Skip to main content
See All Integrations

DBeaver

Connect DBeaver to protected database services through Pomerium TCP routes.

Standard database client access pattern

Categories
Databases, Developer Tools

Overview

DBeaver is a desktop database client. It is not the protected upstream in this access pattern. Pomerium protects the selected PostgreSQL, MySQL, MongoDB, or other database endpoint. DBeaver connects to the local Pomerium tunnel.

DBeaver is the client, not the protected service. The useful access path gives DBeaver a local loopback endpoint while the selected database stays private.

Pomerium controls the TCP tunnel to the selected database endpoint. DBeaver sends the normal database protocol to the local listener. The database server keeps TLS, account authentication, roles, and data permissions.

How it works

Create a Pomerium TCP route for the actual private database or service endpoint. Start a local tunnel with Pomerium CLI or Pomerium Desktop.

Point the desktop client to the local loopback listener. Keep the database or service authentication and TLS controls active.

Select the normal DBeaver driver for the database. Set its host to the local loopback address and its port to the Pomerium client listener. Keep the real database credentials in the normal database authentication flow.

Example

A developer starts a local Pomerium TCP tunnel for a private PostgreSQL route. DBeaver connects to the loopback port. Pomerium checks route access, and PostgreSQL keeps its database account and SQL permissions.

Considerations

  • Pomerium does not protect the DBeaver process or replace its database drivers.
  • Each database protocol and endpoint needs a compatible Pomerium route. Preserve database TLS and authentication.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
  • For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.

Sources and official resources

  • Protect access to PostgreSQL services through Pomerium TCP routes.

  • Protect access to MySQL services through Pomerium TCP routes.

  • Protect access to MongoDB services through Pomerium TCP routes.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo