Install Releem for PostgreSQL on AWS RDS and Aurora
Connect the Releem Agent to Amazon RDS for PostgreSQL or Amazon Aurora PostgreSQL. Configure one Agent for each DB instance endpoint, including the writer and any readers you want to monitor.
Prerequisites
Review PostgreSQL managed-service permissions: create the monitoring account with pg_monitor and pg_read_all_data. Do not run self-managed pg_hba_file_rules grants on RDS or Aurora; the internal rdsadmin role owns that view. Enable Enhanced Monitoring on the instance; it supplies system metrics. Confirm that the effective shared_preload_libraries list on the running instance contains pg_stat_statements so Releem can collect query data:
SHOW shared_preload_libraries;
If it is missing, add pg_stat_statements to the existing comma-separated list in the custom parameter group without removing other entries. For example, if the current value is pgaudit, set it to pgaudit,pg_stat_statements. Reboot when AWS reports a pending reboot.
Dashboard latency is required for a complete installation. Enable Performance Insights / CloudWatch Database Insights and create the pg_stat_statements extension in postgres, which the Agent uses for its statistics connection.
The Agent needs outbound HTTPS and access to the RDS endpoint on its database port. The RDS security group must accept that database connection from the Agent security group or exact Agent address. This applies to both the CloudFormation and EC2 installations.
Prepare the DB parameter group
Create a custom DB parameter group for the instance's engine family and assign it to the RDS instance. Both CloudFormation and EC2 installations need this group to apply recommended configuration; the CloudFormation template requires its name. Merge pg_stat_statements into shared_preload_libraries as described above (for Aurora, in the cluster group; see below), reboot if RDS reports a pending reboot, and confirm the group is In sync. A default group cannot be modified. Check whether other instances or clusters share the group; a change affects every resource using it.
If you intentionally use EC2 for monitoring only, the assigned group can remain unchanged when the required settings are active. Releem can show recommendations, but it cannot apply them through that installation until a custom group and the access below are in place. To apply a recommendation yourself, follow manual application for PostgreSQL on AWS RDS.
Aurora PostgreSQL parameter groups
For Aurora PostgreSQL, create both a custom DB parameter group for each instance and a custom DB cluster parameter group for the cluster. Attach both in AWS before applying recommendations. Enter the exact attached names in Releem; AWS-managed default groups cannot be modified. Leave the cluster group empty for non-Aurora RDS. Reboot an instance if AWS marks a change as pending reboot.
In Aurora PostgreSQL, shared_preload_libraries is a cluster-level parameter. Merge pg_stat_statements into it in the custom DB cluster parameter group, not the instance group, then reboot the writer and readers when AWS reports a pending reboot.
Use each Aurora instance identifier in DBID or AWS_RDS_DB, not the cluster endpoint, and run one Agent per instance. Recommendations can target either parameter group. Only the Agent targeting the writer changes cluster parameters; it needs rds:ModifyDBClusterParameterGroup in addition to rds:ModifyDBParameterGroup. Keep an Agent on the writer when you want to apply cluster recommendations.
Give the EC2 Agent access to the parameter group
Attach an EC2 IAM role with logs:Get*, rds:Describe*, ec2:Describe*, and cloudwatch:Get* for monitoring. To make Releem's Apply action available, grant rds:ModifyDBParameterGroup on the assigned custom group ARN (arn:aws:rds:[REGION]:[ACCOUNT_ID]:pg:[ASSIGNED_INSTANCE_PARAMETER_GROUP]). For the Aurora writer Agent, also grant rds:ModifyDBClusterParameterGroup on the assigned cluster group ARN (arn:aws:rds:[REGION]:[ACCOUNT_ID]:cluster-pg:[ASSIGNED_CLUSTER_PARAMETER_GROUP]). Granting these permissions does not apply a recommendation; you still choose and approve the change in Releem. Omit the write actions only when you intend to use a monitoring-only Agent and apply changes manually.
Automatic installation
Use the Releem CloudFormation template to run the Agent in AWS Fargate:
- Create the
releemdatabase account. - Open the Releem CloudFormation Quick Create page.
- Select the same AWS Region as the RDS instance.
