Before you begin
You need:- organization administrator access to Forge;
- a Linux host with Docker Compose and outbound HTTPS access to Forge;
- internal DNS for the gateway hostname;
- network access from the gateway host to PostgreSQL; and
- a PostgreSQL account suitable for the test.
1. Deploy a Resource gateway
- Open Policies → Resources and choose New → Resource gateway.
- Enter a name and the internal hostname clients will use.
- Select Create deployment command and copy the generated command.
- Run it on the Docker host. The command creates a version-pinned Compose deployment and stores its one-time enrollment value locally.
- Wait for the gateway to show Online.
5432 from test clients and outbound access to the
database. See Deploy a Resource gateway
for the complete network and secret-handling requirements.
2. Create the Resource
- Choose New → Resource and select PostgreSQL.
- Enter its name, destination hostname, port, and database.
- Assign the Resource gateway you just deployed.
- If the database uses a private certificate authority, add only its public CA certificate under Private authority.
- Save the Resource.
3. Assign a destination credential
On the Resource page, add a credential for your PostgreSQL test account. Assign it to yourself or make it the default for this isolated test Resource, then run Test connection. The test runs from the gateway and verifies DNS, network reachability, TLS, and destination authentication. The secret is not returned to the client.4. Add a narrow policy
Create a Resource Policy with:- Resource: the PostgreSQL Resource;
- Condition: PostgreSQL command equals
DELETE; - Action: Block;
- Mode: Enforce; and
- Message:
DELETE requires the approved maintenance workflow.
5. Connect and verify
Open Connect directly on the Resource page. Download the displayed trust certificate, create a short-lived access credential, and copy the generatedpsql command. Run one harmless read:
DELETE should fail before reaching PostgreSQL
and name the responsible policy with your message.
6. Review evidence
Open Live → Resources and filter by the Resource. Confirm the caller, protocol,SELECT and DELETE operations, outcomes, and responsible policy.
Expand the blocked row to review the literal-free query pattern. Forge does not
retain query literals or result values.
To test automatic routing too, enable it on the Resource from a managed device
and repeat the same commands against the database’s original hostname. The
policy and activity behavior should be identical.
Continue with Credentials and identity,
Resource Policies, and
Activity and approvals.