> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloud.cdata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# PostgreSQL

export const title_3 = "PostgreSQL";

export const title_2 = "PostgreSQL";

export const title_1 = "PostgreSQL";

export const title_0 = "PostgreSQL";

## Prerequisites

#### Whitelist CData IPs

To establish a connection to PostgreSQL, you need to allow access to PostgreSQL via CData’s IP. When hosting PostgreSQL behind a firewall, you must safelist these IP addresses in your firewall.

* Range: `52.224.0.160` to `52.224.0.175` and `4.154.117.160` to `4.154.117.175`.
* CIDR notation: `52.224.0.160/28` and `4.154.117.160/28`

#### Ensure PostgreSQL Is Publicly Accessible

Provide a public facing IP/domain to connect to this data source. The following private IP ranges do not work:

* `10.0.0.0` to `10.255.255.255`
* `172.16.0.0` to `172.31.255.255`
* `192.168.0.0` to `192.168.255.255`
* `127.0.0.1` (aka ‘localhost’)

## Setup Guide

Follow these steps to connect PostgreSQL to your Connect AI account:

<Steps>
  <Step>
    Open the **Sources** page of the Connect AI navigation menu.
  </Step>

  <Step>
    Click **+ Add Connection** in the upper-right corner.
  </Step>

  <Step>
    Type *PostgreSQL* into the search field, then click the data source name.
  </Step>

  <Step>
    On the **Basic Settings** tab of the new connection, enter a connection name or keep the default name.
  </Step>

  <Step>
    If your PostgreSQL connection is behind a firewall, set the **Connection Type** to **SSH Tunnel** and follow the instructions in [SSH Tunnel Instructions](#ssh-tunnel-instructions). Then continue with these instructions. Otherwise, leave the **Connection Type** as **Direct**.
  </Step>

  <Step>
    In the **Server** field, enter the host name or IP address of the PostgreSQL server.
  </Step>

  <Step>
    <Note>
      **Note:** If your PostgreSQL database has a self-signed certificate, you must copy the self-signed certificate into the **Advanced Settings** > **SSL Server Cert** field.
    </Note>
  </Step>

  <Step>
    Select the Authentication method, then proceed to the relevant section and follow those instructions.
  </Step>
</Steps>

## Authentication Methods

<Tabs>
  <Tab title="Password">
    <Steps>
      <Step>
        In the **User** field, enter the PostgreSQL username for authentication.
      </Step>

      <Step>
        Enter the user password in the **Password** field.
      </Step>

      <Step>
        (Optional) Enter the name of the PostgreSQL **Database**. If none is entered, the user's default database is used.
      </Step>

      <Step>
        (Optional) Specify the port for connecting to the PostgreSQL server in the **Port** field. This is set to 5432 by default.
      </Step>

      <Step>
        In PostgreSQL, add the Connect AI static IP addresses to your connection whitelist.
      </Step>

      <Step>
        At the top of the Connect AI **Add {title_0} Connection** page, click **Save & Test**.

        * If the connection test succeeds, a **Connection successfully saved** message appears, indicating that your connection has been created. The **Status** on the **Edit Connection** page also changes to **Authenticated**. View the data model of your successful connection in the right pane of the **Edit Connection** page, in the **Data Model** tab.
        * If the connection test fails, ensure that you entered your login information correctly with no stray spaces or other characters. Connect AI displays error messages under the required fields with missing data. Some data sources require that you sign in directly to the source website. If you did not, an error message appears under the **Sign in** button. Correct the errors and try again.
        * Unsuccessful connections are saved as drafts and have a **Status** of **Not Authenticated**. You can return to the connection and authenticate it later.
      </Step>
    </Steps>
  </Tab>

  <Tab title="AzureAD">
    <Steps>
      <Step>
        In the **User** field, enter the PostgreSQL username for authentication.
      </Step>

      <Step>
        Enter the **Azure Tenant** Id to connect to.
      </Step>

      <Step>
        (Optional) Enter the name of the PostgreSQL **Database**. If none is entered, the user's default database is used.
      </Step>

      <Step>
        (Optional) Specify the port for connecting to the PostgreSQL server in the **Port** field. This is set to 5432 by default.
      </Step>

      <Step>
        Click **Sign in** to connect securely through OAuth. This action opens the PostgreSQL sign-in page in a new tab.
      </Step>

      <Step>
        Log in to your PostgreSQL account and provide the requested permissions (if applicable).
      </Step>

      <Step>
        In PostgreSQL, add the Connect AI static IP addresses to your connection whitelist.
      </Step>

      <Step>
        At the top of the Connect AI **Add {title_1} Connection** page, click **Save & Test**.