- Enter the RDS instance ID, database user, security groups, subnets, the assigned DBParameterGroup, and a current
releem/releem-agent:[VERSION]image. Set QueryOptimization totrue. - Supply the API key and database password through AWS Secrets Manager ARNs when available.
- Create the stack and wait for
CREATE_COMPLETE.
Use these exact CloudFormation field values:
- DatabaseType:
postgresqlfor RDS PostgreSQL and Aurora PostgreSQL. The defaultmysqlselects the wrong collector. - DBID: the DB instance identifier, including for Aurora. Deploy one stack per instance; do not select a cluster endpoint.
- DBUser and DBPassword: the monitoring account. APIKey identifies the server in Releem.
- DBSSLMode:
true. The template defaultfalsemaps tosslmode=disable, and RDS for PostgreSQL 15 and later rejects unencrypted connections by default (rds.force_ssl=1).truemaps tosslmode=require. - DBParameterGroup: the exact attached custom instance group.
- DBClusterParameterGroup: the exact attached custom Aurora cluster group. Leave empty for non-Aurora RDS.
- Image, SecurityGroupIDs, SubnetIDs, and QueryOptimization: the image, network settings, and query collection choice described above.
The CloudFormation template will create roles to run Releem Agent with the following permissions:
- logs:Get*
- rds:Describe*
- cloudwatch:Get*
- ecr:GetAuthorizationToken
- ecr:BatchCheckLayerAvailability
- ecr:GetDownloadUrlForLayer
- ecr:BatchGetImage
- secretsmanager:GetSecretValue
- logs:CreateLogStream
- logs:PutLogEvents
- rds:ModifyDBParameterGroup
- rds:ModifyDBClusterParameterGroup
Review those change permissions before creating the stack. If the Agent must have monitoring-only AWS access, use the EC2 method with a read-only IAM role instead.
Manual installation
Install the Agent on an EC2 instance that can reach RDS. Attach the IAM role described above so the Agent can collect metrics and apply a configuration when you approve it. You can install the Agent directly on EC2 or run it in Docker.
Install directly on EC2
Open a private root shell and run this command. Replace the bracketed placeholders with your values.
RELEEM_INSTANCE_TYPE="aws/rds" RELEEM_PG_TYPE=1 RELEEM_AWS_REGION="[AWS_REGION]" RELEEM_AWS_RDS_DB="[RDS_INSTANCE_ID]" RELEEM_AWS_RDS_PARAMETER_GROUP="[ASSIGNED_INSTANCE_PARAMETER_GROUP]" RELEEM_PG_PASSWORD='[MONITORING_PASSWORD]' RELEEM_PG_LOGIN='releem' RELEEM_PG_SSL_MODE=true RELEEM_DB_MEMORY_LIMIT=0 RELEEM_API_KEY='[RELEEM_API_KEY]' RELEEM_CRON_ENABLE=1 RELEEM_QUERY_OPTIMIZATION=true bash -c "$(curl -L https://releem.s3.amazonaws.com/v2/install.sh)"
For Aurora PostgreSQL, include the attached cluster group:
RELEEM_INSTANCE_TYPE="aws/rds" RELEEM_PG_TYPE=1 RELEEM_AWS_REGION="[AWS_REGION]" RELEEM_AWS_RDS_DB="[AURORA_INSTANCE_ID]" RELEEM_AWS_RDS_PARAMETER_GROUP="[ASSIGNED_INSTANCE_PARAMETER_GROUP]" RELEEM_AWS_RDS_CLUSTER_PARAMETER_GROUP="[ASSIGNED_CLUSTER_PARAMETER_GROUP]" RELEEM_PG_PASSWORD='[MONITORING_PASSWORD]' RELEEM_PG_LOGIN='releem' RELEEM_PG_SSL_MODE=true RELEEM_DB_MEMORY_LIMIT=0 RELEEM_API_KEY='[RELEEM_API_KEY]' RELEEM_CRON_ENABLE=1 RELEEM_QUERY_OPTIMIZATION=true bash -c "$(curl -L https://releem.s3.amazonaws.com/v2/install.sh)"
Run one Agent per Aurora instance. Only the writer Agent applies cluster parameter recommendations.
