Connect to a vector store
Find a vector store's endpoints and API key, and connect to it from a workload, from outside the cluster, or with Qdrant's dashboard.
Requires: qdrantcluster/read, qdrantcluster/readSecrets
A client needs two things: an endpoint and the API key. Showing the endpoints needs
qdrantcluster/read; showing the API key needs qdrantcluster/readSecrets as well, which Owner,
Contributor and Databases Operator have.
Find the endpoints
Open Vector Store in the sidebar and choose the vector store. On its Overview, the Connection Details card has Endpoints with the button Show connection info. Each time you show them, it is recorded in the vector store's activity log.
| Endpoint | Form | Reachable from |
|---|---|---|
| REST | http://qdrant-<name>.<namespace>:6333 |
Inside the Kubernetes cluster |
| gRPC | qdrant-<name>.<namespace>:6334 |
Inside the Kubernetes cluster |
| REST (external) | http://<address>:6333 |
Outside, through the load balancer, when it is on and has an address |
| gRPC (external) | <address>:6334 |
The same |
| Dashboard | https://<hostname>/dashboard |
Outside, through the HTTPS ingress, when it is on |
<namespace> is the Kubernetes namespace of the vector store's resource group; the portal shows the
full names. Through the HTTPS ingress the REST API itself is at https://<hostname>; gRPC is not
served there. The hostname is also in Configuration → Networking & Security.
Inside the cluster the connection is plain HTTP and gRPC, without TLS.
Get the API key
In the same card, API Key has Show API key, Hide API key and Copy API key. Showing it is recorded in the activity log. When API key authentication is off, the card says API key auth is disabled.
With the CLI, read it through the API:
stsh api GET /boundaries/<boundary-id>/resourcegroups/<resource-group>/resources/qdrantclusters/<name>/apikeyNote
On a vector store placed on a cluster that is connected to the platform as an Agent cluster, the key cannot be shown: Show API key ends with Error Fetching API Key.
Clients send the key in the api-key header, or as Authorization: Bearer <key>; Qdrant's client
libraries take it as an api_key or apiKey option.
Connect from a workload
Apps, functions and container instances in the same boundary and on the same cluster reach the internal endpoints: the boundary's network rules let its resource groups talk to each other — see Network rules. Workloads in other boundaries cannot reach the internal endpoints.
Important
Workloads in other boundaries can reach the HTTPS endpoint: their network rules allow outbound HTTPS to any address, and the ingress controller reaches every boundary. While the HTTPS ingress is on, which the create wizard makes the default, the API key is all that keeps them out. See Between boundaries.
Keep the API key out of configuration:
- Put the key in a vault as a secret — see Add a secret.
- Reference the secret from the workload, for example as
QDRANT_API_KEY— see Secrets in apps and functions or Secrets in container instances. - Put the REST endpoint in an ordinary setting, for example the environment variable
QDRANT_URL.
An app reads its secrets from /secrets/env.json; a function gets them as environment variables
with the prefix STSH_, such as STSH_QDRANT_API_KEY. In a Python app:
import json
import os
from qdrant_client import QdrantClient
secrets = json.load(open("/secrets/env.json"))
client = QdrantClient(url=os.environ["QDRANT_URL"], api_key=secrets["QDRANT_API_KEY"])After you rotate the key, write the new value into the secret and restart the workload: it reads its secrets only when it starts.
Connect from outside the cluster
Use the HTTPS endpoint where you can. The load balancer carries no TLS, so the API key crosses the network in plain text on every request; keep it for clients that need gRPC, and narrow it with Allowed CIDR blocks — see Networking and the API key.
curl -H "api-key: $QDRANT_API_KEY" https://<hostname>/collectionsOpen the dashboard
Qdrant ships a web dashboard for browsing collections and running queries. When the HTTPS ingress is on, Show connection info lists it as Dashboard. The dashboard talks to the same API, so it needs the API key too. It is not offered over the load balancer, which would send the key without TLS.