Integrations
MySQL (read-only)
Register a database the assistant can query — and the limits of "read-only".
A MySQL database can be registered so the assistant can answer questions from your data: "how many orders were placed yesterday?", "is the sessions table growing?", "show me the ten slowest queries by row count."
Queries are read-only. Statements that would change data are refused.
Connecting one
Today this is set up through the API rather than a screen. There is no Add database form in the UI yet. If you want a database connected, email support@devops-agent.io and we will walk you through it.
What it needs: host, port (3306 by default), database name, username and password. The password is encrypted at rest like every other credential.
Create a dedicated, read-only database user
Please do not connect as root. Make a user that can only read:
CREATE USER 'devops_agent'@'%' IDENTIFIED BY 'a-long-random-password';
GRANT SELECT ON your_database.* TO 'devops_agent'@'%';
FLUSH PRIVILEGES;
The database must also be reachable from our servers, which for a database on your own machine means opening a firewall port — so restrict it to our address rather than the whole internet.
How safe is "read-only"?
Two layers:
- The
GRANT SELECTuser above. This is the real protection. A user withoutINSERT,UPDATEorDELETEcannot write, whatever is sent to it. - A query filter in DevOps Agent that rejects statements that are not reads.
Layer 2 is a filter, not a proof. It is deliberately conservative but it is text analysis, and text analysis of SQL has edge cases. Layer 1 is what makes this genuinely safe. Always use a read-only database user.
Also worth remembering: query results go into the chat, and the chat is stored. Do not point this at a table of customer payment details.
Permissions
Registering a database: Owner or Admin. Querying it in chat: everyone, subject to the role rules — Viewers are refused reads that return secrets.
