Skip to content

querybara profiles

  • CLI
  • PostgreSQL
  • MySQL
  • MariaDB
  • MongoDB
  • Redis / Valkey
  • Elasticsearch

querybara profiles manages the connection profiles in the local store, the same profiles the desktop app shows. Profiles you add here appear in the app, and the other way round. Nothing here prints a secret: show reports only whether each secret is saved.

querybara profiles --help
Usage: querybara profiles [options] [command]
manage saved connection profiles (shared with the desktop app)
Options:
-h, --help show help for a command
Commands:
list [options] list saved profiles
show [options] <profile> show one profile; secrets are never printed,
only whether they are saved
add [options] <name> <uri> save a profile from a connection URI
import-uri [options] <uri> save a profile from a pasted URI, named after
its host and database
remove|rm [options] <profile> remove a profile with its saved secrets and
history
export [options] <file> export profiles to a passphrase-encrypted file
import [options] <file> import profiles from a passphrase-encrypted
export file
help [command] display help for command
querybara profiles list --help
Usage: querybara profiles list [options]
list saved profiles
Options:
--json print as JSON
-h, --help show help for a command
querybara profiles show --help
Usage: querybara profiles show [options] <profile>
show one profile; secrets are never printed, only whether they are saved
Arguments:
profile profile name or id
Options:
--json print as JSON
-h, --help show help for a command
Terminal window
querybara profiles list
querybara profiles show shop-prod --json

show also names the environment variables that supply the profile’s password, such as QUERYBARA_PASSWORD_SHOP_PROD or QUERYBARA_PASSWORD.

querybara profiles add --help
Usage: querybara profiles add [options] <name> <uri>
save a profile from a connection URI
Arguments:
name profile name
uri connection URI; a password in it is saved only
with --password-policy save
Options:
--environment <env> environment label (choices: "dev", "test",
"staging", "production")
--folder <path> folder id or path such as Team/Prod (created when
missing)
--password-policy <policy> save (sealed with QUERYBARA_PASSPHRASE), session
or ask. Default: save a password in the URI when
QUERYBARA_PASSPHRASE is set, else ask (choices:
"save", "session", "ask")
--read-only lock the profile read-only: writes are refused
--confirm-writes ask before every write
--tls <mode> TLS mode for this run: disable, require, verify-ca
or verify-full
--engine <engine> for mysql:// URIs of MariaDB servers (choices:
"mysql", "mariadb")
--tag <tag> add a tag; repeatable
--replace replace a profile with the same name
-h, --help show help for a command
Examples:
QUERYBARA_PASSPHRASE=... querybara profiles add prod "postgres://app:secret@db:5432/app" --environment production
querybara profiles add dev "mysql://[email protected]/app" --folder Local
querybara profiles import-uri --help
Usage: querybara profiles import-uri [options] <uri>
save a profile from a pasted URI, named after its host and database
Arguments:
uri connection URI
Options:
--name <name> profile name (default: host[:port]/database)
--environment <env> environment label (choices: "dev", "test",
"staging", "production")
--folder <path> folder id or path such as Team/Prod (created when
missing)
--password-policy <policy> save (sealed with QUERYBARA_PASSPHRASE), session
or ask. Default: save a password in the URI when
QUERYBARA_PASSPHRASE is set, else ask (choices:
"save", "session", "ask")
--read-only lock the profile read-only: writes are refused
--confirm-writes ask before every write
--tls <mode> TLS mode for this run: disable, require, verify-ca
or verify-full
--engine <engine> for mysql:// URIs of MariaDB servers (choices:
"mysql", "mariadb")
--tag <tag> add a tag; repeatable
--replace replace a profile with the same name
-h, --help show help for a command
Terminal window
querybara profiles add shop-dev "mysql://[email protected]/shop" --folder Local
querybara profiles add shop-prod "postgres://[email protected]:5432/shop" --environment production --read-only
querybara profiles import-uri "postgres://[email protected]/shop" --environment staging

import-uri names the profile after its host, port and database unless you pass --name.

A profile added from a URI that states no TLS settings has TLS off, as in the desktop app. Pass --tls to save another mode:

Terminal window
querybara profiles add shop-prod "postgres://[email protected]:5432/shop" --tls verify-full

The desktop app seals saved passwords with the OS keychain, which the CLI cannot use. The CLI seals the passwords it saves with the passphrase in QUERYBARA_PASSPHRASE instead.

--password-policy What happens
save The password is saved, sealed with QUERYBARA_PASSPHRASE
session The password is remembered for the session, not saved
ask The password is asked for every time

Without --password-policy, a password in the URI is saved when QUERYBARA_PASSPHRASE is set; otherwise the profile asks for it and the CLI warns that it was not saved. save without QUERYBARA_PASSPHRASE is an error.

Terminal window
QUERYBARA_PASSPHRASE="$STORE_PASSPHRASE" querybara profiles add shop-prod "postgres://app:$DB_PASSWORD@db.example.com:5432/shop" --environment production

Later runs need the same QUERYBARA_PASSPHRASE to read the password back.

  • --environment production makes every write to the profile ask for confirmation, in the CLI and in the app.
  • --confirm-writes asks before every write.
  • --read-only locks the profile: writes are refused.
querybara profiles remove --help
Usage: querybara profiles remove|rm [options] <profile>
remove a profile with its saved secrets and history
Arguments:
profile profile name or id
Options:
-y, --yes do not ask for confirmation
-h, --help show help for a command
Terminal window
querybara profiles remove shop-old
querybara profiles rm shop-old --yes

Removing a profile also removes its saved secrets and its history.

querybara profiles export --help
Usage: querybara profiles export [options] <file>
export profiles to a passphrase-encrypted file
Arguments:
file file to write
Options:
--profile <profile> export this profile; repeatable (default: all)
--include-secrets include the saved secrets that are readable here
-h, --help show help for a command
The passphrase comes from QUERYBARA_EXPORT_PASSPHRASE or a prompt.
querybara profiles import --help
Usage: querybara profiles import [options] <file>
import profiles from a passphrase-encrypted export file
Arguments:
file file to read
Options:
--replace replace profiles that already exist (same id)
-h, --help show help for a command
The passphrase comes from QUERYBARA_EXPORT_PASSPHRASE or a prompt.

The export file is encrypted with a passphrase (AES-256-GCM, with a key derived by scrypt). The passphrase comes from QUERYBARA_EXPORT_PASSPHRASE or a prompt, which asks twice when you export. The file holds secrets only when you pass --include-secrets, and then only the saved secrets the CLI can read on this machine.

Terminal window
querybara profiles export team-profiles.export --profile shop-prod --profile shop-staging
QUERYBARA_EXPORT_PASSPHRASE="$EXPORT_PASSPHRASE" querybara profiles import team-profiles.export --replace

Documents Querybara 0.1.1 · built frombc9f5aa