-
-
Notifications
You must be signed in to change notification settings - Fork 2
cmd db
Database operations: migrations, backups, restore, seed, shell.
nself db <subcommand> [flags]
Database operations: migrations, backups, restore, seed, and shell.
nself db migrate <subcommand> [flags]| Flag | Description |
|---|---|
--plugin <name> |
Scope migration operations to a specific plugin |
Apply all pending migrations in lexicographic order.
nself db migrate up [--dry-run] [--migration-dir <path>] [--plugin <name>]| Flag | Description |
|---|---|
--dry-run |
List pending migrations without applying them |
--migration-dir <path> |
Apply all .sql files in <path> in lexicographic order, skipping already-applied files |
Examples:
# Apply all pending migrations
nself db migrate up
# Preview pending migrations
nself db migrate up --dry-run
# Apply external directory of SQL files (G-008)
nself db migrate up --migration-dir /path/to/plugin/migrationsApply a single SQL migration file by path (G-008).
nself db migrate apply --file <path>| Flag | Required | Description |
|---|---|---|
--file <path> |
yes | Path to the .sql migration file to apply |
Double-apply protection: if the file's filename is already recorded in schema_versions, the command prints already applied: <filename> (skipped) and exits cleanly with code 0. It does not re-execute the SQL.
Checksum tracking: the SHA-256 checksum of the file is stored in nself_ops.migrations for audit purposes.
Non-transactional detection: SQL files containing CREATE INDEX CONCURRENTLY, DROP INDEX CONCURRENTLY, REINDEX CONCURRENTLY, or ALTER TYPE are run outside a transaction automatically.
Examples:
# Apply a specific external RLS migration
nself db migrate apply --file /path/to/plugin/rls_policy.sql
# Apply a migration from a plugin's migration directory
nself db migrate apply --file ~/.nself/plugins/claw/migrations/20240115_rls.sqlUse case: plugin-claw external RLS migrations can be applied via CLI without requiring nself db shell as a workaround.
Revert the most recently applied migration.
nself db migrate downLooks for a corresponding .down.sql file next to the original migration.
Show applied and pending migrations.
nself db migrate statusReports: migration name, status (applied/pending), and timestamp for applied migrations.
Create a new migration file pair (up + down).
nself db migrate create <name>Creates migrations/<timestamp>_<name>.sql and migrations/<timestamp>_<name>.down.sql.
Name must be lowercase alphanumeric with underscores or hyphens only.
Run seed data for the current environment.
nself db seed [file]
nself db seed run [--env <env>] [--fixture <name>] [--reset]
nself db seed list
nself db seed verify [--fixture <name>]
nself db seed graphnself db backup [file]
nself db backup list [--format table|json]nself db restore <file> [--overwrite] [--yes]Open an interactive psql shell inside the project's Postgres container.
nself db shellDrop the project database. This is destructive and irreversible.
nself db drop [--yes]Drop and recreate the project database from scratch.
nself db reset [--force] [--yes]Audit database schema and RLS policies.
nself db lint [--format table|json] [--rls] [--metric] [--matrix] [--remediate]Hasura metadata operations.
