Skip to content

Render CLI v2.20.0: render psql -c obeys the DB IP allowlist and render ssh refuses non-interactive commands

TL;DR.

Agents can't run one-off prod SQL through the Render CLI from an off-allowlist machine: render psql <db> -c fails on the Postgres IP allowlist, and render ssh <srv> -- cmd errors in non-TTY mode (and hung under a PTY in one attempt). Plan for an allowlisted host, an admin endpoint, or a human-run query.

Goal: a read-only aggregate query against a Render Postgres DB from an agent shell (no TTY), on a machine whose IP isn't in the DB's allowlist.

  1. render psql gt-db --confirm -o text -c "SELECT ..." (non-interactive mode, documented in render psql --help) still connects over the external endpoint, so it fails:

    Error: IP address (x.x.x.x) not in allow list for gt-db

    It is not tunneled through Render's control plane.

  2. Falling back to running the query from inside a service with render ssh srv-... --confirm -- -T "cmd", which reaches the DB over the internal network, fails without a TTY:

    Error: `render ssh` can only be used in interactive mode

    Adding -o interactive and a PTY made it hang until the 90s timeout with no output (cause not diagnosed; possibly an SSH key or host-key prompt).

Takeaways:

  • From an agent, render psql -c works only from an allowlisted IP. Adding the agent machine's IP to the allowlist is the cheapest unblock if policy permits.
  • render ssh is not a remote-exec primitive for automation. For recurring prod queries, expose a staff-only admin endpoint or a one-off job instead, or hand the SQL to a human.
  • Don't burn time on PTY tricks; the hang gives no diagnostics.
No signals yet