The database agent

Last updated 7 Oct 2026

Some sites keep their orders, bookings or sign-ups only in their database. The agent is a small Docker container that runs next to such a site, reads the database with a read-only user and sends the panel only the tables and columns you approve. It is included in the paid plans.

What it never does

  • write to the database: it runs SELECT only, and switches its own session to read-only as well;
  • send the connection string or the database password anywhere;
  • read columns that look like passwords, hashes, tokens, keys or card data, even if asked to;
  • copy your history: when a table is enabled it sends the latest 100 rows, then only new ones;
  • open a port: it only makes outgoing HTTPS requests to the panel.

Set it up

  1. Create a read-only user in the site's database, with SELECT on the tables you want (or on chosen columns only). For PostgreSQL:

    CREATE ROLE onepanel_reader LOGIN PASSWORD 'a-long-random-password';
    GRANT CONNECT ON DATABASE mysite TO onepanel_reader;
    GRANT USAGE ON SCHEMA public TO onepanel_reader;
    GRANT SELECT ON public.orders TO onepanel_reader;
    
  2. Run the agent next to the site, with the site's key and secret and the read-only connection string (as environment variables):

    onepanelforall-agent:
      image: onepanelforall-agent:latest
      restart: unless-stopped
      environment:
        OnePanel__KeyId: ${ONEPANEL_KEY_ID}
        OnePanel__Secret: ${ONEPANEL_SECRET}
        Database__Engine: postgres        # or mysql, sqlserver
        Database__ConnectionString: Host=db;Database=mysite;Username=onepanel_reader;Password=${ONEPANEL_DB_PASSWORD}
    

    Write to [email protected] to get access to the agent's image.

  3. Approve tables and columns: in the panel, open the site, tab Database. The schema appears within a minute. Tick the tables, the columns and the column that orders new rows (usually id or created_at).

  4. Add alert rules (optional): "an order over 1,000", "no new row in 24 hours" and others, under Alert rules.

Errors (database unreachable, a renamed column) show on the Problems page.