A public image of your app. Set the port it listens on, a size that fits the app, minimum replicas of at least one in production, and an autoscaling trigger.
High availability on, Connection pooler on, and an access control list limited to the addresses your containers connect from — never the default 0.0.0.0/0.
Keep at least one replica in production. Scale-to-zero suits staging and preview environments.
Too many database connections during a spike
New requests fail to connect.
Connect through the PgBouncer pooler, not directly.
Database primary fails
Writes stop until failover.
Turn on high availability, which adds a replica.
Database open to the internet
Credential-stuffing and data exposure.
Restrict the ACL, and use a dedicated user with only the rights the app needs.
Regional outage
The app is down.
Keep the database, containers and storage in one region for latency, and regularly copy database dumps and critical files to another region so you can rebuild there.