Before making a database public, test that clients verify its certificate, that unapproved sources cannot connect, and that removing access takes effect. A working hostname alone tells you none of this.
Dedicated public database endpoints are not implemented in Hakopod. Expanded private TLS and certificate renewal have development evidence, but that is not a public endpoint launch. The managed database guide records current availability. This article describes the checks required before public access can be supported.
Verify identity as well as encryption
TLS encrypts a connection and gives the client a way to verify the server. Configure both parts. A client that accepts any certificate still cannot establish which server it reached.
With PostgreSQL, sslmode=verify-full verifies the issuing certificate authority (CA) and hostname. A private CA also needs to be installed in the client’s trust configuration. For example, using placeholders for a database endpoint and account:
psql "host=DATABASE_HOST port=5432 \
dbname=APP_DATABASE user=APP_USER \
sslmode=verify-full \
sslrootcert=database-ca.crt"
Keep passwords in the client’s supported secret mechanism. Do not put them in copied commands, screenshots or source control. See PostgreSQL’s TLS client documentation for the exact verification modes.
Other clients have different settings. MySQL’s VERIFY_IDENTITY checks the CA and host. MongoDB drivers need TLS trust as well as replica-set discovery. ClickHouse exposes native TLS and HTTPS as separate protocols. Oracle uses TCPS; SQL*Plus clients may need a wallet containing the public CA. Copying a connection URL does not necessarily configure trust for any of them.
Distribute public trust, keep private keys private
For a private CA, applications need its public CA certificate. A publicly trusted CA may already be in the client’s trust store. Applications do not need the server private key, certificate-signing key, database administrator password or Kubernetes credentials.
Renewal must be observable. Check which certificate the running endpoint actually serves, its allowed hostnames and validity period. When the issuer changes, old and new trust may need an overlap period while applications update. A Secret containing a new certificate is not proof that the listener loaded it.
Use a native client connection to test the result. Also test a wrong hostname, an untrusted issuer and a plaintext connection. Those failures establish different boundaries. Fix the trust configuration when verification fails; disabling verification hides the evidence.
Oracle’s transport security is also separate from its license. Oracle Database Free is proprietary software that is free to use within its terms and limits. It is not open source and does not provide an Enterprise Data Guard cluster. A customer-supplied Enterprise image and license confirmation cannot by themselves establish supported failover, recovery or licensed monitoring features. Read the Oracle Free information before choosing an edition.
Review public access before enabling it
A public endpoint needs an explicit route purpose, hostname, native protocol, TLS policy, allowed source networks and connection budget. Keep it private until that review succeeds.
Source restrictions must be enforced where the actual client address is visible. A proxy or NAT can change that address. Test one allowed source and one denied source through the real network path; an allowlist in a configuration file is not enough.
The database account remains a separate boundary. A reachable endpoint should still require authentication and only grant the application its intended database permissions. Network access must not turn an application account into an administrator.
Check what the driver discovers next
A single public address is not sufficient for every cluster protocol. MongoDB drivers discover advertised replica members. Redis Cluster clients discover shard endpoints. If those discovered names resolve only inside a private cluster, the first connection may work while normal queries fail.
That is why public access needs an engine-specific design. Publishing a generic TCP proxy cannot remove discovery, consistency or failover requirements. Native PostgreSQL TLS negotiation also differs from ordinary HTTPS; the proxy and client must agree about the protocol.
Verify removal and recovery too
Removing access needs a completion state backed by the running listener and network policy. Existing sessions matter: blocking new connections does not necessarily revoke connections already established. Define and test both behaviors.
Repeat checks through certificate renewal, primary loss and interrupted updates. A failed change must not reopen an older listener with broader access. Keep the endpoint’s ownership and revision tied to the database throughout its lifecycle.
Replicas do not replace recovery testing. Restore into an isolated target, inspect it and deliberately switch the application’s saved connection. Start with the current database workflows and engine availability before planning a production deployment.