Skip to content

Proxies

  • PostgreSQL
  • MySQL
  • MariaDB
  • MongoDB
  • Redis / Valkey
  • Elasticsearch
  • CLI

A proxy sits between Querybara and the database. Querybara supports SOCKS5 and HTTP proxies that accept the CONNECT method. With an SSH tunnel as well, the proxy carries the connection to the first SSH server.

  1. In the connection dialog, open the Proxy tab and set Proxy type to SOCKS5 or HTTP (CONNECT). It starts at No proxy. The tab shows a green dot while a proxy is set.
  2. Fill in Proxy host and Proxy port (1080 to start).
  3. If the proxy asks for credentials, fill in Proxy user, choose a Proxy password storage other than No password, and type the Proxy password. Leave the storage at No password for a proxy without one.
  4. Choose Test Connection. Without an SSH tunnel, the proxy step is labelled Proxy.
Proxy Behaviour
SOCKS5 Querybara passes the database host name to the proxy, which resolves it (like socks5h).
HTTP (CONNECT) Querybara asks the proxy to open a tunnel to the database with CONNECT, with Basic authentication when set.

During Test Connection, DNS lookup and TCP connect check the proxy itself; the database host is resolved beyond it.

A MongoDB replica set, Redis Sentinel or Redis Cluster also works through a proxy: each server connection goes through the proxy to the address the server announces. See Replica sets, Sentinel and Cluster. Elasticsearch reaches one node through a proxy, and a Unix socket cannot use one. For MongoDB, Redis and Elasticsearch, the Proxy tab explains how the engine’s endpoints are reached through the proxy.

A proxy without an SSH tunnel carries the traffic over the network, so a connection with TLS off or not fully verified gets the weak-TLS warning even for a localhost database; see TLS modes.

Set a proxy on the Proxy tab and tick Connect through an SSH tunnel on the SSH tab to send the SSH connection through the proxy. Querybara connects to the proxy, then through it to the first SSH host, then on through the SSH chain to the database. See SSH tunnels.

A saved profile uses its own proxy. For a URI target, --proxy sets one:

Terminal window
querybara test "postgres://[email protected]/shop" --proxy socks5://proxy.example.com:1080
querybara query "mysql://[email protected]/shop" --proxy http://proxy.example.com:3128 -e "select 1"

With --ssh, the proxy carries the first SSH hop. The proxy password comes from the URL or from QUERYBARA_PROXY_PASSWORD.

Documents Querybara 0.1.1 · built frombc9f5aa