All skills
clickhouse avatar

/infra-postgres

@356a8c1 official
by clickhouseclickhouse/agent-skills543 stars
39

Sets up and manages Postgres using the clickhousectl CLI — runs a local Docker-backed Postgres for development, and creates and operates managed ClickHouse Cloud Postgres services (connections, TLS, runtime config, read replicas, failover, point-in-time restore). Use when the user wants a Postgres or PostgreSQL database for their application, a local Postgres dev environment, psql access, or a managed/production Postgres in ClickHouse Cloud, or mentions moving a local Postgres to production. Also use when migrating an existing Postgres database (Neon, Supabase, RDS, Aurora, Cloud SQL, self-hosted) into ClickHouse Cloud Postgres.

Use this Skill: https://skilld.dev/gh/clickhouse/agent-skills/infra-postgres

This session only. Nothing lands on disk.

reflocal.md

≈874 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Local Postgres for development

Local Postgres instances are Docker containers managed by clickhousectl. Follow these steps in order.

Docker must be installed and running — verify first:

docker info >/dev/null 2>&1 && echo ok || echo "Docker is not running"

If Docker is not running, ask the user to start Docker Desktop (or the Docker daemon) before continuing.

Step 1: Start a Postgres instance

clickhousectl local postgres start --json

Defaults: name default, Postgres 18, port 5432, user postgres, database postgres, and a random 24-character password. The image is pulled automatically if missing. If port 5432 is taken, a free port is auto-assigned — always read the actual port and password from the JSON output rather than assuming defaults:

{
  "name": "default",
  "port": 5433,
  "user": "postgres",
  "password": "n2efVm0c4nL5dstCyIFxqTSa",
  "database": "postgres"
}

Useful options:

  • --name <name> — named instances let you run several side by side (if default is already running and no name is given, a random name is generated)
  • -v, --version <tag> — Postgres image tag: 17 or 18 (e.g. 17, 17-alpine, 18.1). Default: 18
  • --port, --user, --password, --database — override defaults
  • -e KEY=VALUE — extra container env vars (repeatable)

Data persists across restarts at .clickhouse/servers/<name>-pg<major>/data/ in the project directory. Instances are per-project (keyed on the working directory).

Step 2: Run SQL

clickhousectl local postgres client wraps psql — it looks up the port and credentials of a named instance automatically. If psql is not on the host PATH, it runs psql inside the container instead, so no local Postgres install is required.

Single query:

clickhousectl local postgres client --name default --query "SELECT version()"

Apply a SQL file (e.g. schema or seed data):

clickhousectl local postgres client --name default --queries-file schema.sql

Interactive psql session (only when the user asks for one — it blocks the terminal):

clickhousectl local postgres client --name default

Extra psql arguments pass through after --.

Step 3: Wire up the application

Write connection env vars to .env (or .env.local with --local):

clickhousectl local postgres dotenv --name default

This writes POSTGRES_HOST, POSTGRES_PORT, POSTGRES_USER, POSTGRES_PASSWORD, and POSTGRES_DATABASE, replacing any existing POSTGRES_* vars in place. Make sure .env is gitignored, then have the application read these variables (or compose them into a postgres:// connection string).

Managing local instances

clickhousectl local server list          # lists ClickHouse and Postgres instances together
clickhousectl local postgres stop <name>
clickhousectl local postgres stop-all
clickhousectl local postgres remove <name>   # deletes the data directory too

stop keeps data for a later start; remove is destructive — confirm with the user before removing an instance that may hold data they care about. Use -v <version> with stop/remove to disambiguate when two instances share a name.

Going to production

When the user is ready to move from local development to a managed Postgres service in ClickHouse Cloud, read cloud.md — it covers authentication, creating the service, connecting with TLS, and applying the same schema there.

Source: SKILL.md on GitHub

1 alert2d3 checks · Risk HIGH
  • Gen Agent Trust Hub2d

    The skill facilitates Postgres management using the ClickHouse CLI (clickhousectl). It includes a standard vendor installation script from clickhouse.com and follows security best practices by advising users to keep API secrets out of the chat context. It identifies as having an indirect prompt injection surface because it reads and acts upon data produced by command-line tools, though it uses structured JSON data to minimize risk.

  • Socket2d

    No alerts

  • Snyk2d

    Risk: LOW · No issues

Signed by skilld at 356a8c1. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 3 days ago
metadata
{
  "author": "ClickHouse Inc",
  "version": "0.2.0"
}

README badge

README badge for clickhouse/agent-skills/infra-postgres