Skip to content

Sandboxes and queries

A sandbox is a private, throwaway database restored from a backup or from any second in the window. It is the default restore destination, because looking never risks production.

keeper restore team-a/app --at 2026-10-07T09:41:27Z --ttl 6h --wait
keeper sandbox list
keeper sandbox show <sandbox>

What a sandbox is

  • A database pod of the target's engine and version (spec.sandbox.image on the target), in Keeper's sandbox namespace, with generated credentials and a default-deny NetworkPolicy.
  • A TTL (sandbox.defaultTTL, at most sandbox.maxTTL, both per policy and chart-wide). When it expires, Keeper deletes the sandbox and its storage. keeper sandbox extend <sandbox> --by 24h buys more time; keeper sandbox delete <sandbox> ends it early.
  • Owned by whoever asked for it; every action on it is audited.

Querying

The console's Query page and keeper query run SQL through Keeper's query proxy, read-only by default:

keeper query <sandbox> -e "select count(*) from orders where created_at > now() - interval '1 day'"
keeper query <sandbox> -e "select * from coupons" -o csv > coupons.csv

Each query has a 30-second limit and returns at most 1,000 rows; --write allows writes (sandboxes only).

Connecting a client

In the cluster, the sandbox's host, port and credentials are in keeper sandbox show and in a secret next to it. From a laptop, with exposure turned on (expose.provider: cloudflare, restore with --expose):

keeper sandbox connect <sandbox>        # opens cloudflared access tcp and prints a connection string
psql "postgres://…@localhost:15432/app"

The route is protected by Cloudflare Access and disappears with the sandbox.