Integrations

MySQL (read-only)

Register a database the assistant can query — and the limits of "read-only".

A MySQL database can be registered so the assistant can answer questions from your data: "how many orders were placed yesterday?", "is the sessions table growing?", "show me the ten slowest queries by row count."

Queries are read-only. Statements that would change data are refused.

Connecting one

Today this is set up through the API rather than a screen. There is no Add database form in the UI yet. If you want a database connected, email support@devops-agent.io and we will walk you through it.

What it needs: host, port (3306 by default), database name, username and password. The password is encrypted at rest like every other credential.

Create a dedicated, read-only database user

Please do not connect as root. Make a user that can only read:

CREATE USER 'devops_agent'@'%' IDENTIFIED BY 'a-long-random-password';
GRANT SELECT ON your_database.* TO 'devops_agent'@'%';
FLUSH PRIVILEGES;

The database must also be reachable from our servers, which for a database on your own machine means opening a firewall port — so restrict it to our address rather than the whole internet.

How safe is "read-only"?

Two layers:

  1. The GRANT SELECT user above. This is the real protection. A user without INSERT, UPDATE or DELETE cannot write, whatever is sent to it.
  2. A query filter in DevOps Agent that rejects statements that are not reads.

Layer 2 is a filter, not a proof. It is deliberately conservative but it is text analysis, and text analysis of SQL has edge cases. Layer 1 is what makes this genuinely safe. Always use a read-only database user.

Also worth remembering: query results go into the chat, and the chat is stored. Do not point this at a table of customer payment details.

Permissions

Registering a database: Owner or Admin. Querying it in chat: everyone, subject to the role rules — Viewers are refused reads that return secrets.