nself db hasura console
nself db hasura metadata apply
nself db hasura metadata export
nself db hasura metadata reload
nself db hasura diff
nself db hasura validate| Flag | Default | Description |
|---|---|---|
--help, -h
|
— | Show help |
| Name | Description |
|---|---|
backup |
Create pg_dump backup |
backup-sync |
Sync local backups to remote storage (cross-region) |
backup-sync-status |
Show cross-region backup sync status |
drift |
Schema drift detection: scan np_* tables for Theme 25 column compliance |
drop |
Drop the project database (DESTRUCTIVE) |
fk-index |
Audit and create indexes for foreign key columns |
hasura |
Hasura metadata operations |
lint |
Check RLS policies on tenant-scoped tables |
list |
List databases in the project Postgres instance |
migrate |
Manage database migrations |
pgbouncer |
PgBouncer connection pooler operations |
pitr |
Point-in-time recovery: status, enable, test, restore |
reconcile |
Push repo-declared Hasura metadata (permissions, relationships, table tracking) to a live instance |
reset |
Drop and recreate database (DESTRUCTIVE) |
reset-checksum |
Reset stored checksum for a migration (dangerous) |
restore |
Restore from backup |
restore-drill |
Run a non-destructive restore drill |
restore-drill-list |
List past restore drill results |
rls |
Row-Level Security management: audit, apply, rollback |
seed |
Database seeding: run, list, verify, graph |
shell |
Open psql interactive shell |
soft-delete |
Manage soft-delete (deleted_at) patterns across tables |
verify |
Verify what a Hasura role can actually reach via role-scoped introspection |
verify-checksums |
Verify migration file checksums against stored values |
# Apply all pending migrations
nself db migrate up
# Open an interactive psql shell inside the Postgres container
nself db shell
# Audit RLS policies and schema for tenant-scoped tables
nself db lint
# Take a local backup, then check migration status
nself db backup
nself db migrate status- Architecture — stack overview including migration engine
- cmd-plugin-dev — plugin development, including plugin-specific migrations
- cmd-backup — full backup subcommand reference
ɳSelf CLI v1.0.9. MIT licensed. Docs CC BY 4.0.
GitHub · Issues · Discussions · nself.org · nself.org/docs
Getting Started
Commands
- Commands, Overview
- Lifecycle: cmd-init · cmd-build · cmd-start · cmd-stop · cmd-restart · cmd-dev
- Monitoring: cmd-status · cmd-logs · cmd-health · cmd-urls · cmd-doctor · cmd-monitor · cmd-alerts · cmd-sentry · cmd-watchdog
- Data: cmd-db · cmd-backup · cmd-dr · cmd-queue · cmd-webhooks
- Config: cmd-config · cmd-service · cmd-env · cmd-promote
- Networking: cmd-ssl · cmd-trust · cmd-dns-setup
- Security: cmd-access · cmd-security · cmd-secrets
- Tenancy: cmd-tenant · cmd-billing
- Plugins: cmd-plugin · cmd-license · cmd-dogfood (extracted, CLI-R11) · cmd-k8s (extracted, CLI-R11) · cmd-encryption (extracted, CLI-R11) · cmd-waf (extracted, CLI-R11) · cmd-federation (extracted, CLI-R11) · cmd-mail (extracted, CLI-R11) · cmd-dlq (extracted, CLI-R11)
- AI: cmd-ai · cmd-claw · cmd-model
- Templates: cmd-template
- Utilities: cmd-exec · cmd-clean · cmd-reset · cmd-update · cmd-upgrade · cmd-version · cmd-admin · cmd-migrate · cmd-migrate-firebase · cmd-migrate-supabase · cmd-completion
Features
- Features, Overview
- Feature-Auth
- Feature-Storage
- Feature-Search
- Feature-Functions
- Feature-Email
- Feature-Monitoring
- Feature-Plugins
- Feature-nClaw, AI Assistant
- Feature-nChat, Messaging
- Feature-nTV, Media Player
- Feature-nFamily, Family Social
- Feature-nCloud, Managed Hosting
- Feature-Memory-Rooms, Knowledge Organization
- Feature-Agent-Dashboard, Agent Metrics
- Feature-Image-Generation, AI Image Generation
