Install
$ agentstack add mcp-syngnat-gonavi ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ● Filesystem access Used
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
GoNavi
Navigate every data source — native speed, agent-ready, zero Electron bloat.
A high-performance cross-platform database client built with Wails (Go) + React. Desktop-first. MCP-ready. ~30MB class binaries.
Language: English · 简体中文 · 🌐 Website · ⬇ Download · ⚡ Quick Start · ✨ Features · 🤖 MCP
Sponsored by 华龙中转站 / Hualong Transfer Station
Why GoNavi?
Most database GUIs are Electron shells with megabytes of tax. GoNavi takes a different path:
| | Typical Electron client | GoNavi | |---|---|---| | Runtime | Chromium + Node | Go + native WebView | | Binary size | Hundreds of MB | ~30MB class | | Startup | Heavy | Fast | | Memory | High baseline | Lean | | AI / Agents | Bolt-on or absent | First-class MCP + multi-provider AI | | Data sources | Mostly RDBMS | SQL · Cache · Vector · MQ · Search · Time-series · Domestic DBs |
> One cockpit for MySQL, Postgres, Redis, Kafka, Milvus, OceanBase, ClickHouse… > Query, edit, audit, sync — and hand structured context to coding agents without leaking passwords off-host.
At a Glance
┌──────────────────────────────────────────────────────────────────────┐
│ GoNavi Workbench │
│ ┌─────────────┐ ┌──────────────────┐ ┌─────────────────────────┐ │
│ │ Connections │ │ Monaco SQL + AI │ │ Virtualized DataGrid │ │
│ │ SSH / Proxy │ │ Schema context │ │ Batch edit · Export │ │
│ │ Drivers │ │ Slash commands │ │ Txn submit / rollback │ │
│ └─────────────┘ └────────┬─────────┘ └─────────────────────────┘ │
│ │ │
│ ┌─────────────▼─────────────┐ │
│ │ Go core · Audit · Sync │ │
│ │ MCP HTTP · Web Server │ │
│ └───────────────────────────┘ │
└──────────────────────────────────────────────────────────────────────┘
Product screenshots
Each image is a full GoNavi application window, scaled proportionally for README display.
Real desktop captures · full window
✨ Key Features
🤖 AI that knows your schema
- OpenAI · Gemini · Claude · custom OpenAI-compatible APIs
- Attach live table schemas as context
- Slash commands: generate SQL, explain, optimize, review
- MCP: install into Claude Code / Codex, or Streamable HTTP for remote agents
- Secrets stay on the GoNavi host — agents get tools, not raw passwords
⚡ Built for large data
- Virtualized DataGrid for heavy result sets
- In-place cell edit · batch CRUD · transaction submit/rollback
- Large-field popup editor · smart read/write modes
- Export: CSV · XLSX · JSON · Markdown
- Monaco editor with context-aware completion
🔌 Connectivity without drama
- URI generate / parse
- SSH tunnel · proxy
- Connection JSON import / export
- On-demand optional driver agents
- Custom Driver + DSN extensibility
🛡️ Observable & shippable
- SQL execution logs with timing
- Audit center (redacted by default, retention, export)
- Desktop + experimental Web Server mode
- Docker / K8s / Helm / Podman packaging
- Auto update checks · multi-arch releases
🧩 Stack
Go 1.24 · Wails v2 · React 18 · TypeScript · Vite · Ant Design 5 · Zustand · Monaco
🗄 Supported Data Sources
> Built-in — ready out of the box · Optional agent — install via Driver Manager
| | | |---|---| | Built-in | MySQL · GoldenDB · PostgreSQL · Oracle · Redis · Chroma · Qdrant · Milvus · RocketMQ · MQTT · Kafka · RabbitMQ | | Optional | MariaDB · Doris · StarRocks · Sphinx · SQL Server · SQLite · DuckDB · OceanBase · Dameng · Kingbase · HighGo · Vastbase · OpenGauss · GaussDB · IRIS · MongoDB · TDengine · IoTDB · ClickHouse · Trino · Elasticsearch · Custom Driver/DSN |
Full capability matrix
