Skip to content
dbexplore

Aiven for PostgreSQL

No superuser, on purpose, and that costs you nothing here

Aiven documents why it withholds superuser and routes extension installs through a whitelist instead. DBExplore was built to run on a read-only role everywhere, so the real question on Aiven is not privilege, it is which plan tier you are on.

What goes wrong

Tools that assume superuser

Aiven does not grant it. avnadmin creates databases, roles and extensions and replicates logically; the rest arrives through an Aiven-supplied extension. Anything that expects to be superuser fails outright.

The plan tier is your RPO

Hobbyist and startup plans are a single node, and Aiven puts the exposure on a severe failure at up to five minutes or one WAL file. Business adds a standby, premium adds two. The tier, not the database, decides.

Pooling is a thing you turn on

PgBouncer needs a startup plan or higher and answers on its own pooled URI in transaction mode. Half your connections are then counted somewhere the other half are not.

What DBExplore does about it

The operational detail behind this: the read-only role you create, and what it is allowed to read.

A monitoring role is all it takes

No superuser, no host access, no shell. Where a signal needs an extension the service has not enabled, the collector names the gap instead of publishing a number it guessed.

Discovery that reads the tier

Node count and standby presence, replication shape and lag, the pooler in front, and the extensions actually installed, read from the catalog on first connection and re-checked on a schedule.

Index advice and plan regressions

Index candidates ranked from catalog statistics and query history. A regression fires on a structural plan change plus a measured slowdown against the best prior plan, never on a timing wobble.

Evidence for the tier argument

Retained session history and a signed, tamper-evident ledger mean the case for moving off a single node is an incident record rather than a recollection.

Aiven for PostgreSQL: questions we get first

Do you need superuser on Aiven?

No. A read-only monitoring role created by avnadmin is enough, and nothing DBExplore does sits behind a privilege Aiven withholds. Where an extension is absent, the advisor names it rather than degrading quietly.

Is there an Aiven integration or marketplace listing?

Neither. No named connector, no partnership, no listing. DBExplore connects over the service URI like any other client and works out the rest from the catalog.

What leaves the database?

Metrics, catalog metadata, execution plans, and query text with literals scrubbed on the agent before it is sent. Parameter capture is off by default. Row data never leaves.

Can DBExplore change anything without approval?

Not by default. Every tenant starts at approve. Disruptive actions always need two approvers, and every mutating action passes a fail-closed policy gate first.

Run DBExplore on your Aiven for PostgreSQL.

We onboard teams in small batches. Tell us about your fleet and we will reach out when a seat opens. One email, no drip campaign.