Project-local PostgreSQL inside the VM #7

Open
opened 2026-10-01 09:20:28 +00:00 by jan · 0 comments
Owner

Motivation

The work project talks to a shared PostgreSQL server. The agent should test
against a database without reaching the shared one: no network path to it, no
team credentials in the VM, nothing it can damage.

Good news from the project side: its DB layer creates its own tables on an
empty database, so an empty server is enough to start.

Proposal

  • PostgreSQL installed in the project template (#5 (Project templates on top of the agent template)).
  • Started when the sandbox starts (kit startup command or the agent
    wrappers), listening on loopback only, with a throwaway local user.
  • Optional seed: a pg_dump file from a data mount (#6 (Read-only data mounts with a disposable writable layer)),
    restored on create and on an explicit agentbox db reset.
  • The briefing says where the database is and that it is disposable.

Host database access (documented escape hatch, not the default)

sbx policy allow network accepts IP:port over TCP, scoped per sandbox, so
agentbox allow 10.0.0.5:5432 would technically work. The docs should say
clearly what that means: the agent can then do whatever the credentials it
holds allow. Recommend a dedicated read-only database role, never personal
credentials.

Done when

e2e: a sandbox from a template with PostgreSQL has a running server on
loopback after start, and a seed dump is restored.

## Motivation The work project talks to a shared PostgreSQL server. The agent should test against a database without reaching the shared one: no network path to it, no team credentials in the VM, nothing it can damage. Good news from the project side: its DB layer creates its own tables on an empty database, so an empty server is enough to start. ## Proposal - PostgreSQL installed in the project template (#5 (Project templates on top of the agent template)). - Started when the sandbox starts (kit startup command or the agent wrappers), listening on loopback only, with a throwaway local user. - Optional seed: a `pg_dump` file from a data mount (#6 (Read-only data mounts with a disposable writable layer)), restored on `create` and on an explicit `agentbox db reset`. - The briefing says where the database is and that it is disposable. ## Host database access (documented escape hatch, not the default) `sbx policy allow network` accepts `IP:port` over TCP, scoped per sandbox, so `agentbox allow 10.0.0.5:5432` would technically work. The docs should say clearly what that means: the agent can then do whatever the credentials it holds allow. Recommend a dedicated read-only database role, never personal credentials. ## Done when e2e: a sandbox from a template with PostgreSQL has a running server on loopback after start, and a seed dump is restored.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
jan/agentbox#7
No description provided.