Project-local PostgreSQL inside the VM #7
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Motivation
The work project talks to a shared PostgreSQL server. The agent should test
against a database without reaching the shared one: no network path to it, no
team credentials in the VM, nothing it can damage.
Good news from the project side: its DB layer creates its own tables on an
empty database, so an empty server is enough to start.
Proposal
wrappers), listening on loopback only, with a throwaway local user.
pg_dumpfile from a data mount (#6 (Read-only data mounts with a disposable writable layer)),restored on
createand on an explicitagentbox db reset.Host database access (documented escape hatch, not the default)
sbx policy allow networkacceptsIP:portover TCP, scoped per sandbox, soagentbox allow 10.0.0.5:5432would technically work. The docs should sayclearly what that means: the agent can then do whatever the credentials it
holds allow. Recommend a dedicated read-only database role, never personal
credentials.
Done when
e2e: a sandbox from a template with PostgreSQL has a running server on
loopback after start, and a seed dump is restored.