> ## Documentation Index
> Fetch the complete documentation index at: https://docs.springwinter.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Launch a Managed Database in Your AWS Account

> Provision a PostgreSQL or MySQL RDS instance inside your own AWS account, with credentials stored securely in AWS Secrets Manager.

Springwinter provisions PostgreSQL and MySQL databases using AWS RDS, directly inside your AWS account. The master password is generated at creation time and stored in AWS Secrets Manager in your account — Springwinter reads it on demand when you request credentials and never stores it in its own systems. Your database stays in your infrastructure, under your control.

## Supported Engines

<CardGroup cols={2}>
  <Card title="PostgreSQL" icon="elephant">
    The world's most advanced open-source relational database. Choose PostgreSQL for complex queries, JSON workloads, full-text search, or when you need `pg_*` extensions.
  </Card>

  <Card title="MySQL" icon="database">
    A fast, battle-tested relational database widely supported by ORMs and frameworks. Choose MySQL for existing MySQL-based applications or when compatibility with MySQL tooling is required.
  </Card>
</CardGroup>

## Create a Database

<Steps>
  <Step title="Open your project">
    Navigate to your project in the Springwinter dashboard and click **Add resource**.
  </Step>

  <Step title="Select Database">
    Choose **Database** from the resource type list. You will be taken to the database configuration form.
  </Step>

  <Step title="Choose an engine and instance size">
    Select either **PostgreSQL** or **MySQL**, then choose the instance size that fits your workload. Instance size controls vCPU, memory, and IOPS. You can resize later.
  </Step>

  <Step title="Create">
    Click **Create**. Springwinter provisions the RDS instance in your AWS account and stores the generated master password in AWS Secrets Manager. The database status changes to **Available** once provisioning is complete, typically within five to ten minutes.
  </Step>
</Steps>

## Credentials and Connection String

When provisioning is complete, the connection string is visible from the **Connection** tab of the database resource in the Springwinter dashboard. Springwinter retrieves the password from Secrets Manager in your account each time you view credentials — it is never cached in Springwinter's own systems.

The connection string uses the standard URI format:

<Tabs>
  <Tab title="PostgreSQL">
    ```
    postgresql://username:password@<rds-endpoint>:5432/dbname
    ```
  </Tab>

  <Tab title="MySQL">
    ```
    mysql://username:password@<rds-endpoint>:3306/dbname
    ```
  </Tab>
</Tabs>

## Connecting from a Web Server or Worker

The RDS instance is accessible only from within the same project's network. Set `DATABASE_URL` as an environment variable on your web server or worker, pointing to the RDS endpoint, and your application will connect automatically:

```bash theme={null}
DATABASE_URL=postgresql://username:password@<rds-endpoint>:5432/dbname
```

See [Environment Variables](/concepts/environment-variables) for instructions on setting environment variables through the dashboard or API.

<Tip>
  Most modern ORMs and database libraries — including Prisma, SQLAlchemy, Django, ActiveRecord, and GORM — read `DATABASE_URL` automatically. Set the variable once and your application code needs no further changes.
</Tip>

## Backups

Automated backups are managed entirely by AWS RDS. By default, RDS retains daily snapshots for seven days. You can adjust the retention period and backup window directly in the AWS Console under the **Maintenance & backups** section of your RDS instance.

<Info>
  Springwinter does not manage RDS backup settings. Use the AWS Console or AWS CLI to change the automated backup retention period, create manual snapshots, or restore from a snapshot.
</Info>

## Resize an Instance

To change the instance size of a running database, update the resource from the Springwinter dashboard or via the API:

```http theme={null}
PATCH /api/projects/{project_id}/databases/{id}
Authorization: Bearer <token>
Content-Type: application/json
```

```json theme={null}
{
  "instance_size": "db.t3.medium"
}
```

<Warning>
  Resizing an RDS instance causes a brief period of downtime during the instance replacement. Plan resizes during a low-traffic window.
</Warning>

## API Reference

### Get a Database

```http theme={null}
GET /api/projects/{project_id}/databases/{id}
Authorization: Bearer <token>
```

## Delete a Database

To remove the RDS instance from your AWS account:

```http theme={null}
DELETE /api/projects/{project_id}/databases/{id}
Authorization: Bearer <token>
```

<Warning>
  Deleting a database resource is irreversible unless you have an RDS snapshot. All data on the instance is permanently destroyed. Create a manual snapshot in the AWS Console before deleting if you need to preserve your data.
</Warning>

## Security

<Accordion title="Network isolation">
  The RDS instance is deployed inside your project's network with no public inbound access. Only resources in the same network — your web servers, workers, and other Springwinter-managed services — can reach the database endpoint.
</Accordion>

<Accordion title="Credentials in Secrets Manager">
  The master password is generated at creation time and stored as a secret in AWS Secrets Manager in your account. Springwinter assumes your connected IAM role to read the secret on demand. Your password is never stored in Springwinter's own systems.
</Accordion>

<Accordion title="Encryption at rest">
  RDS storage encryption is enabled by default for all databases provisioned by Springwinter, using AWS-managed KMS keys in your account.
</Accordion>
