Host Postgres on EKS for PrivateLink
This page is a working sample for connecting a private database. It runs Postgres with pgvector on Amazon EKS, puts an internal NLB in front of it, and creates the VPC Endpoint Service that Astropods connects to. Adapt the names, sizes, and CIDRs to your environment.
Prerequisites
- An EKS cluster with the AWS Load Balancer Controller installed.
- The Amazon EBS CSI driver add-on, with an IAM role for its service account. A cluster with no stateful workloads yet often lacks it.
- Private subnets in at least two Availability Zones.
kubectlaccess to the cluster and the AWS CLI for the cluster’s account.
The sample uses 10.0.0.0/16 as the VPC CIDR and playbook as the name. Replace both.
Create the namespace, storage, and password
Skip the StorageClass if the cluster already has a gp3 class.
Deploy Postgres
Three settings in this manifest matter:
strategy: Recreate. An EBS volume attaches to one node at a time. A rolling update starts the new pod before the old one releases the volume, so the new pod staysPending.- The capabilities. The image’s entrypoint starts as root, changes the volume’s owner to the
postgresuser, then switches to that user. Dropping all capabilities breaks that step and the pod crash-loops. Don’t setrunAsNonRootorrunAsUserfor the same reason. PGDATApoints at a subdirectory. A new EBS volume containslost+found, and Postgres refuses to initialize a non-empty directory.
Expose Postgres on an internal NLB
The source ranges must include 100.64.0.0/10, because PrivateLink traffic reaches the NLB from that range. Keep the VPC CIDR for callers inside the VPC. The annotation key has no aws- prefix: the controller ignores aws-load-balancer-source-ranges and allows 0.0.0.0/0.
Create the VPC Endpoint Service
Look up the NLB’s ARN from the hostname the previous step printed, then create the endpoint service:
Note the ServiceId (vpce-svc-...) and the ServiceName (com.amazonaws.vpce.<region>.vpce-svc-...) in the output. With --acceptance-required, every connection request waits for you to approve it.
Allow Astropods to connect
In the dashboard, go to Knowledge > Add store and turn PrivateLink on. The form shows the principal to allow and the supported region to add. Set both on the endpoint service:
Connect the store and approve the request
Finish the Add store form with the ServiceName, port 5432, database playbook, and the credentials from step 1. You can use ast knowledge connect instead.
Astropods then requests a connection. Approve it:
The store turns Ready once the connection’s VpcEndpointState is available.
Confirm the agent can query it
Deploy an agent that declares a postgres store and choose Shared for it on the deploy form. Ask the agent a question that only your data can answer. Ready confirms the endpoint exists, not that queries reach Postgres.
If queries hang and time out, the NLB is dropping PrivateLink traffic. Check the source ranges from step 3, then see Troubleshooting.
Next steps
- Knowledge stores: how stores work and how to troubleshoot a connection
- Using knowledge stores: declare a store in an agent and bind it at deploy time