Installer parameters
RELEEM_API_KEYis the API key for the Releem account, available on the Releem Portal Profile page.RELEEM_AWS_REGIONis the RDS Region.RELEEM_AWS_RDS_DBis the RDS or Aurora DB instance identifier, not a cluster endpoint.RELEEM_AWS_RDS_PARAMETER_GROUPis the parameter group assigned to the instance. Releem can modify a custom group only with separately approved IAM access.RELEEM_AWS_RDS_CLUSTER_PARAMETER_GROUPis the custom cluster group attached to Aurora. Omit it for non-Aurora RDS.RELEEM_PG_TYPE=1selects PostgreSQL.RELEEM_PG_LOGINandRELEEM_PG_PASSWORDconfigure the PostgreSQL connection.RELEEM_PG_SSL_MODE=truemaps tosslmode=require; omission orfalsemaps tosslmode=disable. It does not provideverify-fullhostname and certificate verification.RELEEM_DB_MEMORY_LIMITsets the database memory allocation in MB. The default0uses all available memory; set a limit when other software shares the server.RELEEM_HOSTNAMEoverrides the Dashboard server name.RELEEM_CRON_ENABLE=1enables daily Agent updates on EC2. Set it to0if you do not want scheduled updates.RELEEM_QUERY_OPTIMIZATION=trueenables query collection. Remove this flag for baseline monitoring only.
The EC2 installer writes the Agent configuration, including the monitoring password, to /opt/releem/releem.conf. Keep this file readable only by authorized administrators and the Agent service account.
Run on EC2 with Docker
Choose Docker or Docker Compose on the EC2 instance. The container uses the EC2 instance profile for AWS access. If the instance requires IMDSv2, set its metadata response hop limit to 2 or run the container with host networking before starting it; see AWS credentials for Docker on EC2.
Replace every bracketed value.
For Aurora PostgreSQL, set AWS_RDS_DB to the Aurora instance identifier and add -e AWS_RDS_CLUSTER_PARAMETER_GROUP="[ASSIGNED_CLUSTER_PARAMETER_GROUP]" to docker run, or AWS_RDS_CLUSTER_PARAMETER_GROUP: "[ASSIGNED_CLUSTER_PARAMETER_GROUP]" to Compose environment:. RELEEM_AWS_RDS_CLUSTER_PARAMETER_GROUP is an alias. Run one container per instance. Only the writer container applies cluster parameters; omit the cluster group for non-Aurora RDS.
Docker
docker run -d --name releem-agent \
-e RELEEM_API_KEY="[RELEEM_API_KEY]" \
-e RELEEM_HOSTNAME="[SERVER_NAME]" \
-e PG_USER="releem" \
-e PG_PASSWORD="[MONITORING_PASSWORD]" \
-e PG_SSL="true" \
-e INSTANCE_TYPE="aws/rds" \
-e AWS_REGION="[AWS_REGION]" \
-e AWS_RDS_DB="[RDS_INSTANCE_ID]" \
-e AWS_RDS_PARAMETER_GROUP="[ASSIGNED_INSTANCE_PARAMETER_GROUP]" \
-e RELEEM_QUERY_OPTIMIZATION="true" \
--restart unless-stopped \
releem/releem-agent:[VERSION_FROM_DOCKER_HUB]
Docker Compose
services:
releem-agent:
image: "releem/releem-agent:[VERSION_FROM_DOCKER_HUB]"
container_name: releem-agent
environment:
RELEEM_API_KEY: "[RELEEM_API_KEY]"
RELEEM_HOSTNAME: "[SERVER_NAME]"
PG_USER: "releem"
PG_PASSWORD: "[MONITORING_PASSWORD]"
PG_SSL: "true"
INSTANCE_TYPE: "aws/rds"
AWS_REGION: "[AWS_REGION]"
AWS_RDS_DB: "[RDS_INSTANCE_ID]"
AWS_RDS_PARAMETER_GROUP: "[ASSIGNED_INSTANCE_PARAMETER_GROUP]"
RELEEM_QUERY_OPTIMIZATION: "true"
restart: unless-stopped
docker compose up -d
Use a version listed on Docker Hub. Keep a Compose file containing credentials out of version control. The container uses the EC2 instance profile for AWS access, so attach the required IAM role to the EC2 instance.