| Category | Data Source | Driver Mode | Typical Capabilities | |---|---|---|---| | Relational | MySQL | Built-in | Schema browsing, SQL query, data editing, export/backup | | Domestic DB | GoldenDB | Built-in | MySQL-compatible query workflow and distributed transaction scenarios | | Relational | PostgreSQL | Built-in | Schema browsing, SQL query, data editing, object management | | Relational | Oracle | Built-in | Query execution, object browsing, data editing | | Cache | Redis | Built-in | Key browsing, command execution, encoding/view switch | | Vector Database | Chroma | Built-in | Collection browsing, vector retrieval, metadata filtering | | Vector Database | Qdrant | Built-in | Collection browsing, vector search, payload filtering | | Vector Database | Milvus | Built-in | Collection browsing, vector search, scalar filtering | | Message Queue | RocketMQ | Built-in | Topic browsing, consumer-group inspection, message-oriented workflow | | Message Queue | MQTT | Built-in | Broker and topic-filter workflow with QoS-aware connection settings | | Message Queue | Kafka | Built-in | Topic browsing, broker metadata, consumer-group workflow | | Message Queue | RabbitMQ | Built-in | Queue/exchange browsing, virtual host inspection, management API workflow | | Relational | MariaDB | Optional driver agent | Querying, object management, data editing | | Relational | Doris | Optional driver agent | Querying, object browsing, SQL execution | | Columnar Analytics | StarRocks | Optional driver agent | Querying, object browsing, SQL execution | | Search | Sphinx | Optional driver agent | SphinxQL querying and object browsing | | Relational | SQL Server | Optional driver agent | Schema browsing, SQL query, object management | | File-based | SQLite | Optional driver agent | Local DB browsing, editing, export | | File-based | DuckDB | Optional driver agent | Large-table query, pagination, file-DB workflow | | Domestic DB | OceanBase | Optional driver agent | MySQL / Oracle tenant access, object browsing, query workflow | | Domestic DB | Dameng | Optional driver agent | Querying, object browsing, data editing | | Domestic DB | Kingbase | Optional driver agent | Querying, object browsing, data editing | | Domestic DB | HighGo | Optional driver agent | Querying, object browsing, data editing | | Domestic DB | Vastbase | Optional driver agent | Querying, object browsing, data editing | | Domestic DB | OpenGauss | Optional driver agent | PostgreSQL-like schema browsing, SQL query, object management | | Domestic DB | GaussDB | Optional driver agent | PostgreSQL-like schema browsing, SQL query, object management | | Multi-model | InterSystems IRIS | Optional driver agent | Namespace browsing, SQL query, object management | | Document | MongoDB | Optional driver agent | Document query, collection browsing, connection management | | Time-series | TDengine | Optional driver agent | Time-series schema browsing and querying | | Time-series | Apache IoTDB | Optional driver agent | Storage group / device / timeseries browsing and querying | | Columnar Analytics | ClickHouse | Optional driver agent | Analytical query, object browsing, SQL execution | | Federated Query | Trino | Optional driver agent | Cross-source SQL via multiple catalogs, catalog.schema browsing, SQL execution | | Search | Elasticsearch | Optional driver agent | Index browsing, mapping inspection, guarded REST console, JSON DSL / query_string search | | Extensibility | Custom Driver/DSN | Custom | Extend to more data sources via Driver + DSN |
Elasticsearch REST console
Elasticsearch connections reuse the query workspace as a version-aware REST console:
- Write Dev Tools-style
METHOD /pathrequests with JSON bodies, or NDJSON for_bulkand_msearch; run the request at the cursor, the exact selection, or a batch in editor order. - Search hits can be viewed as a table while the complete HTTP response remains available as raw JSON or text.
