BLIND,RUN_ONLY,READ_WRITE,MANAGE,DEFAULT,ALLOWED,STAGE,COMMITallowed_pipelinesAllowedPipelineView[]
List of specific pipelines allowed to use this targetsandboxes_access_levelstring enum
Sandboxes access level for this targetAllowed enum:
DENIED,READ_ONLY,USE_ONLY,BLIND,RUN_ONLY,READ_WRITE,MANAGE,DEFAULT,ALLOWED,STAGE,COMMITallowed_sandboxesAllowedSandboxView[]
List of specific sandboxes allowed to use this targetdisabledboolean
Indicates if this target is disabled (default: false)tagsstring[]
The list of tags associated with the targetConstraints: Unique items required
use_asUseAsView
Defines how the target can be used (as deployment target, proxy, or both)notestring
Note for this resourceagent_notestring
YAML note for AI agents operating on this resourceregionrequiredstring
AWS region of the RDS instance, e.g. us-east-1db_instance_identifierrequiredstring
RDS DB instance identifierintegrationrequiredstring
Hash ID or identifier of an AWS integrationhostrequiredstring
The hostname or IP address of the PostgreSQL serverportstring
The port of the PostgreSQL server. Default: 5432databasestring
The default database namessl_modestring enum
SSL mode: DISABLE (no encryption), REQUIRE (default; encrypted but server certificate is NOT validated, vulnerable to MITM), or VERIFY_FULL (encrypted with full server certificate validation; requires caCertificate). VERIFY_FULL cannot be combined with proxy: through an SSH tunnel the client connects to 127.0.0.1, so the server certificate fails hostname validation. With a proxy keep REQUIRE — TLS still terminates on the RDS instance, so the bastion never sees the wire protocol.Allowed enum:
DISABLE,REQUIRE,VERIFY_FULLca_certificatestring
PEM-encoded CA certificate (required when sslMode is VERIFY_FULL)authrequiredPostgresqlAuthView
PostgreSQL authentication credentialsproxyTargetK8sProxyView
SSH proxy target for tunneling to private ClickHouse serversResponse
RESPONSE BODY
typestring
The type of the targetValue: RDS_POSTGRESQL
urlread-onlystring
API endpoint to GET this objecthtml_urlread-onlystring
Web URL to view this object in Buddy.worksidstring
The ID of the targetidentifierrequiredstring
A human-readable ID. Alphanumeric characters, underscores, and hyphens (hyphens cannot appear at the start or end).namestring
The name of the targetprojectShortProjectView
Short representation of a projectpipelineShortPipelineView
Short representation of a pipelineenvironmentShortEnvironmentView
permissionsPermissionsView
Access permissions configurationpipelines_access_levelstring enum
Pipelines access level for this targetAllowed enum:
DENIED,READ_ONLY,USE_ONLY,BLIND,RUN_ONLY,READ_WRITE,MANAGE,DEFAULT,ALLOWED,STAGE,COMMITallowed_pipelinesAllowedPipelineView[]
List of specific pipelines allowed to use this targetsandboxes_access_levelstring enum
Sandboxes access level for this targetAllowed enum:
DENIED,READ_ONLY,USE_ONLY,BLIND,RUN_ONLY,READ_WRITE,MANAGE,DEFAULT,ALLOWED,STAGE,COMMITallowed_sandboxesAllowedSandboxView[]
List of specific sandboxes allowed to use this targetdisabledboolean
Indicates if this target is disabled (default: false)tagsstring[]
The list of tags associated with the targetConstraints: Unique items required
use_asUseAsView
Defines how the target can be used (as deployment target, proxy, or both)notestring
Note for this resourceagent_notestring
YAML note for AI agents operating on this resourceregionrequiredstring
AWS region of the RDS instance, e.g. us-east-1db_instance_identifierrequiredstring
RDS DB instance identifierintegrationrequiredstring
Hash ID or identifier of an AWS integrationhostrequiredstring
The hostname or IP address of the PostgreSQL serverportstring
The port of the PostgreSQL server. Default: 5432databasestring
The default database namessl_modestring enum
SSL mode: DISABLE (no encryption), REQUIRE (default; encrypted but server certificate is NOT validated, vulnerable to MITM), or VERIFY_FULL (encrypted with full server certificate validation; requires caCertificate). VERIFY_FULL cannot be combined with proxy: through an SSH tunnel the client connects to 127.0.0.1, so the server certificate fails hostname validation. With a proxy keep REQUIRE — TLS still terminates on the RDS instance, so the bastion never sees the wire protocol.Allowed enum:
DISABLE,REQUIRE,VERIFY_FULLca_certificatestring
PEM-encoded CA certificate (required when sslMode is VERIFY_FULL)authrequiredPostgresqlAuthView
PostgreSQL authentication credentialsproxyTargetK8sProxyView
SSH proxy target for tunneling to private ClickHouse serversLast modified on Sep 28, 2026
Request example
curl -X POST "https://api.buddy.works/workspaces/:workspace/targets" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "Content-Type: application/json" \
-d '{
"type": "RDS_POSTGRESQL",
"identifier": "rds-postgresql-prod",
"name": "Production PostgreSQL on RDS",
"integration": "aws-prod",
"region": "us-east-1",
"db_instance_identifier": "my-prod-postgresql",
"host": "my-prod-postgresql.abc123.us-east-1.rds.amazonaws.com",
"port": "5432",
"database": "production",
"ssl_mode": "REQUIRE",
"auth": {
"method": "PASSWORD",
"username": "admin",
"password": "secured"
},
"tags": [
"rds",
"postgresql",
"production"
]
}'STATUS201 Created