> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tensor9.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Cloud SQL for PostgreSQL

> Cloud SQL for PostgreSQL APIs with Cloud Adapter.

This page describes how Cloud SQL for PostgreSQL maps to services in the environment where the application runs. Some profiles adapt origin API calls; others translate infrastructure or document target-native behavior.

## Supported environments

| Environment | Mapping |
| ----------- | ------- |
| AWS         | API     |
| Azure       | API     |

API means the profile adapts origin API behavior. Infrastructure means the profile changes provisioned resources or documents a target-native alternative without promising an origin API endpoint. Check the operation and capability tables for the behavior your application depends on.

## How the targets compare

Each row compares a capability of Cloud SQL for PostgreSQL with its adaptation on each target.
A dash means this profile does not state the capability for that target.

### Cloud Adapter

| Capability   | Cloud SQL for PostgreSQL | AWS  | Azure |
| ------------ | ------------------------ | ---- | ----- |
| API coverage | full                     | high | high  |

## On AWS

### RDS PostgreSQL

| Operation                         | Area    | Support      | Depth        | Notes                                                                                                                                                                                       |
| --------------------------------- | ------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Connector / Auth Proxy handshake  | Connect | Partial      | Common       | The adapter handles the short-lived client certificate handshake required by Google's connector libraries before they connect.                                                              |
| IAM database authentication       | Connect | Partial      | Full surface | The build identifies the target's database-token authentication flow, which differs from Google's.                                                                                          |
| Extensions and preload libraries  | Control | Partial      | Most usage   | The build identifies unavailable extensions and differences in shared\_preload\_libraries.                                                                                                  |
| authorizedNetworks                | Control | Out of scope | Most usage   | Authorized networks are flagged at build time. The target uses security groups, which this mapping does not configure.                                                                      |
| databaseFlags                     | Control | Partial      | Most usage   | Flags become an RDS parameter group. The build identifies settings RDS does not accept.                                                                                                     |
| instances.insert / patch / delete | Control | Supported    | Common       | The instance becomes an RDS database instance with mapped compute and storage capacity and a target-compatible engine version. The build identifies unsupported size or version selections. |
| users.insert / delete             | Control | Partial      | Most usage   | Users are created and deleted with SQL because the target has no managed users API.                                                                                                         |
| PostgreSQL wire protocol          | Data    | Supported    | Common       | The application continues using the PostgreSQL protocol with a managed PostgreSQL server.                                                                                                   |

Cloud SQL for PostgreSQL becomes an RDS PostgreSQL instance, and the application keeps the PostgreSQL protocol.

### Connection setup and instance changes

The source management API and the database protocol serve different purposes. The adapter creates and configures the target instance and handles the connector certificate exchange; SQL then uses the target engine. Verify the complete connection sequence with the actual client library, including token acquisition and certificate renewal.

### Moving the database

Provisioning a target instance does not copy data, users, or backup history. Transfer the required database state, stop or coordinate writes for the final cutover, and test reconnection after target failover. Select the target engine version and settings together with the application's extension and authentication requirements.

### Compatibility differences

The adapter handles the short-lived client certificate handshake used by Google's connector libraries and Auth Proxy. Users are created with SQL. Supported extensions and preload libraries differ between the services, so the build identifies requirements RDS cannot provide.

## On Azure

### PostgreSQL Flexible Server

| Operation                         | Area    | Support      | Depth        | Notes                                                                                                                                                                                           |
| --------------------------------- | ------- | ------------ | ------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Connector / Auth Proxy handshake  | Connect | Partial      | Common       | The adapter handles the short-lived client certificate handshake required by Google's connector libraries before they connect.                                                                  |
| IAM database authentication       | Connect | Partial      | Full surface | The build identifies the target's database-token authentication flow, which differs from Google's.                                                                                              |
| Extensions and preload libraries  | Control | Partial      | Most usage   | The build identifies extensions the target does not provide.                                                                                                                                    |
| authorizedNetworks                | Control | Out of scope | Most usage   | Authorized networks are flagged at build time. The target has network rules, which this mapping does not configure.                                                                             |
| databaseFlags                     | Control | Supported    | Most usage   | Database flags become server parameters.                                                                                                                                                        |
| instances.insert / patch / delete | Control | Supported    | Common       | The instance becomes a PostgreSQL Flexible Server with mapped compute and storage capacity and a target-compatible engine version. The build identifies unsupported size or version selections. |
| users.insert / delete             | Control | Partial      | Most usage   | Users are created and deleted with SQL because the target has no managed users API.                                                                                                             |
| PostgreSQL wire protocol          | Data    | Supported    | Common       | The application continues using the PostgreSQL protocol with a managed PostgreSQL server.                                                                                                       |

Cloud SQL for PostgreSQL becomes an Azure PostgreSQL Flexible Server, and the application keeps the PostgreSQL protocol. Database flags become server parameters.

### Connection setup and instance changes

The source management API and the database protocol serve different purposes. The adapter creates and configures the target instance and handles the connector certificate exchange; SQL then uses the target engine. Verify the complete connection sequence with the actual client library, including token acquisition and certificate renewal.

### Moving the database

Provisioning a target instance does not copy data, users, or backup history. Transfer the required database state, stop or coordinate writes for the final cutover, and test reconnection after target failover. Select the target engine version and settings together with the application's extension and authentication requirements.

### Compatibility differences

The adapter handles the certificate handshake used by Google's connector libraries and Auth Proxy. Users are created with SQL, and the target's allowed extension set still applies.

## Existing data and credentials

Selecting a backend does not copy existing data, credentials or access policies. Plan and verify migration separately before changing an application's endpoint. Do not assume an identifier, credential or encrypted value from the origin service works unchanged on the target.

## Configure, tune and debug

Start with [setup](/cloud-adapter/getting-started/overview) and [configuration](/cloud-adapter/configuration/overview). Use [tuning](/cloud-adapter/tuning/overview) to understand supported request tags, [debugging](/cloud-adapter/debugging/overview) to investigate a request, and [High Fidelity Cloud Emulators](/cloud-adapter/local-testing/overview) to validate a bounded reproduction.
