> ## Documentation Index
> Fetch the complete documentation index at: https://www.towbar.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Datastores

> Run supported databases and caches with persistent storage and recovery.

Datastores are supported database and cache engines that Towbar configures with persistent storage, connection details, health checks, and backup and restore. Use a [Service](/docs/services) for any other OCI image.

Use the [Datastore manifest](/docs/datastores/manifest) to review every declaration field. The [engine guides](/docs/databases) show required runtime inputs and supported versions. [Backups](/docs/backups) and [restores](/docs/restores) cover recovery.

## Supported types

| Type                           | Use it for            | Towbar behavior                                                                             |
| ------------------------------ | --------------------- | ------------------------------------------------------------------------------------------- |
| `postgres`, `mysql`, `mariadb` | Relational databases  | Readiness checks, persistent data volume, native backup and fresh-target restore            |
| `mongodb`                      | Document databases    | Authenticated health checks, persistent data volume, native backup and fresh-target restore |
| `redis`, `dragonfly`, `keydb`  | Redis-compatible data | Password protection, persistent snapshot, backup and fresh-target restore                   |
| `clickhouse`                   | Analytical databases  | Authenticated checks, persistent data, native backup and restore                            |

Managed engines have reviewed digest-pinned defaults. Custom managed images must use a digest and the supported major version. See [Engine guides](/docs/databases) for versions, architectures, declarative runtime inputs, and restore boundaries.

<div className="towbar-doc-screenshot">
  <div className="towbar-product-light">
    <img src="https://mintcdn.com/avgeek/EGkEWLTQnOwecqNx/assets/release-v2/resource-overview-light.jpg?fit=max&auto=format&n=EGkEWLTQnOwecqNx&q=85&s=e1a9514326964a2d84d38f271762833e" alt="Datastore state and the latest deployment attempt are shown separately." width="3200" height="1800" loading="lazy" data-path="assets/release-v2/resource-overview-light.jpg" />
  </div>

  <div className="towbar-product-dark">
    <img src="https://mintcdn.com/avgeek/EGkEWLTQnOwecqNx/assets/release-v2/resource-overview-dark.jpg?fit=max&auto=format&n=EGkEWLTQnOwecqNx&q=85&s=f283ea8f30c29ca0e7661ec83f90b3a5" alt="Datastore state and the latest deployment attempt are shown separately." width="3200" height="1800" loading="lazy" data-path="assets/release-v2/resource-overview-dark.jpg" />
  </div>

  <p>Datastore state and the latest deployment attempt are shown separately.</p>
</div>

## Add a database

<CodeGroup>
  ```yaml title="towbar.yml" theme={"system"}
  version: 2
  environments:
    production: {}
  ```

  ```yaml title=".towbar/datastores/database.datastore.yml" theme={"system"}
  id: database
  name: Primary database
  type: postgres
  container:
    network: app-network
    resources:
      cpus: 1
      memory: 1g
  access:
    sshTunnel:
      hostPort: 15432
  secrets:
    runtime:
      - POSTGRES_USER
      - POSTGRES_DB
      - POSTGRES_PASSWORD
  environments:
    production:
      server: 192.0.2.10
  ```
</CodeGroup>

Register the server, then save values for the declared keys under **Datastore →
Settings → Secrets**. The manifest contains their names, while production and
staging keep independent encrypted values in Towbar. Each [database
guide](/docs/databases) lists the required keys and initialization behavior for
its engine.

Deploy the datastore, wait for its health check to pass, and verify connectivity from the intended client.

## Connect privately

Services and datastores on the same host can share a named network. The datastore ID
becomes its alias unless you set another one:

```yaml title=".towbar/datastores/database.datastore.yml" highlight={1-5} theme={"system"}
container:
  network: app-network
  networkAlias: database
access:
  sshTunnel:
    hostPort: 15432
```

Towbar creates a missing bridge network and reuses an existing one. The SSH
tunnel port binds only to the server's `127.0.0.1`; it does not create a public
route.

## Persist data

Every datastore receives a managed data volume. Deployment and image rollback are not database migration tools: plan engine upgrades and schema compatibility separately.

Changing `POSTGRES_PASSWORD` in Towbar does not rotate the password already stored inside an existing database. Coordinate that change with the database before replacing the running datastore.

## Back up and restore

All eight managed engine presets support Towbar-managed backup and restore. Enable an S3, Cloudflare R2, or Google Cloud Storage runtime integration, reference its provider in the [backup policy](/docs/backups), and verify a fresh-target restore before relying on it. Read the [restore procedure](/docs/restores) before production recovery.
