Sandboxes and queries¶
A sandbox is a private, throwaway database restored from a backup or from any second in the window. It is the default restore destination, because looking never risks production.
keeper restore team-a/app --at 2026-10-07T09:41:27Z --ttl 6h --wait
keeper sandbox list
keeper sandbox show <sandbox>
What a sandbox is¶
- A database pod of the target's engine and version (
spec.sandbox.imageon the target), in Keeper's sandbox namespace, with generated credentials and a default-deny NetworkPolicy. - A TTL (
sandbox.defaultTTL, at mostsandbox.maxTTL, both per policy and chart-wide). When it expires, Keeper deletes the sandbox and its storage.keeper sandbox extend <sandbox> --by 24hbuys more time;keeper sandbox delete <sandbox>ends it early. - Owned by whoever asked for it; every action on it is audited.
Querying¶
The console's Query page and keeper query run SQL through Keeper's query proxy, read-only by default:
keeper query <sandbox> -e "select count(*) from orders where created_at > now() - interval '1 day'"
keeper query <sandbox> -e "select * from coupons" -o csv > coupons.csv
Each query has a 30-second limit and returns at most 1,000 rows; --write allows writes (sandboxes only).
Connecting a client¶
In the cluster, the sandbox's host, port and credentials are in keeper sandbox show and in a secret next to it. From
a laptop, with exposure turned on (expose.provider: cloudflare, restore with --expose):
keeper sandbox connect <sandbox> # opens cloudflared access tcp and prints a connection string
psql "postgres://…@localhost:15432/app"
The route is protected by Cloudflare Access and disappears with the sandbox.