Skip to main content
Direct clients connect to the Resource gateway on TCP 5432. Append the Resource access name to the requested database; the short-lived Forge token is consumed by the gateway and never sent upstream.
With automatic routing, keep the destination hostname, database, and ordinary client command.

Policy fields and actions

Forge can match database, requested database user, command, schemas, tables, and a literal-free query pattern. It supports simple and prepared commands. Connections and commands can be allowed, flagged, approved, or blocked. For query results, Forge can redact exact columns or remove rows matching a predicate. Filtering runs before redaction, preserves NULL, and corrects delivered-row counts for SELECT and FETCH. Nullification supports text and binary fields; other transformations require a text-compatible value.

Destination authentication

The gateway can use an assigned username and password or generate a temporary AWS IAM database password from its workload identity for RDS and Aurora. Destination TLS and hostname verification are always required.

Current limits

COPY transformation, suspended extended-protocol portals, lineage-based column discovery, database-semantic query rewriting, and arbitrary binary value rewriting are not supported. Missing or ambiguous targeted columns, malformed messages, and incompatible formats fail closed before an original targeted value is released. See Credentials and identity and Resource Policies.