DATABASES

Postgres, MySQL, MariaDB —
no SSH required.

Auto-discovered from systemd, Docker, or standard ports. Panel surface for users, privileges, queries, backups — every action audit-logged with read-only-by-default SQL editor.

cloudnan.com / dashboard / databases

Databases

3 PostgreSQL · 2 MySQL · 1 Redis (auto-discovered)

app_prod

PostgreSQL 16

Size

12.4 GB

Tables

84

analytics

PostgreSQL 16

Size

4.8 GB

Tables

42

wp_db

MySQL 8.0

Size

1.2 GB

Tables

28

sessions

Redis 7.2

Size

128 MB

staging_db

PostgreSQL 16

Size

2.1 GB

Tables

84

orders_legacy

MySQL 8.0

Size

8.7 GB

Tables

156

How it works

What happens under the hood.

  1. 01

    Auto-discover instances

    Agent detects MySQL / MariaDB / PostgreSQL via systemd services, Docker containers, or standard ports.

  2. 02

    Credentials in a vault

    AES-256-GCM vault on the agent. Master credential never reaches our control plane.

  3. 03

    Panel surfaces databases

    List databases + users + privileges. Click into any database to browse tables, sizes, indexes.

  4. 04

    Read-only by default

    SQL editor opens read-only. Destructive operations require explicit toggle + confirmation, all audit-logged.

  5. 05

    Encrypted backups

    Stream pg_dump / mysqldump straight to S3 / MinIO / R2 with client-side encryption. Your customer-held key.

  6. 06

    Restore

    One-click restore from any snapshot. Streams ciphertext from your destination, decrypts on the agent, replays.

What you get

The capabilities that ship.

3 engines

MySQL, MariaDB, PostgreSQL — first-class panel support for all three.

DB Vault

Database master credentials live encrypted on the agent. Cloudnan never sees them.

User + privilege management

Create / drop users, grant / revoke privileges per database, per table.

Audited SQL editor

Read-only by default. Every query logged with user + timestamp + row count.

Encrypted backups

Client-side AES-256 to S3 / MinIO / R2 / B2 / Wasabi / Vultr / DO Spaces.

Scheduled snapshots

Daily / weekly / per-cron-expression. Retention policy per destination.

FAQ

Common questions.

Are credentials sent to the control plane?
No. Database credentials are encrypted on the agent with a key the agent generated locally. The control plane only sees encrypted blobs and metadata about the connection.
Does the SQL editor support transactions?
Yes. SELECT runs in a read-only transaction by default. Mutating statements require the destructive-mode toggle + a confirmation dialog.
Can I run point-in-time recovery?
For PostgreSQL with WAL archiving wired to S3, yes. MySQL/MariaDB PITR is on the roadmap.

Your fleet deserves better.

Get started in minutes.

Deploy agents on your servers, connect securely, and take full control. Start free, upgrade when ready.

  • 7-day free trial
  • No credit card
  • Cancel anytime