- A server-side allowlist accepts supported search, document, index, mapping, settings, alias, health, and limited CAT operations. Unknown and high-privilege endpoints are rejected by default.
- Destructive operations require an expiring one-time confirmation. Connection protection still takes precedence and blocks writes as well as script-bearing reads.
- Writes are limited to concrete indices and require Elasticsearch
view_index_metadata(ormanage) permission so GoNavi can verify the target before sending data; aliases and data streams are not accepted as write targets. - Request templates adapt document, mapping, and Bulk paths for Elasticsearch 6, 7, and 8.
> This console targets Elasticsearch 6/7/8. It does not claim OpenSearch compatibility, and intentionally excludes reindex, security, snapshot, node, cluster-settings, template, pipeline, lifecycle, and other unrestricted administration APIs.
🚀 Quick Start
Prerequisites
go install github.com/wailsapp/wails/v2/cmd/wails@v2.11.0
Develop
git clone https://github.com/Syngnat/GoNavi.git
cd GoNavi
wails dev # full hot reload
node tools/wails-fast-dev.mjs # faster when Go exports unchanged
node tools/wails-fast-dev.mjs --refresh-bindings # after Go export signature changes
Build
wails build
wails build -clean # clean build before release
Artifacts → build/bin.
Prefer a binary?
Grab the latest build from Releases (macOS AMD64/ARM64 · Windows AMD64 · Linux WebKitGTK 4.0/4.1).
🌐 Web Server (Experimental)
Same Go backend + React UI over HTTP — not a containerized Wails window.
go build .
.\GoNavi-Wails.exe web-server --addr 127.0.0.1:34116
- First visit →
/setup(admin password; optional Google Authenticator) - Bridge:
window.go.*/window.runtime.*→ HTTP / SSE - Sessions, recovery codes, login rate limits
Docker / Podman
cp docker.web-server.env.example docker.web-server.env
# set GONAVI_HOST_DATA_ROOT (absolute path)
# optional: GONAVI_WEB_PASSWORD (min 6 chars)
docker compose --env-file docker.web-server.env -f docker-compose.web-server.yml up -d
Open http://127.0.0.1:34116. Mount the active data root at /data (connections.json, daily_secrets.json, optional drivers/). Auth state → web_auth.json.
> Do not expose an unhardened web entry to the public internet. Use reverse proxy + HTTPS in production.
Health: GET /__gonavi/healthz Local source build: add -f docker-compose.web-server.local.yml --build.
After changing env passwords:
docker compose --env-file docker.web-server.env -f docker-compose.web-server.yml up -d --force-recreate
(docker restart does not reload env files.)
🤖 MCP & Agents
Ship schema tools to agents without shipping your vault:
cp docker.mcp-server.env.example docker.mcp-server.env
docker compose --env-file docker.mcp-server.env -f docker-compose.mcp-server.yml up -d
| Surface | Entry | |---|---| | MCP container | docker-compose.mcp-server.yml → ghcr.io/syngnat/gonavi-mcp-server | | Web UI container | docker-compose.web-server.yml → ghcr.io/syngnat/gonavi-web-server | | Podman / Quadlet | [deploy/podman/gonavi-mcp-server](deploy/podman/gonavi-mcp-server) | | Kubernetes | [deploy/k8s/gonavi-mcp-server](deploy/k8s/gonavi-mcp-server) | | Helm | [deploy/helm/gonavi-mcp-server](deploy/helm/gonavi-mcp-server) | | Build-only image | Dockerfile.build-env → ghcr.io/syngnat/gonavi-build-env |
Safety defaults: remote schema-only omits execute_sql; mutating SQL requires explicit allowMutating=true. Details: [cmd/gonavi-mcp-server/README.md](cmd/gonavi-mcp-server/README.md).
