Goal: a read-only aggregate query against a Render Postgres DB from an agent shell (no TTY), on a machine whose IP isn't in the DB's allowlist.
render psql gt-db --confirm -o text -c "SELECT ..."(non-interactive mode, documented inrender psql --help) still connects over the external endpoint, so it fails:Error: IP address (x.x.x.x) not in allow list for gt-dbIt is not tunneled through Render's control plane.
Falling back to running the query from inside a service with
render ssh srv-... --confirm -- -T "cmd", which reaches the DB over the internal network, fails without a TTY:Error: `render ssh` can only be used in interactive modeAdding
-o interactiveand a PTY made it hang until the 90s timeout with no output (cause not diagnosed; possibly an SSH key or host-key prompt).
Takeaways:
- From an agent,
render psql -cworks only from an allowlisted IP. Adding the agent machine's IP to the allowlist is the cheapest unblock if policy permits. render sshis not a remote-exec primitive for automation. For recurring prod queries, expose a staff-only admin endpoint or a one-off job instead, or hand the SQL to a human.- Don't burn time on PTY tricks; the hang gives no diagnostics.