Share a copy (attach)
The agent gets in. The key does not.
kling db up pg -name crmkling db role crm -ro -name agent # a read-only rolekling run -image toolchain -name a1 -egress allowlist -allow example.org -allow-execkling db attach a1 crm -role agent # a1 gets a placeholder in PGPASSWORDkling db detach a1 crm # out, and its sessions cutInside a1:
psql "host=crm.db.internal user=agent dbname=appdb sslmode=disable"How it works
Section titled “How it works”a1’s credential proxy fills in the password when it connects.- On every connection the daemon checks that the copy exists, is running, is
readyand has the same owner. If not, the agent gets08006. - Freezing, stopping or deleting the copy cuts the open sessions.
- On macOS it goes through the daemon’s link broker.
The read-only role
Section titled “The read-only role”LOGIN NOSUPERUSER NOBYPASSRLS, CONNECTION LIMIT 5, SELECT only, a 5 s statement_timeout. It is not carried over to child copies: fork and undo remove it.
In the repo: docs/db.md: model A · docs/postgres.md