Proxies
- PostgreSQL
- MySQL
- MariaDB
- MongoDB
- Redis / Valkey
- Elasticsearch
- CLI
A proxy sits between Querybara and the database. Querybara supports SOCKS5 and HTTP proxies that accept the CONNECT method. With an SSH tunnel as well, the proxy carries the connection to the first SSH server.
Set up a proxy
Section titled “Set up a proxy”- In the connection dialog, open the Proxy tab and set Proxy type to SOCKS5 or HTTP (CONNECT). It starts at No proxy. The tab shows a green dot while a proxy is set.
- Fill in Proxy host and Proxy port (1080 to start).
- If the proxy asks for credentials, fill in Proxy user, choose a Proxy password storage other than No password, and type the Proxy password. Leave the storage at No password for a proxy without one.
- Choose Test Connection. Without an SSH tunnel, the proxy step is labelled Proxy.
How Querybara uses the proxy
Section titled “How Querybara uses the proxy”| Proxy | Behaviour |
|---|---|
| SOCKS5 | Querybara passes the database host name to the proxy, which resolves it (like socks5h). |
| HTTP (CONNECT) | Querybara asks the proxy to open a tunnel to the database with CONNECT, with Basic authentication when set. |
During Test Connection, DNS lookup and TCP connect check the proxy itself; the database host is resolved beyond it.
A MongoDB replica set, Redis Sentinel or Redis Cluster also works through a proxy: each server connection goes through the proxy to the address the server announces. See Replica sets, Sentinel and Cluster. Elasticsearch reaches one node through a proxy, and a Unix socket cannot use one. For MongoDB, Redis and Elasticsearch, the Proxy tab explains how the engine’s endpoints are reached through the proxy.
A proxy without an SSH tunnel carries the traffic over the network, so a connection with TLS off
or not fully verified gets the weak-TLS warning even for a localhost database; see
TLS modes.
With an SSH tunnel
Section titled “With an SSH tunnel”Set a proxy on the Proxy tab and tick Connect through an SSH tunnel on the SSH tab to send the SSH connection through the proxy. Querybara connects to the proxy, then through it to the first SSH host, then on through the SSH chain to the database. See SSH tunnels.
From the command line
Section titled “From the command line”A saved profile uses its own proxy. For a URI target, --proxy sets one:
querybara query "mysql://[email protected]/shop" --proxy http://proxy.example.com:3128 -e "select 1"With --ssh, the proxy carries the first SSH hop. The proxy password comes from the URL or from
QUERYBARA_PROXY_PASSWORD.
Related
Section titled “Related”Documents Querybara 0.1.1 · built frombc9f5aa