PG_USER and PG_PASSWORD select the monitoring account; PG_SSL is the boolean SSL switch. AWS_REGION, AWS_RDS_DB, AWS_RDS_PARAMETER_GROUP, and AWS_RDS_CLUSTER_PARAMETER_GROUP are the Docker equivalents of the installer parameters. RELEEM_API_KEY identifies the server in Releem and RELEEM_HOSTNAME supplies its Dashboard name.
To monitor another RDS instance from the same EC2 VM, duplicate the Compose service. Give the second service and container unique names, then set its own RELEEM_HOSTNAME, AWS_RDS_DB, assigned parameter group, and database credentials. Start both services with docker compose up -d; each Agent should appear as a separate server in the Dashboard.
Expected result
After installation, the Dashboard should show Agent Status: Connected, current metrics, and latency data.
Verify the installation
Confirm the Agent connection, current metrics, a populated Latency graph, and query data in the Dashboard. Verify the effective shared_preload_libraries value and the pg_stat_statements extension in postgres. If you intend to apply a recommended configuration, also confirm that the assigned DB parameter group is custom and In sync and that the Agent has the approved parameter-group permissions. If any check fails, review the Agent logs and the troubleshooting steps below.
For Aurora, also confirm the exact attached custom cluster group, its status, and the writer Agent's rds:ModifyDBClusterParameterGroup access. Verify that each Agent targets its own DB instance identifier.
Troubleshooting
For a CloudFormation deployment, open CloudWatch → Log groups and select the Releem Agent log group. For an EC2 deployment, review the Agent logs; for Docker, run docker logs releem-agent.
Failed to read log stream ... RDSOSMetrics
Enable Enhanced Monitoring for the RDS instance. Confirm that the Agent identity has the documented CloudWatch Logs read access and that the instance is publishing the RDSOSMetrics stream. Restart only the Agent after correcting its AWS access.
The Dashboard has no latency data
Check Performance Insights / CloudWatch Database Insights for the instance. Verify the effective pg_stat_statements preload, extension setup, and monitoring permissions, then confirm that the Latency graph receives data after database activity.
PostgreSQL connection failed / password authentication failed
Confirm the database endpoint, user name, password, database, and SSL setting used by the Agent, and the security-group access from the Agent. Compare the account with PostgreSQL managed-service permissions. Update the credential in the Agent configuration or secret, then restart the Agent.
Connect: connection timed out
Confirm that the RDS security group accepts the database port from the Agent security group or exact Agent address. Check the Agent subnet route, network ACLs, DNS resolution, and the selected RDS endpoint. Do not open the database port to all sources.
The CloudFormation stack remains CREATE_IN_PROGRESS
Open the stack's Events tab and resolve the first failed or waiting resource. Confirm the selected subnets and security groups, Secrets Manager references, Fargate task startup, outbound HTTPS access, RDS connectivity, Enhanced Monitoring, and Database Insights. Confirm that DatabaseType is postgresql and DBSSLMode is true. Review the ECS service and stopped-task reason before retrying or replacing the stack.
EC2 Docker cannot obtain AWS credentials
Check the EC2 instance metadata options and the container's network mode as described in AWS credentials for Docker on EC2.
Aurora apply fails because the cluster parameter group is missing or does not match
Create and attach a custom DB cluster parameter group. Set DBClusterParameterGroup, AWS_RDS_CLUSTER_PARAMETER_GROUP, or RELEEM_AWS_RDS_CLUSTER_PARAMETER_GROUP to that exact name. Default groups cannot be modified. Check the writer Agent's scoped rds:ModifyDBClusterParameterGroup access.
Cluster parameters are not applied on a reader
Only the Agent targeting the writer modifies cluster parameters. Keep an Agent on the writer instance and verify its configured instance identifier and attached groups.
For other failures, use Troubleshoot the Releem Agent. Correct the reported permission, network, or configuration issue before retrying the installation.