Database command line
What this page covers
Section titled “What this page covers”Command line work on a database goes through the same gateway. The backend hosts the local command line program and proxies it over a PTY, so the real credential stays out of the child process arguments; the text stream carries the same command auditing, recording, live view, and blocking as a terminal. For a graphical schema tree and result grid, use the query console instead.
What you need
Section titled “What you need”The target database listening on its service port and accepting connections from this system. Default ports: MySQL 3306, PostgreSQL 5432, Redis 6379, SQL Server 1433.
How to set it up
Section titled “How to set it up”Choose the matching database as the protocol when creating the asset, then fill in the host and port. The login secret is either a credential dedicated to this asset, or a shared credential in the library that matches the protocol. Redis still has no username; the secret itself can go into the library. Two fields are shared by all four protocols:
- Database: the database to connect to; empty means the default one.
- TLS mode: default (up to the client), encryption off, encrypted without certificate verification, encrypted with server certificate verification, or encrypted with certificate and hostname verification. The last two need a CA certificate.
SQL Server carries an authentication type field as well. To restrict which databases this asset may reach, see the allowed database list in the query console.
Clicking the asset row in the workspace sidebar opens a command line tab.
After connecting
Section titled “After connecting”- The backend injects the password at the prompt, so it appears in neither the child process arguments nor its environment.
- The command line program runs under a dedicated unprivileged identity whose home and temporary directories are not writable.
- The interactive history file is pointed at the null device, so the work leaves no history file in the container.
- Line editing passes through in full: arrow keys, Home and End, Tab, and the common Ctrl combinations all arrive as they are.
- A SQL Server batch is sent by typing
GOon a line of its own, and the interface says so.
What auditors can see
Section titled “What auditors can see”- Recording: text recording, in the same format and player as SSH.
- Commands: in MySQL and PostgreSQL sessions a statement spanning several lines accumulates into one complete record, settled when the terminator arrives; Redis is recorded line by line; SQL Server is split on the batch terminator.
- Blocking and alerting for dangerous commands is split by protocol; see Command rules and blocking.
- A session in progress can be watched read-only by an auditor.
- An asset whose TLS mode is empty or set to encryption off carries a transmission risk badge in the asset list.