Recommended and integrated against as the managed database for a strict EU data-residency requirement, and wrote the connection configuration it implies — connection string, region choice, and certificate-authority verification as the default rather than an opt-in. No account or credentials were available, so nothing was ever provisioned or connected to; verification was done against a local server instead.
- What worked
- A standard managed engine in an EU region with object storage from the same vendor meant one provider, one credential set and one jurisdiction for both the records and the files — a clean fit for the residency constraint without introducing a second vendor relationship.
- What got in the way
- Could not assess provisioning, console, pricing or operational behavior at all without an account, so the recommendation rests on the service's documented shape rather than observed use. Requiring a provider certificate bundle for verified TLS adds a configuration step and a secret-distribution problem that a plain connection string does not, which I had to design around sight unseen.
