Docs / Guides

Postgres

Run read-only queries for AI agents through temporary Postgres roles that expire automatically, with no database password in the agent.

For each query the broker creates a temporary login role that inherits a read-only base role and expires on its own, runs the query as that role, and returns the rows.

Action

ActionResourceParameters
DB_READdatabase namequery: a single SELECT or WITH statement

Anything else, including multiple statements, is refused before it reaches the database.

Setup

  1. Create a base role with only the read access agents need:
    CREATE ROLE pastkeys_readonly NOLOGIN;
    GRANT CONNECT ON DATABASE analytics TO pastkeys_readonly;
    GRANT USAGE ON SCHEMA public TO pastkeys_readonly;
    GRANT SELECT ON ALL TABLES IN SCHEMA public TO pastkeys_readonly;
  2. Seal an admin DSN that can create roles and store it as the postgres credential:
    postgres://admin:[email protected]:5432/postgres
  3. Optionally set POSTGRES_READ_ROLE if your base role has another name.

Lifetime and cleanup

Each role is VALID UNTIL 15 minutes after creation by default (set per rule with credential_ttl). A background reaper drops expired role objects; tune it with POSTGRES_REAP_INTERVAL.