Configure the database

  1. Sizing
  2. Required extensions
    1. Azure Database for PostgreSQL Flexible Server
    2. Amazon RDS for PostgreSQL
    3. Self-managed PostgreSQL
    4. Enable the extensions
  3. Secure the database connection
    1. Obtain the root certificates
    2. Construct the certificate bundle
    3. Create the Kubernetes secret
  4. Database initialization
    1. Manual initialization
  5. Next step

SAS Retrieval Agent Manager requires a PostgreSQL 16 database for application data, vector embeddings, and more. The database can run on any platform as long as the Kubernetes cluster can reach it.

The terraform scripts will provision the database instance for you and the helm installation will initialize the different databases and hydrate them with the necessary data automatically.

This page offers an alternative approach for configuring the database manually, instead of using the provided Terraform scripts.

If you are having the database automatically created by terraform (default behavior), proceed to install the application.

Sizing

The database uses the same Small, Medium, and Large tiers as the cluster. Choose your tier from the workload criteria in Cluster sizing, then size the database:

Deployment size Total vCPU (min) Total RAM (Gb) Storage (Gb) Queries per day Agents/Custom sources/MCP servers
Small 4 16 128 4000 6
Medium 4 16 128 8000 20
Large 8 32 128 8000+ 20+

Required extensions

Extension Required/Recommended Description
pgcrypto Required Database encryption of application data
vector Recommended Storing vector embeddings in the PostgreSQL database (alternative is Weaviate)

Making an extension available differs per platform. Follow the section for your platform, then enable the extensions.

Azure Database for PostgreSQL Flexible Server

Azure requires extensions to be allow-listed at the server level before they can be activated in a database.

# Allow pgcrypto and vector on the Flexible Server
az postgres flexible-server parameter set \
  --resource-group <resource_group> \
  --server-name <server_name> \
  --name azure.extensions \
  --value pgcrypto,vector

Note: If the azure.extensions parameter already has values, append the new ones as a comma-separated list rather than replacing them. You can check the current value with:

az postgres flexible-server parameter show \
  --resource-group <resource_group> \
  --server-name <server_name> \
  --name azure.extensions

Alternatively, allow-list the extensions in the Azure Portal by navigating to your Flexible Server → Server parameters → search for azure.extensions → add PGCRYPTO and VECTOR to the value list → Save.

Amazon RDS for PostgreSQL

Amazon RDS ships pgcrypto and pgvector as pre-built extensions. No system package installation is required.

Note: pgvector is available on RDS PostgreSQL 15.2 and later. Verify your RDS instance meets this requirement before proceeding.

Self-managed PostgreSQL

Install the system packages first. The required packages depend on your PostgreSQL version.

Ubuntu (PostgreSQL 16):

# Update package index
sudo apt-get update

# Install pgcrypto (ships with the postgresql-16 package)
sudo apt-get install -y postgresql-16

# Install pgvector
sudo apt-get install -y postgresql-16-pgvector

RHEL 8/9 (PostgreSQL 16):

# Install the PostgreSQL repository (if not already configured)
sudo dnf install -y https://download.postgresql.org/pub/repos/yum/reporpms/EL-9-x86_64/pgdg-redhat-repo-latest.noarch.rpm

# Disable the built-in PostgreSQL module to avoid conflicts (RHEL 8/9)
sudo dnf -qy module disable postgresql

# Install pgcrypto (ships with the postgresql-contrib package)
sudo dnf install -y postgresql16-contrib

# Install pgvector build dependencies
sudo dnf install -y gcc make git postgresql16-devel

# Clone and build pgvector
git clone --branch v0.7.4 https://github.com/pgvector/pgvector.git
cd pgvector
make
sudo make install
cd ..
rm -rf pgvector

Note: Replace 16 with your actual PostgreSQL major version (for example 17) in the package names and --branch tag above. Adjust the pgdg-redhat-repo URL for your RHEL version (EL-8 vs EL-9) and architecture. Check the pgvector releases page for the latest stable version.

