- A Neki database with a ready branch.
- An application role for that branch. Use
pg_read_all_datafor read traffic and addpg_write_all_datawhen the application writes rows. These inherited data roles do not grantCREATEorALTER, so application credentials cannot change the schema. - A separate migration role, if you run schema changes against the branch. DDL
requires the
postgresinherited role. Neki restricts execution of the cross-router DDL barrier function__neki.wait_for_ddlto itsneki_viewerrole, so addneki_viewer, which requirespg_read_all_data, to the same role. Keep the migration credentials out of the application’s runtime configuration. - The Primary connection details from the database’s Connect page.
Create a Bun project
Install Bun, then initialize a project:Add the connection string
Bun automatically loads local environment variables from.env. Copy the
connection URI from the Connect page:
.env
sslmode=verify-full directly, verifying the server
certificate against trusted CAs and checking the hostname. Do not add
sslrootcert=system; Bun does not use it as a trust-store selector. Do not
commit the .env file.
Connect and run a query
Use Bun’ssql template literal:
index.ts
Apply schema changes
Framework migration commands send DDL through a normal Neki connection. The
router fans that DDL out to the managed shards, but it does not create a
managed schema-change workflow. Use a schema-change
workflow when you want Neki to prepare and coordinate
an Online DDL change.
pg_read_all_data and pg_write_all_data
cannot run CREATE or ALTER, so a migration that uses application
credentials fails on its first DDL statement.
Apply migration DDL with psql and the migration role so the client prints
PostgreSQL notices:
NOTICE containing the barrier call
for that transaction:
psql when the framework cannot preserve
the notice. If the notice is lost, its version pair cannot be reconstructed.
Bun SQL does not expose PostgreSQL notices. Apply migration SQL with psql so
you can capture and run the DDL barrier.
For read-only traffic, add the Neki replica startup option described in
Primary and replica routing
to the connection URI.