Configuration
- Configuration, Overview
- Config-Env-Vars
- Config-Postgres
- Config-Hasura
- Config-Auth
- Config-Nginx
- Config-Optional-Services
- Config-Custom-Services
- Config-System
Plugins (87 + 10 monitoring)
Free (25)
- plugin-backup
- plugin-content-acquisition
- plugin-content-progress
- plugin-cron
- plugin-donorbox
- plugin-feature-flags
- plugin-github
- plugin-github-runner
- plugin-invitations
- plugin-jobs
- plugin-link-preview
- plugin-mdns
- plugin-mlflow
- plugin-monitoring
- plugin-notifications
- plugin-notify
- plugin-paypal
- plugin-search
- plugin-shopify
- plugin-stripe
- plugin-subtitle-manager
- plugin-tokens
- plugin-torrent-manager
- plugin-vpn
- plugin-webhooks
Pro (62)
- plugin-access-controls
- plugin-activity-feed
- plugin-admin-api
- plugin-nself-ai-gateway
- plugin-nself-ai-mcp
- plugin-nself-ai-mcp
- plugin-analytics
- plugin-auth
- plugin-backup-pro
- plugin-bots
- plugin-browser
- plugin-calendar
- plugin-cdn
- plugin-chat
- plugin-claw
- plugin-claw-budget
- plugin-claw-news
- plugin-claw-web
- plugin-cloudflare
- plugin-cms
- plugin-compliance
- plugin-cron-pro
- plugin-ddns
- plugin-devices
- plugin-documents
- plugin-donorbox-pro
- plugin-entitlements
- plugin-epg
- plugin-file-processing
- plugin-game-metadata
- plugin-geocoding
- plugin-geolocation
- plugin-google
- plugin-home
- plugin-idme
- plugin-knowledge-base
- plugin-linkedin
- plugin-livekit
- plugin-media-processing
- plugin-meetings
- plugin-moderation
- plugin-mux
- plugin-notify-pro
- plugin-object-storage
- plugin-observability
- plugin-paypal-pro
- plugin-photos
- plugin-podcast
- plugin-post
- plugin-realtime
- plugin-recording
- plugin-retro-gaming
- plugin-rom-discovery
- plugin-shopify-pro
- plugin-social
- plugin-sports
- plugin-stream-gateway
- plugin-streaming
- plugin-stripe-pro
- plugin-support
- plugin-tmdb
- plugin-voice
- plugin-web3
- plugin-workflows
Planned (26)
plugin-auditplugin-blogplugin-checkoutplugin-commerceplugin-drmplugin-exportplugin-flowplugin-importplugin-ldapplugin-mailgunplugin-mediaplugin-oauth-providersplugin-pagesplugin-postmarkplugin-rate-limitplugin-reportsplugin-samlplugin-schedulerplugin-sendgridplugin-ssoplugin-subscriptionplugin-thumbplugin-transcoderplugin-twilioplugin-wafplugin-watermark
Guides
- Guide-Production-Deployment
- Guide-SSL-Setup
- Guide-Multi-Tenancy
- Guide-Security-Hardening
- Guide-Monitoring-Setup
- Guide-Backup-Restore
- Guide-Custom-Services
- Guide-Migration-from-v1
Architecture
Reference
- API-Reference
- error-codes, Error Codes
Licensing
Security
Brand
Operations
- operations/release-cascade, Release Cascade
- operations/self-healing, Self-Healing Schema
- operations/redis-tuning, Redis Pool Tuning
- operations/meilisearch-warmup, MeiliSearch Warm-Up
- operations/jwt-rotation, JWT Key Rotation
- operations/windows-wsl2-setup, Windows / WSL2 Setup
- operations/gemini-oauth-reauth, Gemini OAuth Reauth
Contributing
Admin
- USER-ACTION-QUEUE, Pending Admin Actions
All commands (52)
- A: cmd-access · cmd-account · cmd-admin
- B: cmd-backup · cmd-build · cmd-bundle
- C: cmd-ci · cmd-clean · cmd-completion · cmd-config
- D: cmd-db · cmd-deploy · cmd-dev · cmd-doctor
- E: cmd-env · cmd-exec
- F: cmd-functions
- G: cmd-generate
- H: cmd-health · cmd-help-topics
- I: cmd-init · cmd-install
- L: cmd-license · cmd-login · cmd-logout · cmd-logs
- M: cmd-man · cmd-mcp · cmd-migrate
- O: cmd-oauth · cmd-ops
- P: cmd-plugin · cmd-promote
- R: cmd-remove · cmd-reset · cmd-restart · cmd-runner
- S: cmd-secrets · cmd-security · cmd-self-heal · cmd-server · cmd-service · cmd-start · cmd-status · cmd-stop
- T: cmd-telemetry · cmd-template · cmd-trust
- U: cmd-update · cmd-urls
- V: cmd-verify-sbom · cmd-version