Blog
Operator field notes
Short, command-first guides for self-diagnosing the misconfigurations our agent can't catch from outside — open auth, plaintext transport, missing audit trails, EOL versions. Every command on this site has been run against a real cluster.
Latest posts
8 postsFour Security 101 deep dives, one per backend we support. Read, run, fix in under fifteen minutes per cluster.
- PrismGetting startedelkutils
How Prism works — keys, AI, billing, and security
Prism is a small program you run next to your databases. This guide explains API keys, how optional AI access works, how billing is metered, and why the design stays least-privilege.
Published 2026-08-26 · 7 min read
- Securitymonitor-agentZero knowledge
Zero-knowledge encryption for the monitor-agent
How the install script seals exporter addresses and passwords to a key that never leaves your host, what happens if you lose device.key, and how a second agent reuses the same file.
Published 2026-08-18 · 6 min read
- SupabaseSecurity 101PostgreSQLRLS
Supabase security: why healthy metrics do not prove RLS is safe
The hosted Metrics API proves the platform is running; catalog-only SQL advisors reveal public tables without RLS, broad anon grants, permissive policies, security-definer views, and PII-like column names.
Published 2026-08-14 · 8 min read
- PrometheusCustom exporterMonitor agent
Scrape any Prometheus `/metrics` endpoint with the monitor-agent
Point the monitor-agent at Traefik, node_exporter, or any app `/metrics` URL — with optional static labels and Bearer/Basic auth via host env vars (never stored in our DB).
Published 2026-08-11 · 7 min read
- MongoDBSecurity 101Tested on MongoDB 7.0
MongoDB with auth bolted on as an afterthought — fixing the four classic mistakes
Four checks and fixes for the misconfigurations a fresh mongod ships with: no authentication on by default, the bind-all-interfaces footgun, over-privileged exporter users, and an unprotected mongodb_exporter `:9216/metrics` endpoint.
Published 2026-06-03 · 9 min read
- PostgresSecurity 101Tested on PG 16
Postgres on the public internet — six checks before you sleep
Six self-diagnose commands and the fixes the Postgres docs forget to put on the same page. SSL, pg_hba trust, MD5 hashes, rogue superusers, idle-in-transaction storms, and the missing audit trail.
Published 2026-05-26 · 12 min read
- ClickHouseSecurity 101Tested on CH 24.3
ClickHouse with the default user wide open — fixing the four classic mistakes
Four checks and fixes for the misconfigurations ClickHouse self-installs ship with: default user with empty password, the XML-vs-SQL access-management gotcha, sustained authentication failures, and an unprotected :9363 Prometheus endpoint.
Published 2026-05-26 · 10 min read
- ElasticsearchOpenSearchSecurity 101Tested on ES 8.11
An open Elasticsearch on the internet — five checks before bedtime
Five self-diagnose curl commands and the fixes the Elastic docs split across six pages. xpack.security, EOL versions, single-node-pretending-to-be-HA, the cluster.routing.allocation footgun, and the no-replicas data-loss trap.
Published 2026-05-26 · 11 min read
Let the agent watch the rest
Most of these checks should happen once and then become an alert. Install the monitor-agent and get the operational guardrails — capacity, GC, shard skew, lag — covered automatically. Pay-per-use, $10 to start.