        * If the connection test succeeds, a **Connection successfully saved** message appears, indicating that your connection has been created. The **Status** on the **Edit Connection** page also changes to **Authenticated**. View the data model of your successful connection in the right pane of the **Edit Connection** page, in the **Data Model** tab.
        * If the connection test fails, ensure that you entered your login information correctly with no stray spaces or other characters. Connect AI displays error messages under the required fields with missing data. Some data sources require that you sign in directly to the source website. If you did not, an error message appears under the **Sign in** button. Correct the errors and try again.
        * Unsuccessful connections are saved as drafts and have a **Status** of **Not Authenticated**. You can return to the connection and authenticate it later.
      </Step>
    </Steps>
  </Tab>

  <Tab title="AzurePassword">
    <Steps>
      <Step>
        In the **User** field, enter the PostgreSQL username for authentication.
      </Step>

      <Step>
        Enter the user password in the **Password** field.
      </Step>

      <Step>
        Enter the **Azure Tenant** Id to connect to.
      </Step>

      <Step>
        (Optional) Enter the name of the PostgreSQL **Database**. If none is entered, the user's default database is used.
      </Step>

      <Step>
        (Optional) Specify the port for connecting to the PostgreSQL server in the **Port** field. This is set to 5432 by default.
      </Step>

      <Step>
        In PostgreSQL, add the Connect AI static IP addresses to your connection whitelist.
      </Step>

      <Step>
        At the top of the Connect AI **Add {title_2} Connection** page, click **Save & Test**.

        * If the connection test succeeds, a **Connection successfully saved** message appears, indicating that your connection has been created. The **Status** on the **Edit Connection** page also changes to **Authenticated**. View the data model of your successful connection in the right pane of the **Edit Connection** page, in the **Data Model** tab.
        * If the connection test fails, ensure that you entered your login information correctly with no stray spaces or other characters. Connect AI displays error messages under the required fields with missing data. Some data sources require that you sign in directly to the source website. If you did not, an error message appears under the **Sign in** button. Correct the errors and try again.
        * Unsuccessful connections are saved as drafts and have a **Status** of **Not Authenticated**. You can return to the connection and authenticate it later.
      </Step>
    </Steps>
  </Tab>

  <Tab title="AWSIAMRoles">
    <Steps>
      <Step>
        In the **User** field, enter the PostgreSQL username for authentication.
      </Step>

      <Step>
        Enter the **AWS Access Key** associated with the AWS root account.
      </Step>

      <Step>
        Enter the **AWS Secret Key** associated with the AWS root account.
      </Step>

      <Step>
        Enter the **AWS Role ARN** for the authenticating User Id.
      </Step>

      <Step>
        (Optional) Enter the **AWS External Id** only if emulating a different role.
      </Step>

      <Step>
        (Optional) Enter the name of the PostgreSQL **Database**. If none is entered, the user's default database is used.
      </Step>

      <Step>
        (Optional) Specify the port for connecting to the PostgreSQL server in the **Port** field. This is set to 5432 by default.
      </Step>

      <Step>
        In PostgreSQL, add the Connect AI static IP addresses to your connection whitelist.
      </Step>

      <Step>
        At the top of the Connect AI **Add {title_3} Connection** page, click **Save & Test**.

        * If the connection test succeeds, a **Connection successfully saved** message appears, indicating that your connection has been created. The **Status** on the **Edit Connection** page also changes to **Authenticated**. View the data model of your successful connection in the right pane of the **Edit Connection** page, in the **Data Model** tab.
        * If the connection test fails, ensure that you entered your login information correctly with no stray spaces or other characters. Connect AI displays error messages under the required fields with missing data. Some data sources require that you sign in directly to the source website. If you did not, an error message appears under the **Sign in** button. Correct the errors and try again.
        * Unsuccessful connections are saved as drafts and have a **Status** of **Not Authenticated**. You can return to the connection and authenticate it later.
      </Step>
    </Steps>
  </Tab>
</Tabs>

## SSH Tunnel Instructions

If your PostgreSQL data source is behind a firewall, follow these instructions.

<Steps>
  <Step>
    Click **Connection Type** of **SSH Tunnel**.
  </Step>

  <Step>
    Enter the following information:

    * **SSH Server**–enter the name of the SSH server.
    * **SSH Port**–enter the SSH port. The default value is 22.
    * **SSH Auth Mode**–enter the authentication mode of **Password** or **Public\_Key**.
      * If **Password**, enter the **SSH User** name and **SSH Password**.
      * If **Public\_Key**, enter the **SSH User** name, **SSH Client Cert**, and **SSH Client Cert Password** (optional). Only PEMKEY\_BLOB is available as the **SSH Client Cert Type**. The **SSH Client Cert** is required, and is a valid private key. Enter the **SSH Client Cert Password** if the SSH client certificate has a password.
  </Step>

  <Step>
    Continue with the authentication instructions in the [Setup Guide](#setup-guide).
  </Step>
</Steps>

## Connect Gateway Connection

PostgreSQL is a supported connector with Connect Gateway, which acts as a bridge between your on-premises data and Connect AI. See [Connect Gateway](/en/Connect-Gateway) for more information. Once you set up the gateway, you can select the **Connection Type** of **Connect Gateway**. Then enter **Location Name** of the gateway and the PostgreSQL authentication information.

## More Information

For more information about interactions between Connect AI and PostgreSQL, see [this information page](https://cdn.cdata.com/help/FPM/cloud/default.htm#default).
