querybara profiles
- CLI
- PostgreSQL
- MySQL
- MariaDB
- MongoDB
- Redis / Valkey
- Elasticsearch
querybara profiles manages the connection profiles in the local store, the same profiles the
desktop app shows. Profiles you add here appear in the app, and the other way round. Nothing here
prints a secret: show reports only whether each secret is saved.
Usage: querybara profiles [options] [command]
manage saved connection profiles (shared with the desktop app)
Options: -h, --help show help for a command
Commands: list [options] list saved profiles show [options] <profile> show one profile; secrets are never printed, only whether they are saved add [options] <name> <uri> save a profile from a connection URI import-uri [options] <uri> save a profile from a pasted URI, named after its host and database remove|rm [options] <profile> remove a profile with its saved secrets and history export [options] <file> export profiles to a passphrase-encrypted file import [options] <file> import profiles from a passphrase-encrypted export file help [command] display help for commandList and show
Section titled “List and show”Usage: querybara profiles list [options]
list saved profiles
Options: --json print as JSON -h, --help show help for a commandUsage: querybara profiles show [options] <profile>
show one profile; secrets are never printed, only whether they are saved
Arguments: profile profile name or id
Options: --json print as JSON -h, --help show help for a commandquerybara profiles listquerybara profiles show shop-prod --jsonshow also names the environment variables that supply the profile’s password, such as
QUERYBARA_PASSWORD_SHOP_PROD or QUERYBARA_PASSWORD.
Add a profile
Section titled “Add a profile”Usage: querybara profiles add [options] <name> <uri>
save a profile from a connection URI
Arguments: name profile name uri connection URI; a password in it is saved only with --password-policy save
Options: --environment <env> environment label (choices: "dev", "test", "staging", "production") --folder <path> folder id or path such as Team/Prod (created when missing) --password-policy <policy> save (sealed with QUERYBARA_PASSPHRASE), session or ask. Default: save a password in the URI when QUERYBARA_PASSPHRASE is set, else ask (choices: "save", "session", "ask") --read-only lock the profile read-only: writes are refused --confirm-writes ask before every write --tls <mode> TLS mode for this run: disable, require, verify-ca or verify-full --engine <engine> for mysql:// URIs of MariaDB servers (choices: "mysql", "mariadb") --tag <tag> add a tag; repeatable --replace replace a profile with the same name -h, --help show help for a command
Examples: QUERYBARA_PASSPHRASE=... querybara profiles add prod "postgres://app:secret@db:5432/app" --environment production querybara profiles add dev "mysql://[email protected]/app" --folder LocalUsage: querybara profiles import-uri [options] <uri>
save a profile from a pasted URI, named after its host and database
Arguments: uri connection URI
Options: --name <name> profile name (default: host[:port]/database) --environment <env> environment label (choices: "dev", "test", "staging", "production") --folder <path> folder id or path such as Team/Prod (created when missing) --password-policy <policy> save (sealed with QUERYBARA_PASSPHRASE), session or ask. Default: save a password in the URI when QUERYBARA_PASSPHRASE is set, else ask (choices: "save", "session", "ask") --read-only lock the profile read-only: writes are refused --confirm-writes ask before every write --tls <mode> TLS mode for this run: disable, require, verify-ca or verify-full --engine <engine> for mysql:// URIs of MariaDB servers (choices: "mysql", "mariadb") --tag <tag> add a tag; repeatable --replace replace a profile with the same name -h, --help show help for a commandquerybara profiles add shop-prod "postgres://[email protected]:5432/shop" --environment production --read-onlyimport-uri names the profile after its host, port and database unless you pass --name.
A profile added from a URI that states no TLS settings has TLS off, as in the desktop app. Pass
--tls to save another mode:
Saving the password
Section titled “Saving the password”The desktop app seals saved passwords with the OS keychain, which the CLI cannot use. The CLI
seals the passwords it saves with the passphrase in QUERYBARA_PASSPHRASE instead.
--password-policy |
What happens |
|---|---|
save |
The password is saved, sealed with QUERYBARA_PASSPHRASE |
session |
The password is remembered for the session, not saved |
ask |
The password is asked for every time |
Without --password-policy, a password in the URI is saved when QUERYBARA_PASSPHRASE is set;
otherwise the profile asks for it and the CLI warns that it was not saved. save without
QUERYBARA_PASSPHRASE is an error.
QUERYBARA_PASSPHRASE="$STORE_PASSPHRASE" querybara profiles add shop-prod "postgres://app:$DB_PASSWORD@db.example.com:5432/shop" --environment productionLater runs need the same QUERYBARA_PASSPHRASE to read the password back.
Safety settings
Section titled “Safety settings”--environment productionmakes every write to the profile ask for confirmation, in the CLI and in the app.--confirm-writesasks before every write.--read-onlylocks the profile: writes are refused.
Remove a profile
Section titled “Remove a profile”Usage: querybara profiles remove|rm [options] <profile>
remove a profile with its saved secrets and history
Arguments: profile profile name or id
Options: -y, --yes do not ask for confirmation -h, --help show help for a commandquerybara profiles remove shop-oldquerybara profiles rm shop-old --yesRemoving a profile also removes its saved secrets and its history.
Export and import
Section titled “Export and import”Usage: querybara profiles export [options] <file>
export profiles to a passphrase-encrypted file
Arguments: file file to write
Options: --profile <profile> export this profile; repeatable (default: all) --include-secrets include the saved secrets that are readable here -h, --help show help for a command
The passphrase comes from QUERYBARA_EXPORT_PASSPHRASE or a prompt.Usage: querybara profiles import [options] <file>
import profiles from a passphrase-encrypted export file
Arguments: file file to read
Options: --replace replace profiles that already exist (same id) -h, --help show help for a command
The passphrase comes from QUERYBARA_EXPORT_PASSPHRASE or a prompt.The export file is encrypted with a passphrase (AES-256-GCM, with a key derived by scrypt). The
passphrase comes from QUERYBARA_EXPORT_PASSPHRASE or a prompt, which asks twice when you export.
The file holds secrets only when you pass --include-secrets, and then only the saved secrets the
CLI can read on this machine.
querybara profiles export team-profiles.export --profile shop-prod --profile shop-stagingQUERYBARA_EXPORT_PASSPHRASE="$EXPORT_PASSPHRASE" querybara profiles import team-profiles.export --replaceRelated
Section titled “Related”Documents Querybara 0.1.1 · built frombc9f5aa