Troubleshooting Droplet‑to‑DigitalOcean Managed PostgreSQL Connection Failures
When a Droplet can’t connect to a Managed PostgreSQL database, the issue is often a firewall rule, missing trusted source, SSL mismatch, or network hiccup. This guide walks through a step‑by‑step diagnostic flow and offers concrete fixes.
21 Aug 2026, 05:16 UTC

Recognizable Condition
When a Droplet cannot establish a TCP connection to a Managed PostgreSQL instance, the error typically appears as psql: could not connect to server: Connection refused or could not connect to server: No route to host. The problem is usually local to the Droplet or the DigitalOcean control‑panel configuration, not the database itself.
Root Cause Table
| Cause | Typical Symptom |
|---|---|
| Outbound firewall blocks port 5432 | Connection timed out or refused, nc -zv reports failure. |
| Missing Trusted Source (IP or VPC) | SSL handshake fails, psql reports FATAL: database is not allowed to accept connections from this IP address. |
| SSL mismatch (client non‑SSL vs. server SSL‑only) | Authentication error: SSL error: SSL connection failed. |
| Network latency or packet loss | Intermittent connection drops, longer than expected timeouts. |
Ordered Diagnostic Checks
- Verify TCP reachability. From the Droplet, run:
If the command exits with status 0, the port is reachable. A non‑zero exit indicates a network or firewall issue. Risk: None.nc -zv <db-host> 5432 - Inspect the Droplet’s outbound firewall. Depending on the firewall in use:
Look for rules that drop or reject traffic to the database’s IP range on TCP port 5432. If you find a rule, you can temporarily allow traffic:# UFW ufw status verbose # iptables iptables -L -v -n
Replaceufw allow out to <db-ip> port 5432 proto tcp iptables -A OUTPUT -p tcp -d <db-ip> --dport 5432 -j ACCEPT<db-ip>with the actual private IP of the database instance. Risk: Opening the port may expose the Droplet to unwanted traffic if the rule is too permissive. - Confirm Trusted Sources in the Control Panel. Log in to the DigitalOcean dashboard, navigate to Databases → Settings → Trusted Sources. Ensure the Droplet’s public IP or its VPC subnet (e.g.,
10.0.0.0/24) is listed. If not, add it and wait a few seconds for propagation. Risk: Adding a subnet that is too broad may allow other Droplets to connect. - Test SSL‑only connection. Managed PostgreSQL enforces SSL by default. From the Droplet, try:
If the connection succeeds, SSL is not the problem. If it fails with an SSL error, the client may be misconfigured or the database’s TLS certificates may be missing.psql "host=<db-host> port=5432 dbname=defaultdb user=doadmin sslmode=require" - Check DNS resolution and latency. Resolve the database host and measure round‑trip time:
High latency (>200 ms) or packet loss may indicate network congestion. Risk: None.dig +short <db-host> ping -c 4 <db-host>
Fixes Tied to Findings
- Firewall blocked outbound traffic. Remove or modify the offending rule. Example for UFW:
For iptables, delete the rule:ufw delete deny out to <db-ip> port 5432 proto tcpiptables -D OUTPUT -p tcp -d <db-ip> --dport 5432 -j DROP - Missing Trusted Source. Add the Droplet’s IP or VPC subnet in the DigitalOcean UI. After adding, test connectivity again. If the Droplet is in a floating IP, use that address.
- SSL mismatch. In the PostgreSQL client configuration (e.g.,
~/.psqlrcor connection string), setsslmode=requireorprefer. If the client is a library (e.g., psycopg2), pass the appropriate SSL parameters. - Network instability. Verify that the Droplet and the database are in the same region or VPC. If they are in different regions, consider moving one of them or enabling a private network connection. You can also use DigitalOcean’s VPC to reduce latency.
Escalation Criteria
If all the above steps succeed but the client still cannot connect, or if the database reports a FATAL error unrelated to IP restrictions, the issue may be internal to DigitalOcean’s Managed PostgreSQL service. Gather the following before opening a support ticket:
- Output of
psql -h <db-host> -U doadmin -d defaultdb -p 5432 -c "SELECT version();" - Timestamp of the failed connection attempt.
- Result of
ufw status verboseoriptables -L -v -n. - Screenshot of the Trusted Sources list.
Include these artifacts in your ticket to expedite resolution.
Limitations & Verification
This guide assumes the Droplet runs a supported Linux distribution and that you have root or sudo access. It also presumes the Managed PostgreSQL instance is in the same DigitalOcean account. For databases in a different account, you must coordinate with that account’s administrator to add the Droplet’s IP to the trusted list.
After applying a change, re‑run the nc -zv test and the psql connection to confirm success. If the connection now works, the issue is resolved. If not, double‑check each step again or proceed to escalation.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.