AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Postgres

skill-digitalocean-labs-do-app-platform-skills-postgres · by digitalocean-labs

Configure DigitalOcean Managed Postgres with bindable variables or schema isolation. Use when setting up databases, creating users, managing permissions, configuring multi-tenant schemas, or troubleshooting database connectivity on App Platform.

No reviews yet
0 installs
24 views
0.0% view→install

Install

$ agentstack add skill-digitalocean-labs-do-app-platform-skills-postgres

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-digitalocean-labs-do-app-platform-skills-postgres)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Postgres? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Postgres Skill

Configure DigitalOcean Managed Postgres databases with proper security isolation and production-ready defaults.

Quick Decision

Need multiple isolated schemas in one database?
├── YES → Path B (Schema Isolation)
└── NO  → Path A (Bindable Variables) ✅ RECOMMENDED

Path A: Bindable Variables (Recommended)

Use when: Single app per database, standard CRUD applications.

Quick Start

# 1. Create cluster + user via doctl (DO stores password internally)
doctl databases create my-app-db --engine pg --region nyc3 --size db-s-1vcpu-2gb
CLUSTER_ID=$(doctl databases list --format ID,Name --no-header | grep my-app-db | awk '{print $1}')
doctl databases db create $CLUSTER_ID myappdb
doctl databases user create $CLUSTER_ID myappuser

# 2. Grant permissions (REQUIRED - users have no access by default!)
# Run: scripts/grant_permissions.sql as doadmin

# 3. Reference in app spec
# .do/app.yaml
databases:
  - name: db
    engine: PG
    production: true
    cluster_name: my-app-db
    db_name: myappdb
    db_user: myappuser

services:
  - name: api
    envs:
      - key: DATABASE_URL
        scope: RUN_TIME
        value: ${db.DATABASE_URL}

Full guide: See [path-a-bindable-vars.md](reference/path-a-bindable-vars.md)


Path B: Schema Isolation

Use when: Multi-tenant SaaS, multiple apps sharing one cluster, schema-level isolation needed.

Quick Start

# Hands-free setup (requires gh CLI)
./scripts/secure_setup.sh \
  --admin-url "$ADMIN_URL" \
  --app-name myapp \
  --schema myapp \
  --repo owner/repo

Password flows directly to GitHub Secrets — never displayed.

Full guide: See [path-b-schema-isolation.md](reference/path-b-schema-isolation.md)


Available Bindable Variables

| Variable | Example | |----------|---------| | ${db.DATABASE_URL} | postgresql://user:pass@host:25060/db?sslmode=require | | ${db.HOSTNAME} | my-db-do-user-123.db.ondigitalocean.com | | ${db.PORT} | 25060 | | ${db.USERNAME} | myappuser | | ${db.PASSWORD} | (auto-populated) | | ${db.DATABASE} | myappdb | | ${db.CA_CERT} | (certificate content) |


Scripts

| Script | Purpose | |--------|---------| | scripts/secure_setup.sh | Hands-free Path B setup with GitHub Secrets | | scripts/create_schema_user.py | Create isolated schema + user | | scripts/list_schemas_users.py | Audit existing schemas/users | | scripts/generate_connection_string.py | Build connection strings |


Reference Files

  • [path-a-bindable-vars.md](reference/path-a-bindable-vars.md) — Full Path A workflow, connection pools, multi-app setup
  • [path-b-schema-isolation.md](reference/path-b-schema-isolation.md) — Full Path B workflow, multi-tenant patterns
  • [orm-configurations.md](reference/orm-configurations.md) — Prisma, SQLAlchemy, Drizzle, TypeORM configs
  • [database-migrations.md](reference/database-migrations.md) — Alembic, Prisma Migrate, Drizzle Migrate
  • [doctl-reference.md](reference/doctl-reference.md) — All doctl databases commands
  • [troubleshooting.md](reference/troubleshooting.md) — Common errors and fixes
  • [bundled-scripts.md](reference/bundled-scripts.md) — Script usage documentation

Common Issues (Quick Fixes)

| Error | Fix | |-------|-----| | "permission denied for schema" | Run permission SQL as doadmin | | "relation does not exist" | Check search_path or use schema-qualified names | | "too many connections" | Create connection pool via doctl | | "SSL connection required" | Add ?sslmode=require to connection string | | Bindable vars not populated | Verify production: true and names match exactly |

Full troubleshooting: See [troubleshooting.md](reference/troubleshooting.md)


Integration with Other Skills

  • → designer: Add database block to app spec
  • → deployment: GitHub Actions workflow with DATABASE_URL secret
  • → devcontainers: Local Postgres with prod parity
  • → troubleshooting: Debug container for connectivity testing

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.