Lymeno
← All updates

Security

Lymeno now provides TLS, connection pooling, and IP allowlists

Every database gets its own hostname with TLS, and you can add a connection pool and limit where connections come from.

TLS on every connection

Each database has its own hostname under db.lymeno.com, with a publicly trusted certificate. Connect with sslmode=verify-full so that your client verifies both the certificate and the hostname.

Connection pooling

Always-on databases include a PgBouncer pool on port 6432, which is recommended for applications. It runs in transaction mode by default, with a pool size of 20 and up to 400 client connections; you can change these settings, or switch to session mode, under Configure → Connection pooler. Use the direct port, 5432, for migrations, long transactions, and LISTEN/NOTIFY.

IP allowlists

By default, a database accepts connections from any address. Add up to 50 rules, each an IPv4 or IPv6 address or a CIDR range with an optional note, to accept connections only from those sources. Changes take effect within a few seconds. In the API, use GET and PUT /v1/databases/:id/network/allowlist.

Create the first database for your agents

Sign up and create an API token to begin.