Linux build environment only
docker build -f Dockerfile.build-env -t gonavi-build-env:local .
docker run --rm -it -v "$PWD:/workspace" -w /workspace gonavi-build-env:local bash
📦 Release Pipeline
Push a v* tag → GitHub Actions builds multi-arch releases. Notes auto-generated from merged PRs via .github/release.yaml.
🛠 Troubleshooting
Windows: missing Microsoft Edge WebView2 Runtime (common on intranet images)
The GoNavi desktop app on Windows depends on the Microsoft Edge WebView2 Runtime (a system component, not full Chrome). Some intranet / thin / Server / LTSC images ship without it. Symptoms:
- Process exits immediately, blank/white window
- Errors about missing WebView2 / WebView2 Runtime
- Installer blocked by AV or group policy
1. Check whether Runtime is installed
In PowerShell:
# Common Evergreen install path (64-bit Windows)
Test-Path "${env:ProgramFiles(x86)}\Microsoft\EdgeWebView\Application"
# Registry (a `pv` version usually means installed)
Get-ItemProperty -Path "HKLM:\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\Clients\{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}" `
-ErrorAction SilentlyContinue |
Select-Object pv, name
If the path is missing and registry has no pv, install the Runtime.
2. Online install (simplest)
- Open the official download page:
- Download the Evergreen Bootstrapper (small; needs network during install)
- Run as Administrator, then restart GoNavi
3. Offline / intranet: Standalone installer (recommended for IT)
The Bootstrapper fails on fully air-gapped machines. Use the Evergreen Standalone Installer instead:
- On a machine with internet, download the matching architecture package, e.g.:
MicrosoftEdgeWebView2RuntimeInstallerX64.exe(most 64-bit PCs)…X86.exe/…ARM64.exeas needed
- Copy the installer into the intranet (USB, software center, share)
- Install as Administrator on the target PC:
# Interactive
.\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
# Silent (batch / SCCM friendly)
.\MicrosoftEdgeWebView2RuntimeInstallerX64.exe /silent /install
- Start GoNavi again. If it still fails, sign out or reboot Windows once.
4. Group policy / locked-down PCs
- Needs local admin, or IT push via SCCM / software center
- Ensure policies do not block Edge/WebView2 install or updates
- Enterprises may pin a Fixed Version Runtime (most users should prefer Evergreen)
5. Temporary workaround: Web Server mode
If the desktop WebView cannot be installed yet, run the experimental Web Server and use a normal browser:
.\GoNavi.exe web-server --addr 127.0.0.1:34116
Open http://127.0.0.1:34116. See the Web Server section above. Do not expose an unhardened Web endpoint to the public internet.
Tracker / discussion: #672.
macOS: “App is damaged and can’t be opened”
Without Apple notarization, Gatekeeper may block the app:
sudo xattr -rd com.apple.quarantine /Applications/GoNavi.app
Or right-click → Open (Control-click flow). Move the app to Applications first.
Linux: missing WebKitGTK
# Debian 13 / Ubuntu 24.04+
sudo apt-get update
sudo apt-get install -y libgtk-3-0 libwebkit2gtk-4.1-0 libjavascriptcoregtk-4.1-0
# Ubuntu 22.04 / Debian 12
sudo apt-get update
sudo apt-get install -y libgtk-3-0 libwebkit2gtk-4.0-37 libjavascriptcoregtk-4.0-18
Artifacts with -WebKit41 prefer Debian 13 / Ubuntu 24.04+.
Linux: Chinese glyphs as tofu boxes
sudo apt-get update
sudo apt-get install -y fonts-noto-cjk fonts-wqy-microhei
fc-cache -fv
💖 Sponsors
华龙中转站 · Hualong Transfer Station AI API Gateway · multi-model routing · domestic high-speed endpoint
Spe
…
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Syngnat
- Source: Syngnat/GoNavi
- License: Apache-2.0
- Homepage: https://gonavi.org
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.