Find the connection details
Open the service in My services. Its Connect section shows:- the namespace, which is the service name;
- each address, with a Copy button;
- the name of the Secret that holds the credentials;
- for each key in that Secret, a
kubectlcommand that prints its value.
<service> standing for the service name.
Addresses and Secrets
The addresses resolve from any namespace on the service’s cluster, and not from outside it. On a cluster with a custom DNS domain, use the shorter
<name>.<service>.svc form, for example valkey.<service>.svc:6379.
Read a value
Run this against the service’s cluster (see Kubeconfig for access), with the Secret, namespace and key from the table:orders-db, this prints its connection URI:
ca.crt, needs the dot escaped:
Wire it into an application
A workload can only read Secrets in its own namespace, so an application in another namespace cannot use the service’s Secret directly. Copy the values it needs into a Secret in the application’s namespace. For an application instorefront using the orders-db PostgreSQL service:
Notes per service
- PostgreSQL. From another namespace, use
fqdn-uri, orfqdn-jdbc-urifor JDBC. The operator also writesuri,jdbc-uriandhostkeys, but they name the short hostpostgresql-rw, which resolves only inside the service’s own namespace. You connect asapp, the owner of the databaseapp, and superuser access is off. The read-only address reaches replicas only, so it answers only wheninstancesis above 1. The image includes the pgvector and pgaudit extensions. - Valkey. Authenticate as the
defaultuser withpassword;urlis a completeredis://URL. Write to the primary address. The read-replicas address serves reads from every pod. - NATS. Connect as
app.urlcarries no credentials, so passusernameandpasswordseparately. JetStream is on; memory-backed streams are disabled. - OpenSearch. Use HTTPS with basic auth as
admin, the only user. The certificate is signed by a private CA generated in the cluster: have your client trustca.crt. - SeaweedFS. Use the S3 API over plain HTTP inside the cluster, with path-style addressing. The admin key pair can read, write, list and administer buckets. The read-only key pair can only read.
- VictoriaLogs. Send logs over HTTP with basic auth, as JSON lines, Loki push, OpenTelemetry or Elasticsearch bulk, and query them with LogsQL. No log collector is installed, so ship logs with your own agent.
- VictoriaMetrics. Push metrics with basic auth using Prometheus
remote_write, OpenTelemetry, InfluxDB or another supported protocol, and query with PromQL or MetricsQL on the Prometheus HTTP API. It scrapes nothing itself, so push from vmagent, a Prometheus agent or an OpenTelemetry Collector.
Check that the service answers
Ankra does not verify readiness yet: a finished deployment reads Verification needed, not ready. Check the service before you rely on it. Its pods run in its namespace:Next steps
Managed service settings
What each setting changes, with its range and default.
Managed services
How the services run, and their current limits.