# Monitoring rds postgres with pmm docker container

**URL:** <https://forums.percona.com/t/monitoring-rds-postgres-with-pmm-docker-container/7172>\
**Category:** PMM 1.x\
**Created:** [August 26, 2019, 12:43pm UTC](https://forums.percona.com/t/monitoring-rds-postgres-with-pmm-docker-container/7172 "2019-08-26T12:43:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![peru\_uparkar](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/peru_uparkar/32/7298_2.png) [@peru\_uparkar](https://forums.percona.com/u/peru_uparkar)\
**Post date:** [August 26, 2019, 12:43pm UTC](https://forums.percona.com/t/monitoring-rds-postgres-with-pmm-docker-container/7172/1 "2019-08-26T12:43:20Z")

</div>

I am trying to setup rds postgres monitoring with pmm docker contaner. As part of setup , I created aws user plus following user policy plus separate db user with necessary permissions.

{  
“Version”: “2012-10-17”,  
“Statement”: [{  
“Sid”: “Stmt1508404837003”,  
“Effect”: “Allow”,  
“Action”: [  
“rds:DescribeDBInstances”,  
“cloudwatch:GetMetricStatistics”,  
“cloudwatch:ListMetrics”  
],  
“Resource”: [“_"]  
},  
{  
“Sid”: “Stmt1508410723001”,  
“Effect”: “Allow”,  
“Action”: [  
“logs:DescribeLogStreams”,  
“logs:GetLogEvents”,  
“logs:FilterLogEvents”  
],  
“Resource”: ["arn:aws:logs:_:_:log-group:RDSOSMetrics:_”]  
}  
]

}

* * *

## CREATE USER pmm\_user with ENCRYPTED PASSWORD ‘xxxxzzzzzyyyy’; grant rds\_superuser to pmm\_user;

Finally when I try to add rds postgres database using PMM GUI → Add Remote Postgresql Instance, I run into following error

[LEFT][COLOR=#D8D9DA]

Any comments /suggestions ?

---

<div class="post-metadata">

**Author:** ![peru\_uparkar](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/peru_uparkar/32/7298_2.png) [@peru\_uparkar](https://forums.percona.com/u/peru_uparkar)\
**Post date:** [August 26, 2019, 12:52pm UTC](https://forums.percona.com/t/monitoring-rds-postgres-with-pmm-docker-container/7172/2 "2019-08-26T12:52:08Z")

</div>

One more thing, db conection from pmm docker container to rds postgresql database using psql client works with no issues.

---

<div class="post-metadata">

**Author:** ![peru\_uparkar](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/peru_uparkar/32/7298_2.png) [@peru\_uparkar](https://forums.percona.com/u/peru_uparkar)\
**Post date:** [August 27, 2019, 10:33am UTC](https://forums.percona.com/t/monitoring-rds-postgres-with-pmm-docker-container/7172/3 "2019-08-27T10:33:18Z")

</div>

I think this is related to SSL configuration on pmm docker container. I checked the rds postgresql logs, and found following lines relevant to above error.

2019-08-26 20:13:28 UTC:10.40.72.117(41640):pmm\_user@postgres:[20063]:FATAL: no pg\_hba.conf entry for host “10.40.72.117”, user “pmm\_user”, database “postgres”, SSL off 2019-08-26 20:19:45 UTC:10.40.72.117(52212):pmm\_user@postgres:[28180]:LOG: connection authorized: user=pmm\_user database=postgres SSL enabled (protocol=TLSv1.2, cipher=ECDHE-RSA-AES256-GCM-SHA384, bits=256, compression=off)

Issue is when I try to do “Add a remote PostgreSQL instance” using “\_PMM Add Instance”, it trys to open db connection with SSL option disabled. And thats the reason the db connection is failing.

{{ [LEFT][COLOR=#D8D9DA]

}}

---

<div class="post-metadata">

**Author:** ![peru\_uparkar](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/peru_uparkar/32/7298_2.png) [@peru\_uparkar](https://forums.percona.com/u/peru_uparkar)\
**Post date:** [August 27, 2019, 8:25pm UTC](https://forums.percona.com/t/monitoring-rds-postgres-with-pmm-docker-container/7172/4 "2019-08-27T20:25:11Z")

</div>

I was able to resolve this issue, by using pmm-admin commands from the docker container. Here is what I end up doing,

yum update -y  
yum install initscripts

pmm-admin config --server 127.0.0.1 --server-insecure-ssl --client-name 10.xx.xx.xxx

pmm-admin add postgresql --host=[postgres-dev.xxxxyyyyzzz.us-east-1.rds.amazonaws.com](http://postgres-dev.xxxxyyyyzzz.us-east-1.rds.amazonaws.com) --user=pmm\_user --password=‘secret’ --port=5432 --sslmode require
