pg.
Before you start, you need:
- A Neki database with a ready branch.
- An application role for that branch. Use
pg_read_all_datafor read traffic and addpg_write_all_datawhen the application writes rows. These inherited data roles do not grantCREATEorALTER, so application credentials cannot change the schema. - A separate migration role, if you run schema changes against the branch. DDL
requires the
postgresinherited role. Neki restricts execution of the cross-router DDL barrier function__neki.wait_for_ddlto itsneki_viewerrole, so addneki_viewer, which requirespg_read_all_data, to the same role. Keep the migration credentials out of the application’s runtime configuration. - The Primary connection details from the database’s Connect page.
Install the Postgres client
Installpg. This example also uses dotenv to load local environment
variables:
Add the connection string
Copy the Primary connection URI from the Connect page into.env:
.env
.env file. Set the same value through your
deployment platform’s secret manager in production.
Connect and run a query
Create a client fromDATABASE_URL. The node-postgres connection-string
parser maps sslmode=verify-full to Node.js TLS certificate and hostname
verification. Do not add sslrootcert=system; node-postgres treats its value
as a certificate filename.
index.js
Apply schema changes
Framework migration commands send DDL through a normal Neki connection. The
router fans that DDL out to the managed shards, but it does not create a
managed schema-change workflow. Use a schema-change
workflow when you want Neki to prepare and coordinate
an Online DDL change.
pg_read_all_data and pg_write_all_data
cannot run CREATE or ALTER, so a migration that uses application
credentials fails on its first DDL statement.
Apply migration DDL with psql and the migration role so the client prints
PostgreSQL notices:
NOTICE containing the barrier call
for that transaction:
psql when the framework cannot preserve
the notice. If the notice is lost, its version pair cannot be reconstructed.
For read-only traffic, see Primary and replica
routing.

