Skip to main content
Version: 1.0.0

pgAdmin on Aruba Cloud

Deploy pgAdmin 4 — the leading open-source PostgreSQL administration tool — on Aruba Cloud using Terraform and cloud-init. pgAdmin is installed from the official pgAdmin apt repository in web mode, served by Apache on port 80.

Provider version: arubacloud/arubacloud ~> 1.0 | Terraform: ≥ 1.9


Introduction​

pgAdmin 4 is a comprehensive GUI for managing PostgreSQL databases. This example provisions a dedicated pgAdmin instance on Aruba Cloud with:

  • pgAdmin 4 installed from the official pgAdmin apt repository (web mode)
  • Apache configured automatically by the pgAdmin setup script
  • Port 80 restricted to admin_cidr — pgAdmin must never be exposed to the public internet
  • Admin email and password configured at bootstrap time

Security note: pgAdmin has access to all PostgreSQL databases you add to it. Always restrict admin_cidr to your specific management IP and use a strong password. Consider pairing this example with the WireGuard VPN so pgAdmin is only reachable from your VPN tunnel.


Architecture Overview​


Infrastructure Created​

ResourceName patternDescription
arubacloud_projectpgadmin-prodProject container
arubacloud_vpcpgadmin-prod-vpcVirtual Private Cloud
arubacloud_subnetpgadmin-prod-subnetBasic subnet
arubacloud_securitygrouppgadmin-prod-vm-sgSecurity group
arubacloud_securityrulepgadmin-prod-vm-sshSSH ingress
arubacloud_securityrulepgadmin-prod-vm-admin-uiAdmin UI ingress TCP 80
arubacloud_elasticippgadmin-prod-vm-eipVM public IP
arubacloud_blockstoragepgadmin-prod-boot20 GB boot disk (Performance)
arubacloud_keypairpgadmin-prod-keypairSSH public key
arubacloud_cloudserverpgadmin-prod-vmCloudServer VM

Estimated Monthly Cost​

ResourceSpecEst. cost/mo
CloudServer VMCSO1A2 — 1 vCPU / 2 GB~€9
Boot disk20 GB Performance~€3
Elastic IP—~€3
Total~€15/mo

Requirements​

  • Terraform ≥ 1.9
  • ArubaCloud Terraform Provider ~> 1.0
  • An ArubaCloud account with OAuth2 API credentials
  • An SSH key pair
  • One or more PostgreSQL servers reachable from the VM

Variables​

Required​

VariableDescription
arubacloud_client_idArubaCloud OAuth2 client ID
arubacloud_client_secretArubaCloud OAuth2 client secret
ssh_public_keySSH public key content
pgadmin_emailLogin email address for pgAdmin
pgadmin_passwordLogin password for pgAdmin (min 8 chars)

Optional​

VariableDefaultDescription
app_name"pgadmin"Short name used in all resource names
environment"prod"Environment label
location"ITBG-Bergamo"ArubaCloud region
zone"ITBG-1"Availability zone
billing_period"Hour""Hour" or "Month"
vm_flavor"CSO1A2"CloudServer flavor
vm_image"LU22-001"Boot disk image (Ubuntu 22.04 LTS)
vm_disk_size_gb20Boot disk size in GB
ssh_cidr"0.0.0.0/0"CIDR for SSH — restrict in production
admin_cidr"0.0.0.0/0"CIDR for web UI — always restrict

Outputs​

OutputDescription
pgadmin_urlpgAdmin web interface URL
pgadmin_emailLogin email address
vm_public_ipPublic IP address of the VM
ssh_commandSSH command to connect to the VM

Deployment Instructions​

1. Clone and navigate​

git clone https://github.com/arubacloud/terraform-arubacloud-examples.git
cd terraform-arubacloud-examples/pgadmin

2. Configure variables​

cp terraform.tfvars.example terraform.tfvars

Set credentials, email, password, and restrict CIDRs:

pgadmin_email = "admin@example.com"
pgadmin_password = "your-strong-password"
admin_cidr = "203.0.113.42/32"
ssh_cidr = "203.0.113.42/32"

3. Deploy​

terraform init
terraform plan
terraform apply

Bootstrap takes approximately 5–8 minutes (pgAdmin package download + Apache setup).

4. Open pgAdmin​

terraform output pgadmin_url

Log in with pgadmin_email and pgadmin_password. pgAdmin 4 opens at /pgadmin4.

5. Add a PostgreSQL server​

In the pgAdmin UI: Object → Register → Server

  • General → Name: any friendly name
  • Connection → Host: IP or hostname of your PostgreSQL server
  • Connection → Port: 5432
  • Connection → Username / Password: your PostgreSQL credentials

The pgAdmin VM must be able to reach the PostgreSQL server on TCP port 5432. Ensure the PostgreSQL server's security group or firewall allows inbound connections from the pgAdmin VM IP.


Security Recommendations​

  1. Always restrict admin_cidr. pgAdmin stores PostgreSQL credentials — never expose it to 0.0.0.0/0 in production.

  2. Use VPN access. The most secure setup is to keep admin_cidr set to your WireGuard VPN tunnel CIDR and access pgAdmin only from within the VPN. See the WireGuard example.

  3. Use SSH tunnelling as an alternative. If you prefer not to expose port 80 at all, set admin_cidr = "127.0.0.1/32" and access pgAdmin via an SSH tunnel:

    ssh -L 5050:localhost:80 ubuntu@<vm-ip>
    # Then open http://localhost:5050/pgadmin4 in your browser

Troubleshooting​

pgAdmin page not loading​

sudo systemctl status apache2
sudo cat /var/log/apache2/error.log | tail -20
sudo cat /var/log/cloud-init-output.log | tail -30

Cannot connect to PostgreSQL​

From the pgAdmin VM, verify TCP connectivity:

nc -zv <postgres-host> 5432

Check that the PostgreSQL pg_hba.conf allows connections from the pgAdmin VM IP, and that any security group or firewall on the PostgreSQL server permits port 5432.


References​