Skip to main content

Reference

Compatibility & support matrix

The PostgreSQL versions, managed-database providers, extensions, permissions, and architectures Elevarq Signals is supported and tested against.

This page documents the PostgreSQL versions, managed-database providers, extensions, permissions, and network requirements Elevarq Signals supports. The matrix distinguishes supported (tested + green in CI), best-effort (works, monitored by support, no SLA), unsupported (known gaps), and planned (on the roadmap, not yet shipped).

The runtime signalsctl doctor command (and the --json form for automation) reports compatibility gaps against the live target. See Operator preflight below.

PostgreSQL major versions

MajorStatusNotes
14SupportedCatalog mappings, regression tests, release smoke.
15SupportedSame as 14.
16SupportedSame as 14.
17SupportedIncludes the pg_stat_progress_vacuum PG-17 column additions.
18SupportedLatest tested major; release smoke runs against PG 18 too.
19+ExperimentalPG 19 is accepted with a warning so operators on rolling early-adopter clusters aren't blocked. Collectors that depend on PG-19-only columns are gated; the rest run unchanged.
12, 13UnsupportedEOL upstream. No catalog mapping. Collector refuses to start with unsupported_pg_major.
≤ 11UnsupportedOut of scope.

Managed-database providers

ProviderStatusNotes
Self-hosted PostgreSQLSupportedThe reference deployment.
AWS RDS for PostgreSQLSupportedStandard read permissions; pg_monitor role required for some signal collectors. The rds_superuser role is NOT required.
AWS RDS Aurora PostgreSQL-compatibleBest-effortAurora's catalog implements PG-compatible system views; common collectors work. The pg_stat_statements_info.dealloc column (used by pgss_capacity_v1) is present in Aurora. Aurora-Serverless's elastic-IOPS surface is invisible to the collector — operator-declared values in the Elevarq Analyzer's TargetContext are the right path.
Google Cloud SQL for PostgreSQLSupportedStandard read permissions. Assign pg_monitor directly to the monitoring role; the collector does NOT require superuser (nor cloudsqlsuperuser).
AlloyDBBest-effortPG-compatible catalog. Storage / IOPS abstraction is invisible to the collector; same TargetContext path applies.
Azure Database for PostgreSQL — Flexible ServerSupportedStandard read permissions; azure_pg_admin is NOT required.
Azure Database for PostgreSQL — Single ServerUnsupportedRetired upstream.
Crunchy Bridge / Supabase / Render / NeonBest-effortPG-compatible; community-reported working. No automated CI coverage.
Citus / CockroachDB / YugabyteDBUnsupportedDistributed SQL forks; catalog and pg_stat semantics diverge.

PostgreSQL extensions

The collector reads catalogs / functions that are part of vanilla PostgreSQL OR managed-provider standard images. Some collectors have OPTIONAL upgrades when an extension is installed.

ExtensionRequired?Used byBehaviour when missing
pg_stat_statementsRecommendedpgss_capacity_v1, pgss_top_statements_v1, planner-corpus driversWorkload-shape collectors skip; informational warning.
pgstattupleOptionalpg_class_storage_v1 bloat upgradeFalls back to pg_class.relpages-only estimate.
hypopgNot used at collection time(Analyzer-side index advice)N/A — collector doesn't reach for hypopg.
pg_partman / pg_repack / etc.Not used—Collector doesn't depend on management extensions.

Extension presence is captured by the pg_extensions_v1 collector; the Elevarq Analyzer consumes it to gate rules.

Permissions

Elevarq Signals is designed to run as a non-superuser role.

Minimum read permissions

NeedGrant
ConnectGRANT CONNECT ON DATABASE <db> TO signals;
Read public schemaGRANT USAGE ON SCHEMA public TO signals;
Read all tablesGRANT SELECT ON ALL TABLES IN SCHEMA public TO signals; + ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT SELECT ON TABLES TO signals;
Read pg_stat_statementsGrant membership in pg_monitor (or pg_read_all_stats + pg_read_server_files on PG 14+).

Roles by environment

EnvironmentRecommended role
Self-hostedpg_monitor membership + SELECT on application schemas.
RDS PostgreSQLpg_monitor (available since PG 10).
RDS Aurorards_pg_monitor (the Aurora equivalent).
Cloud SQLpg_monitor (grant it directly to the monitoring role; cloudsqlsuperuser is not required and over-privileged).
AlloyDBpg_monitor plus the AlloyDB-specific read role if present.
Azure FlexMembership in the azure_pg_admin_role group or the dedicated read role.

The signalsctl doctor command's role_safe check refuses to run as superuser by default (override with SIGNALS_ALLOW_UNSAFE_ROLE=1 for evaluation only — the override is refused in env: prod).

Network requirements

  • Inbound to Postgres: 5432/tcp (or operator-configured port) from the Signals collector. No additional ports.
  • Outbound from Signals: NONE in v1. The collector is a pull-only service against the target Postgres. Snapshots are written to a local SQLite store; export is operator-driven.
  • TLS: sslmode=verify-full recommended in production; verify-ca acceptable; prefer emits a warning (target identity not verified). disable only with SIGNALS_ALLOW_INSECURE_PG_TLS=1 and never in env=prod.

Container / Kubernetes compatibility

SurfaceStatus
Container image (multi-arch: linux/amd64, linux/arm64)Supported. Distroless base. Non-root UID 65532.
Docker / Docker ComposeSupported for local development. A reference Docker Compose example ships with the distribution.
Kubernetes ≥ 1.27Supported. A Helm chart is provided. See the Kubernetes production install guidance for production-profile rules.
Kubernetes < 1.27Best-effort. Chart should render but no CI coverage.
Helm 3Supported.
Helm 2Unsupported.
OpenShiftBest-effort. Chart uses standard PSP-free patterns; SCC mapping is operator-side.

Architecture

ArchStatus
linux/amd64Supported.
linux/arm64Supported. Verified on Apple Silicon dev machines + AWS Graviton.
OtherUnsupported. No CI coverage.

Operator preflight

The signalsctl doctor command runs read-only checks against the configured target and reports compatibility gaps in the closed check-id schema (config_valid, target_reachable, role_safe, collector_prerequisites, snapshot_freshness, store_writable).

Run before deployment:

signalsctl doctor --config config.yaml

JSON output for automation:

signalsctl doctor --config config.yaml --json

A failing check produces a status: "fail" entry with a closed reason string + the next operator action. Non-zero exit code signals at least one failed check.

Footnotes

  • Sales / SE quick-answer: if the prospect's stack is in the "Supported" column for PG version + managed provider + Kubernetes version, Elevarq Signals fits. Best-effort answers should be flagged for a brief technical exchange before commitment.
  • Unsupported is final: distributed forks (Citus, Cockroach, Yugabyte) and Single-Server Azure are out of scope by design, not by gap.
  • Planned entries land in this matrix as Supported or Best-effort when CI coverage exists.

Run Signals

docker pull ghcr.io/elevarq/signals