Skip to content
Back to skills

Postgres

ASecurity

Configure DigitalOcean Managed Postgres with bindable variables or schema isolation. Use when setting up databases, creating users, managing permissions, configuring multi-tenant schemas, or troubleshooting database connectivity on App Platform.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
databasesbashsqltestinggitapidatabasesecuritydocumentation

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 27, 2026

npx -y skills add David-Li0406/meta-skill-evloving --skill postgres --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Postgres?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Postgres
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-postgres/badge)](https://www.skillsdirectory.com/skills/david-li0406-postgres)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: postgres
version: 1.0.0
min_doctl_version: "1.82.0"
description: Configure DigitalOcean Managed Postgres with bindable variables or schema isolation. Use when setting up databases, creating users, managing permissions, configuring multi-tenant schemas, or troubleshooting database connectivity on App Platform.
related_skills: [designer, networking]
deprecated: false
---

# Postgres Skill

Configure DigitalOcean Managed Postgres databases with proper security isolation and production-ready defaults.

## Quick Decision

```
Need multiple isolated schemas in one database?
├── YES → Path B (Schema Isolation)
└── NO  → Path A (Bindable Variables) ✅ RECOMMENDED
```

---

## Path A: Bindable Variables (Recommended)

Use when: Single app per database, standard CRUD applications.

### Quick Start

```bash
# 1. Create cluster + user via doctl (DO stores password internally)
doctl databases create my-app-db --engine pg --region nyc3 --size db-s-1vcpu-2gb
CLUSTER_ID=$(doctl databases list --format ID,Name --no-header | grep my-app-db | awk '{print $1}')
doctl databases db create $CLUSTER_ID myappdb
doctl databases user create $CLUSTER_ID myappuser

# 2. Grant permissions (REQUIRED - users have no access by default!)
# Run: scripts/grant_permissions.sql as doadmin

# 3. Reference in app spec
```

```yaml
# .do/app.yaml
databases:
  - name: db
    engine: PG
    production: true
    cluster_name: my-app-db
    db_name: myappdb
    db_user: myappuser

services:
  - name: api
    envs:
      - key: DATABASE_URL
        scope: RUN_TIME
        value: ${db.DATABASE_URL}
```

**Full guide**: See [path-a-bindable-vars.md](reference/path-a-bindable-vars.md)

---

## Path B: Schema Isolation

Use when: Multi-tenant SaaS, multiple apps sharing one cluster, schema-level isolation needed.

### Quick Start

```bash
# Hands-free setup (requires gh CLI)
./scripts/secure_setup.sh \
  --admin-url "$ADMIN_URL" \
  --app-name myapp \
  --schema myapp \
  --repo owner/repo
```

Password flows directly to GitHub Secrets — never displayed.

**Full guide**: See [path-b-schema-isolation.md](reference/path-b-schema-isolation.md)

---

## Available Bindable Variables

| Variable | Example |
|----------|---------|
| `${db.DATABASE_URL}` | `postgresql://user:pass@host:25060/db?sslmode=require` |
| `${db.HOSTNAME}` | `my-db-do-user-123.db.ondigitalocean.com` |
| `${db.PORT}` | `25060` |
| `${db.USERNAME}` | `myappuser` |
| `${db.PASSWORD}` | (auto-populated) |
| `${db.DATABASE}` | `myappdb` |
| `${db.CA_CERT}` | (certificate content) |

---

## Scripts

| Script | Purpose |
|--------|---------|
| `scripts/secure_setup.sh` | Hands-free Path B setup with GitHub Secrets |
| `scripts/create_schema_user.py` | Create isolated schema + user |
| `scripts/list_schemas_users.py` | Audit existing schemas/users |
| `scripts/generate_connection_string.py` | Build connection strings |

---

## Reference Files

- **[path-a-bindable-vars.md](reference/path-a-bindable-vars.md)** — Full Path A workflow, connection pools, multi-app setup
- **[path-b-schema-isolation.md](reference/path-b-schema-isolation.md)** — Full Path B workflow, multi-tenant patterns
- **[orm-configurations.md](reference/orm-configurations.md)** — Prisma, SQLAlchemy, Drizzle, TypeORM configs
- **[database-migrations.md](reference/database-migrations.md)** — Alembic, Prisma Migrate, Drizzle Migrate
- **[doctl-reference.md](reference/doctl-reference.md)** — All `doctl databases` commands
- **[troubleshooting.md](reference/troubleshooting.md)** — Common errors and fixes
- **[bundled-scripts.md](reference/bundled-scripts.md)** — Script usage documentation

---

## Common Issues (Quick Fixes)

| Error | Fix |
|-------|-----|
| "permission denied for schema" | Run permission SQL as doadmin |
| "relation does not exist" | Check `search_path` or use schema-qualified names |
| "too many connections" | Create connection pool via doctl |
| "SSL connection required" | Add `?sslmode=require` to connection string |
| Bindable vars not populated | Verify `production: true` and names match exactly |

**Full troubleshooting**: See [troubleshooting.md](reference/troubleshooting.md)

---

## Integration with Other Skills

- **→ designer**: Add database block to app spec
- **→ deployment**: GitHub Actions workflow with DATABASE_URL secret
- **→ devcontainers**: Local Postgres with prod parity
- **→ troubleshooting**: Debug container for connectivity testing

Files in this skill

  • README.md4 KB
  • SKILL.md4.4 KB
  • reference/bundled-scripts.md2.6 KB
  • reference/database-migrations.md3.1 KB
  • reference/doctl-reference.md2.3 KB
  • reference/orm-configurations.md3.6 KB
  • reference/path-a-bindable-vars.md7.1 KB
  • reference/path-b-schema-isolation.md7 KB
  • reference/troubleshooting.md3.1 KB
  • scripts/add_client.py8.4 KB
  • scripts/cleanup_client.py6.1 KB
  • scripts/create_schema_user.py10.4 KB
  • scripts/generate_connection_string.py3.6 KB
  • scripts/get_admin_conn.sh2.2 KB
  • scripts/list_schemas_users.py4.5 KB
  • scripts/secure_setup.py9.9 KB
  • scripts/secure_setup.sh9.2 KB
  • templates/migrations/alembic.template.py4.5 KB
  • templates/orm/drizzle.template.ts4.3 KB
  • templates/orm/prisma.template.prisma1.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…