Skip to content
Stackship documentation Svenska

Vector stores (Qdrant)Users

Connect to a vector store

Find a vector store's endpoints and API key, and connect to it from a workload, from outside the cluster, or with Qdrant's dashboard.

Requires: qdrantcluster/read, qdrantcluster/readSecrets

A client needs two things: an endpoint and the API key. Showing the endpoints needs qdrantcluster/read; showing the API key needs qdrantcluster/readSecrets as well, which Owner, Contributor and Databases Operator have.

Find the endpoints

Open Vector Store in the sidebar and choose the vector store. On its Overview, the Connection Details card has Endpoints with the button Show connection info. Each time you show them, it is recorded in the vector store's activity log.

Endpoint Form Reachable from
REST http://qdrant-<name>.<namespace>:6333 Inside the Kubernetes cluster
gRPC qdrant-<name>.<namespace>:6334 Inside the Kubernetes cluster
REST (external) http://<address>:6333 Outside, through the load balancer, when it is on and has an address
gRPC (external) <address>:6334 The same
Dashboard https://<hostname>/dashboard Outside, through the HTTPS ingress, when it is on

<namespace> is the Kubernetes namespace of the vector store's resource group; the portal shows the full names. Through the HTTPS ingress the REST API itself is at https://<hostname>; gRPC is not served there. The hostname is also in Configuration → Networking & Security.

Inside the cluster the connection is plain HTTP and gRPC, without TLS.

Get the API key

In the same card, API Key has Show API key, Hide API key and Copy API key. Showing it is recorded in the activity log. When API key authentication is off, the card says API key auth is disabled.

With the CLI, read it through the API:

bash
stsh api GET /boundaries/<boundary-id>/resourcegroups/<resource-group>/resources/qdrantclusters/<name>/apikey

Note

On a vector store placed on a cluster that is connected to the platform as an Agent cluster, the key cannot be shown: Show API key ends with Error Fetching API Key.

Clients send the key in the api-key header, or as Authorization: Bearer <key>; Qdrant's client libraries take it as an api_key or apiKey option.

Connect from a workload

Apps, functions and container instances in the same boundary and on the same cluster reach the internal endpoints: the boundary's network rules let its resource groups talk to each other — see Network rules. Workloads in other boundaries cannot reach the internal endpoints.

Important

Workloads in other boundaries can reach the HTTPS endpoint: their network rules allow outbound HTTPS to any address, and the ingress controller reaches every boundary. While the HTTPS ingress is on, which the create wizard makes the default, the API key is all that keeps them out. See Between boundaries.

Keep the API key out of configuration:

  1. Put the key in a vault as a secret — see Add a secret.
  2. Reference the secret from the workload, for example as QDRANT_API_KEY — see Secrets in apps and functions or Secrets in container instances.
  3. Put the REST endpoint in an ordinary setting, for example the environment variable QDRANT_URL.

An app reads its secrets from /secrets/env.json; a function gets them as environment variables with the prefix STSH_, such as STSH_QDRANT_API_KEY. In a Python app:

python
import json
import os

from qdrant_client import QdrantClient

secrets = json.load(open("/secrets/env.json"))
client = QdrantClient(url=os.environ["QDRANT_URL"], api_key=secrets["QDRANT_API_KEY"])

After you rotate the key, write the new value into the secret and restart the workload: it reads its secrets only when it starts.

Connect from outside the cluster

Use the HTTPS endpoint where you can. The load balancer carries no TLS, so the API key crosses the network in plain text on every request; keep it for clients that need gRPC, and narrow it with Allowed CIDR blocks — see Networking and the API key.

bash
curl -H "api-key: $QDRANT_API_KEY" https://<hostname>/collections

Open the dashboard

Qdrant ships a web dashboard for browsing collections and running queries. When the HTTPS ingress is on, Show connection info lists it as Dashboard. The dashboard talks to the same API, so it needs the API key too. It is not offered over the load balancer, which would send the key without TLS.