Enable the extensions

Connect to your PostgreSQL instance as a superuser and activate the extensions in the target database. Replace <your_database> with the actual database name.

-- Connect to the target database first
\c <your_database>

-- Required: encryption support used by SAS Retrieval Agent Manager
CREATE EXTENSION IF NOT EXISTS pgcrypto;

-- Recommended: vector similarity search for embedding storage
CREATE EXTENSION IF NOT EXISTS vector;

Verify that the extensions are active:

SELECT name, default_version, installed_version
FROM pg_available_extensions
WHERE name IN ('pgcrypto', 'vector');

Both extensions should show a value in installed_version.

For a non-interactive approach, such as a shell script or CI pipeline:

PGPASSWORD=<admin_password> psql \
  -h <db_host> \
  -U <admin_user> \
  -d <your_database> \
  -c "CREATE EXTENSION IF NOT EXISTS pgcrypto; CREATE EXTENSION IF NOT EXISTS vector;"

Secure the database connection

If your database requires SSL, provide the SSL certificate bundle as a Kubernetes secret in the same namespace as your SAS Retrieval Agent Manager deployment.

Obtain the root certificates

Platform Source
Azure DigiCert Global Root G2 (pem) and Microsoft RSA Root Certificate Authority 2017 (crt). See the Azure PostgreSQL TLS documentation.
AWS Download the bundle for your RDS region.
OpenShift (Crunchy Postgres Operator) Extract from the <clusterName>-cluster-cert secret. See the OpenShift deployment guide.

If an Azure .crt file is in DER format, convert it to PEM first:

openssl x509 -inform DER -in "Microsoft RSA Root Certificate Authority 2017.crt" -out msrsa2017.pem -outform PEM

To find which RDS region certificate you need:

# Find the region you need the RDS SSL bundle for
aws rds describe-db-instances --query 'DBInstances[*].[DBInstanceIdentifier,AvailabilityZone]' --output table

Construct the certificate bundle

The cert.pem secret key must contain a single PEM file that concatenates four components in the following order:

  1. Chain certificate (trustedcerts.pem)
  2. Intermediate certificate (ca.crt)
  3. Server certificate (tls.crt)
  4. Private key (tls.key)

The resulting file structure should look like this:

-----BEGIN CERTIFICATE-----
<trustedcerts.pem contents>
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
<ca.crt contents>
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
<tls.crt contents>
-----END CERTIFICATE-----
-----BEGIN RSA PRIVATE KEY-----
<tls.key contents>
-----END RSA PRIVATE KEY-----

Build the bundle with the following command:

cat trustedcerts.pem ca.crt tls.crt tls.key > combined-cert.pem

Create the Kubernetes secret

Upload the bundle as a secret with the key cert.pem:

# The correct namespace to store all SAS Retrieval Agent Manager Resources
kubectl create ns retagentmgr

# Create a secret with the PostgreSQL SSL bundle
kubectl create secret generic <your-secret-name> --from-file=cert.pem=combined-cert.pem -n retagentmgr

Note: It is critical to enter the name of the secret in the postgreSQLCertSecret key in the values file under global.configuration.vhub. For example, with this secret name, it would be: postgreSQLCertSecret: '<your-secret-name>'

Database initialization

SAS Retrieval Agent Manager automatically initializes the required databases during deployment unless specified otherwise. This requires database admin credentials in your values file.

Manual initialization

If you do not want to give SAS Retrieval Agent Manager database-admin-level access, set database initialization to false in your values file and initialize the databases separately before you install:

db:
  init:
    config:
      database:
        initializeDb: "False"

The manual initialization scripts require a PostgreSQL administrator only while the databases, roles, schemas, and required extensions are prepared. After they complete, SAS Retrieval Agent Manager can connect using its application-specific database credentials.

Follow the Manual Database Initialization guide for the required environment variables and Docker or bare-metal commands.

Next step

Continue to Install dependencies.