Overview
There is no separate free-tier construct. UseRdsInstance with free-tier-eligible settings, or scaffold the whole application on the Tinkerer tier, which applies those settings for you.
Free-tier eligibility
AWS changed its free tier in 2025. What an account gets depends on when it was created:- Older accounts carry the classic 12-month service allowances (750 hours per month of
db.t4g.micro, 20 GB of GP3 storage, 20 GB of backup storage, single-AZ only). - Newer accounts get a credit-based free plan instead of those allowances.
Provision through the CLI
The Tinkerer tier is Fjall’s free-tier path. It scaffolds at4g.micro instance with Multi-AZ off, no proxy, no read replica, and a VPC with no NAT gateway.
--tier on fjall add database requires --type as well, because each tier describes each database type differently. Valid tiers: tinkerer, lightweight, standard, resilient, enterprise.
Resource class
Basic usage
instanceType takes the bare class.size form (t4g.micro), not the
db.-prefixed form AWS uses in its free-tier tables. The construct passes the
value straight to new InstanceType(...), so a db. prefix produces an
invalid instance class.Free-tier settings
Database Insights is a separate question. It defaults to on in
standard mode, which uses the default 7-day retention and carries no charge, so leaving it enabled stays inside the free tier. Set databaseInsights: false only if you want the feature off.
Network placement
The construct puts the instance in aPRIVATE_WITH_EGRESS subnet unless you set publiclyAccessible: true, in which case it uses a PUBLIC subnet.
A private-with-egress subnet needs a NAT gateway, which costs roughly $32 per month and is never free. A free-tier VPC therefore has no NAT gateway, and the database has to sit in a public subnet. This is exactly what the Tinkerer tier does.
Configuration options
Core properties
Storage
Backup and maintenance
Optional features
Security defaults
RdsInstance applies these regardless of tier, and none of them cost anything on the free tier:
- Storage encryption with KMS
- GP3 storage
- SSL/TLS enforced through the parameter group
- Generated credentials in Secrets Manager
- IAM database authentication (
iamAuthentication, on by default, granted per user withgrantIamConnect) - Deletion protection, plus a
SNAPSHOTremoval policy
Network access
Methods
Complete example
Staying inside the allowance
- Run one instance. 750 hours per month covers a single
db.t4g.microrunning continuously. - Set
allocatedStorage: 20and leavemaxAllocatedStoragealone. Autoscaling only fires when the instance fills up. - Set
multiAz: false,proxy: falseandreadReplica: false. - Cut
backupRetentionto 7 days. Backup storage above the allowance is billed. - Skip the NAT gateway. It is the single largest non-free cost in a small stack.
- Tear the stack down before the allowance ends.
deletionProtectiondefaults totrue, so set it tofalsefirst, or runfjall destroy.
Upgrade path
When the free tier stops fitting, change the same properties in place. Moving the instance into a private subnet also requires a NAT gateway in the VPC.Adding a proxy moves the client-facing port to the engine default (
5432),
because AWS gives CreateDBProxy no port parameter. If you also set a custom
port, the construct emits a synth warning and getHostPort() returns the
proxy’s port, not the instance’s.Cost once the allowance ends
Indicative on-demand pricing inus-east-1. Check the AWS pricing calculator for your region.
Use cases
Good for:- Development and throwaway environments
- Proofs of concept
- Learning and experimentation
- CI test databases
- Production workloads
- Anything needing high availability
- Applications needing consistent performance
- Databases larger than 20 GB
Next Steps
Tinkerer Pattern
Scaffold the whole free-tier stack in one command
RDS Instance
Configure a production-grade PostgreSQL instance
RDS Aurora
Scale up to a managed Aurora cluster
Database Factory
Create databases with the DatabaseFactory pattern