Skip to main content
See Configuration for ~/.formal/config.toml.

Authentication

List Resources

Interactive TUI with:
  • ↑/k - Move up
  • ↓/j - Move down
  • enter - Connect to resource
  • / - Filter resources
  • q - Quit
  • ? - Show help

Connect to Resources

Databases (PostgreSQL, MySQL, MongoDB)

Then connect with your database client:
Formal automatically injects your credentials - no username/password needed! Note that the database name is required for the connection to be successful. You can also use the --launch argument to launch the appropriate CLI program after connecting (for example psql or ssh), e.g.

Specify Native User

To request a Native User instead of the Resource’s assigned default, append its label using formal@<native_user_label>.
See Native Users for label selection and policy controls.

Specify Resource Hostname

If a resource has multiple Resource Hostnames (for example, separate reader and writer endpoints), target one by appending @<hostname-name> to the resource name:
Resource hostname targeting is currently supported for PostgreSQL and MySQL resources.
Connect with your database client as usual, using the port from the formal connect output:
Use the same RESOURCE_NAME@HOSTNAME_NAME target to disconnect:

SSH

This updates your ~/.ssh/config automatically.

Configure SSH without write access

Formal adds the following block to the top of ~/.ssh/config on your first SSH connection:
If Formal cannot modify this file, add the block manually before any Host entries. Then run formal connect <resource-name> again. Formal writes subsequent SSH resource changes to ~/.formal/ssh_config.

Kubernetes

This updates your ~/.kube/config to route through the Connector.

Disconnect

Decrypt Data

Decrypt Formal-encrypted data:

S3 Operations

The Formal s3 command automatically routes traffic to the right Connector so your users don’t have to worry about formatting the right parameters for S3. Interact with S3 through Formal:
See AWS CLI S3 commands for more operations.