# RDS_POSTGRESQL

AWS RDS for PostgreSQL target for executing queries on an RDS-managed PostgreSQL instance.

## YAML Parameters

```typescript
interface YAMLParameters {
  /** Hash ID or identifier of an AWS integration */
  integration: string;
  /** AWS region of the RDS instance, e.g. us-east-1 */
  region: string;
  /** RDS DB instance identifier */
  db_instance_identifier: string;
  /** The endpoint hostname of the RDS instance */
  host: string;
  /** The human-readable ID of the target */
  target: string;
  /** The name of the target */
  name?: string;
  /** The port of the RDS PostgreSQL instance. Default: 5432 */
  port?: string;
  /** The default database name */
  database?: string;
  /** SSL connection mode. Default: REQUIRE. VERIFY_FULL cannot be combined with proxy — through an SSH tunnel the client connects to 127.0.0.1, so the server certificate fails hostname validation. */
  ssl_mode?: "DISABLE" | "REQUIRE" | "VERIFY_FULL";
  /** PEM-encoded CA certificate (required when ssl_mode is VERIFY_FULL) */
  ca_certificate?: string;
  /** PostgreSQL authentication credentials */
  auth?: PostgresqlAuthYaml;
  /** SSH proxy target for tunneling to RDS instances in private VPCs. Keep ssl_mode at REQUIRE (the default) — TLS still terminates on the RDS instance, so the bastion never sees the wire protocol. VERIFY_FULL is not usable together with a proxy. */
  proxy?: string;
  /** Access permissions for the target */
  permissions?: PermissionsYaml;
  /** Indicates if this target is disabled (default: false) */
  disabled?: boolean;
  /** The list of tags associated with the target */
  tags?: string[];
  /** Defines how the target can be used (as deployment target, proxy, or both) */
  use_as?: UseAsYaml;
  /** Note for this resource */
  note?: string;
  /** YAML note for AI agents operating on this resource */
  agent_note?: string;
  type?: "RDS_POSTGRESQL";
}
```

## Type Definitions

```typescript
interface PostgresqlAuthYaml {
  /** The PostgreSQL username */
  username?: string;
  /** The PostgreSQL password */
  password?: string;
}

interface PermissionsYaml {
  /** Access level for other workspace members */
  others?: "DENIED" | "READ_ONLY" | "USE_ONLY" | "BLIND" | "RUN_ONLY" | "READ_WRITE" | "MANAGE" | "DEFAULT" | "ALLOWED" | "STAGE" | "COMMIT";
  /** Map of specific users (username or email) to their access levels */
  users?: object;
  /** List of user groups with their access levels */
  groups?: object;
  /** List of pipelines allowed to access this resource */
  pipelines?: AllowedPipelineYaml[];
  /** List of sandboxes allowed to access this resource */
  sandboxes?: AllowedSandboxYaml[];
}

interface AllowedPipelineYaml {
  /** When true, allow all pipelines to access this resource */
  all?: "DENIED" | "READ_ONLY" | "USE_ONLY" | "BLIND" | "RUN_ONLY" | "READ_WRITE" | "MANAGE" | "DEFAULT" | "ALLOWED" | "STAGE" | "COMMIT";
  /** Project name containing the allowed pipeline */
  project?: string;
  /** Pipeline identifier that is allowed to access this resource */
  pipeline?: string;
  /** Access level granted to the pipeline */
  access?: "DENIED" | "READ_ONLY" | "USE_ONLY" | "BLIND" | "RUN_ONLY" | "READ_WRITE" | "MANAGE" | "DEFAULT" | "ALLOWED" | "STAGE" | "COMMIT";
}

interface AllowedSandboxYaml {
  /** When true, allow all sandboxes to access this resource */
  all?: "DENIED" | "READ_ONLY" | "USE_ONLY" | "BLIND" | "RUN_ONLY" | "READ_WRITE" | "MANAGE" | "DEFAULT" | "ALLOWED" | "STAGE" | "COMMIT";
  /** Project name containing the allowed sandbox */
  project?: string;
  /** Sandbox identifier that is allowed to access this resource */
  sandbox?: string;
  /** Access level granted to the sandbox */
  access?: "DENIED" | "READ_ONLY" | "USE_ONLY" | "BLIND" | "RUN_ONLY" | "READ_WRITE" | "MANAGE" | "DEFAULT" | "ALLOWED" | "STAGE" | "COMMIT";
}

interface UseAsYaml {
  /** Whether the target can be used as a deployment target (default: on) */
  target?: boolean | "on" | "off";
  /** Whether the target can be used as a proxy (default: on) */
  proxy?: boolean | "on" | "off";
}

```

## YAML Examples

### RDS PostgreSQL target with SSL verification

```yaml
- target: rds-postgresql-prod
  type: RDS_POSTGRESQL
  name: Production PostgreSQL on RDS
  integration: aws-prod
  region: us-east-1
  db_instance_identifier: my-prod-postgresql
  host: my-prod-postgresql.abc123.us-east-1.rds.amazonaws.com
  port: '5432'
  database: production
  ssl_mode: VERIFY_FULL
  ca_certificate: |
    -----BEGIN CERTIFICATE-----
    <paste the AWS RDS regional CA bundle for us-east-1 here>
    -----END CERTIFICATE-----
  auth:
    username: admin
    password: secured

```

### Minimal

```yaml
- target: rds-postgresql
  type: RDS_POSTGRESQL
  integration: aws-prod
  region: us-east-1
  db_instance_identifier: my-postgresql
  host: my-postgresql.abc123.us-east-1.rds.amazonaws.com
  auth:
    username: admin
    password: secured

```


---
Original source: https://buddy.works/docs/yaml/yaml-targets/rds-postgresql