CockroachDB
CockroachDB Cloud (Dedicated/Serverless) or self-hosted.
Access mode: Read-only or read-write
Required information
| Field | Details |
|---|---|
| Host / IP | Cluster endpoint. Cloud: from CockroachDB Cloud console. |
| Port | Default 26257. |
| Database(s) | CockroachDB databases. |
| Credentials | Username + password, or client certificate. |
| Access level | Read-only: SELECT on databases/tables. Standard PostgreSQL-compatible GRANT model. |
Network considerations
CockroachDB Cloud (Dedicated): VPC peering or IP allowlisting. PrivateLink available.
CockroachDB Serverless: HTTPS-based connections. IP allowlisting in console.
Self-hosted: Standard networking: VPN and firewall rules on port 26257.
Wire protocol: PostgreSQL-compatible. Standard Postgres drivers work.
Credential and auth management
Preferred: Client certificate auth. Flume generates cert, client adds to cluster’s CA. No password.
Acceptable: Password auth. SCRAM-SHA-256. Same patterns as PostgreSQL.
CockroachDB Cloud: Cluster certificates downloadable from console. Include CA cert in connection config.
Stored procedure and logic access
CockroachDB supports user-defined functions (UDFs) as of v22.2. EXECUTE privilege required. Introspection via information_schema.routines. Full stored procedures (with transactions) are still maturing. Confirm version compatibility.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Network reachability | pg_isready -h <host> -p 26257 | Accepting connections |
| Authentication | SELECT 1; | Returns 1 |
| Database access | SHOW TABLES FROM <db>.<schema>; | Lists tables |
| UDF listing | SELECT routine_name FROM information_schema.routines; | Lists functions |
| Permission check | SHOW GRANTS FOR <user>; | Matches expected grants |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.