DigitalOcean Managed Databases, at a glance
DigitalOcean Managed Databases is a fully managed database cluster service for PostgreSQL, MySQL, Kafka, MongoDB, Valkey and OpenSearch. Duskwatch is an independent iPhone app for DigitalOcean, in development; it shows whether each cluster is online, has a standby, faces maintenance or has gone read-only, sends a push when one fails over, and never shows a password or connection string.
Updated
Nodes, standbys and failovers
A cluster with one node and no standby is one hardware fault away from downtime. The cluster screen leads with that kind of fact: its status, how many nodes it has, whether a standby can take over, and any recent failover. A single-node production database shows "No standby node", with a note when the plan is too small to add one.
db-prod · PostgreSQL · 2 nodes
"db-prod failed over" · acme-prod · A standby took over at 03:40.
"db-prod is powered off" · acme-prod · Since 02:14.
If the primary node fails, a standby node is automatically promoted to replace it. Standby nodes are only supported on plans with 2 GB of RAM or more.
DigitalOcean docs: add standby nodes (PostgreSQL) (external link), verified
Read-only mode
When a cluster runs out of room, DigitalOcean can stop accepting writes to protect it. Your app then fails on every insert while reads still work, which is easy to misread as a bug in your code. The app shows "Writes are blocked" when DigitalOcean reports the cluster read-only, suggests adding storage or deleting data, and with alerts on sends a push: "db-prod is read-only · Writes are failing." Another push follows when it is back online.
For MongoDB clusters, DigitalOcean blocks further writes when a cluster's disk reaches 97% capacity.
Maintenance windows and backups
Pending maintenance appears as a calm line on the cluster, not an alarm. When the cluster has a single node, it says "Maintenance will restart the only node", which is the case worth planning around. Engine versions near end of life get a finding with the number of days left. The backups section shows the last backup, the next one, a running backup's progress, and flags "No backups" or "Backups are overdue".
Each cluster has a weekly four-hour maintenance window, and updates may begin at any time during it. DigitalOcean builds an updated cluster, replicates the data and updates DNS, which changes the cluster's underlying IP address; it describes no downtime but possible brief latency.
DigitalOcean docs: schedule updates (PostgreSQL) (external link), verified
Trusted sources and Add my IP
Trusted sources decide who may connect. The security section grades them in words, from "Only your DigitalOcean resources can connect" to "Open to any IP address", and flags "TLS is not required". For Valkey, it also warns when "Writes fail when memory is full" or "Data is lost on restart".
Add my IP is the one database action. It finds your network's public IPv4 address, shows it on a sheet that names the cluster and team, and adds it after a tap and Face ID. You can also enter an address or a range of /24 or narrower, for a laptop or an office. Looking up your IP is the only call the app makes outside DigitalOcean when you have alerts off. The database still needs its username and password, which the app never asks for.
Trusted sources can be IPv4 addresses and CIDR ranges, droplets, tags, apps and Kubernetes clusters; IPv6 rules are not supported, and a cluster allows up to 100 rules.
DigitalOcean docs: secure a PostgreSQL cluster (external link), verified
| Shown | Never shown |
|---|---|
| Status, engine, version, region and node count | Passwords |
| Standbys, read-only nodes and recent failovers | Connection strings or URIs |
| Maintenance, backups and recent events | Database users' credentials |
| Trusted sources, TLS setting and the apps that use it | Your data, queries or logs |
What Duskwatch doesn't do here
- No passwords, connection strings or user credentials, ever.
- No database charts or metrics; DigitalOcean shows them under Insights in its control panel.
- No database logs, which DigitalOcean does not offer through its API.
- No creating, resizing, forking or deleting clusters, and no removing trusted sources.
- No query console.
Questions
Will I know if my database fails over?
With alerts on, yes: a push says that a standby took over and when. The cluster screen also shows a failover from the last 24 hours as a finding.
Why did my managed database go read-only?
Usually because its disk is nearly full; for MongoDB, DigitalOcean blocks writes at 97% capacity. Add storage or delete data, and the push tells you when it is back online.
How do I add my current IP to a database from my phone?
Open the cluster, choose Add my IP, check the address on the sheet and confirm with Face ID. It adds your network's public IPv4 address to the trusted sources.
Does it show database passwords or connection strings?
Never. The app does not display, cache or store them, and it has no field that could carry one.
When is the next maintenance?
The cluster screen shows its maintenance window and any pending update. It warns when maintenance will restart the only node.