← Lakefront

Data

Databases, buckets
and secrets.

The stateful half of an application, provisioned into your own account with the same push-button experience as the stateless half, priced honestly before you commit.

Databases · new
Provision a database
PostgreSQL 17SQL Server 2022
Cloud
Azure · eastus
Compute
D2ds_v5 · 2 vCPU
Storage
128 GiB
High availability
zone-redundant
Compute
$142
Storage
$18
Est. / month
$160
Credentials are written into your Key Vault. Lakefront never stores a copy it could read.

Managed databases, in your account

PostgreSQL and SQL Server on Azure or AWS, each with its own isolated stack. Pick the shape you want and Lakefront prices it live from the provider’s own rate card before anything is created.

  • Live cost estimatesCompute, storage and high availability, itemised, before you press create.
  • Credentials you holdConnection details land in your Key Vault, not in a Lakefront database.
  • Wired to your servicesAttach a database to a service and the environment variables appear.
Databases · new
Provision a database
PostgreSQL 17SQL Server 2022
Cloud
Azure · eastus
Compute
D2ds_v5 · 2 vCPU
Storage
128 GiB
High availability
zone-redundant
Compute
$142
Storage
$18
Est. / month
$160
Credentials are written into your Key Vault. Lakefront never stores a copy it could read.

Object storage with a browser

Azure Blob and Amazon S3 buckets, provisioned the same way and billed by what you actually use. The in-app explorer mints a short-lived signed URL per click, so browsing your objects never means handing Lakefront a standing key.

Storage · acme-invoices
acme-invoicesBlob · eastus
Objects
184k
Size
412 GiB
Est. / month
$9.40
2026/08/INV-88214.pdf182 KB
2026/08/INV-88215.pdf176 KB
2026/08/manifest.json4 KB
Browsed with a short-lived signed URL, minted per click and never stored.

A vault that maintains itself

Store secrets once and let them rotate on a schedule. Bulk-import an existing .env file and Lakefront detects which values are secret; the rest stay plain configuration you can read at a glance.

Secrets
checkout-apiauto-rotate
DATABASE_URL
v14 · rotated 2d ago
Current
STRIPE_SECRET_KEY
v9 · rotates in 12d
Current
REDIS_PASSWORD
v22 · rotating now
Swapping
04:00:02 generate REDIS_PASSWORD v23
04:00:09 swap · both versions valid
04:01:14 revoke v22 · no failed connections

Bring the configuration you already have

Paste an existing .env file and Lakefront works out which values are secret, encrypts those before storing them, and leaves the rest as plain configuration you can read at a glance.

Import .env
18 variables detected6 marked secret
DATABASE_URL••••••••••secret
STRIPE_SECRET_KEY••••••••••secret
NEXT_PUBLIC_APP_URLhttps://acme.devplain
LOG_LEVELhttps://acme.devplain
Secret values are encrypted before they are stored and never rendered back into the page.
  • Every managed resource is provisioned by its own stack, so one failure never strands another.
  • Deleting a resource in Lakefront deletes it in your cloud. There is no shadow copy.

Deploy it into your own cloud.