The database agent
Last updated 7 Oct 2026
Some sites keep their orders, bookings or sign-ups only in their database. The agent is a small Docker container that runs next to such a site, reads the database with a read-only user and sends the panel only the tables and columns you approve. It is included in the paid plans.
What it never does
- write to the database: it runs
SELECTonly, and switches its own session to read-only as well; - send the connection string or the database password anywhere;
- read columns that look like passwords, hashes, tokens, keys or card data, even if asked to;
- copy your history: when a table is enabled it sends the latest 100 rows, then only new ones;
- open a port: it only makes outgoing HTTPS requests to the panel.
Set it up
Create a read-only user in the site's database, with
SELECTon the tables you want (or on chosen columns only). For PostgreSQL:CREATE ROLE onepanel_reader LOGIN PASSWORD 'a-long-random-password'; GRANT CONNECT ON DATABASE mysite TO onepanel_reader; GRANT USAGE ON SCHEMA public TO onepanel_reader; GRANT SELECT ON public.orders TO onepanel_reader;Run the agent next to the site, with the site's key and secret and the read-only connection string (as environment variables):
onepanelforall-agent: image: onepanelforall-agent:latest restart: unless-stopped environment: OnePanel__KeyId: ${ONEPANEL_KEY_ID} OnePanel__Secret: ${ONEPANEL_SECRET} Database__Engine: postgres # or mysql, sqlserver Database__ConnectionString: Host=db;Database=mysite;Username=onepanel_reader;Password=${ONEPANEL_DB_PASSWORD}Write to [email protected] to get access to the agent's image.
Approve tables and columns: in the panel, open the site, tab Database. The schema appears within a minute. Tick the tables, the columns and the column that orders new rows (usually
idorcreated_at).Add alert rules (optional): "an order over 1,000", "no new row in 24 hours" and others, under Alert rules.
Errors (database unreachable, a renamed column) show on the Problems page.