# Operate a self-hosted database workload

Review exposure, backup strategy, access, version changes, and restore validation. Check the named site's prerequisites, task result, backup scope and recovery handoff with xCloud.

Canonical: https://xcloud.host/use-cases/operations/operate-a-self-hosted-database-workload/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Review exposure, backup strategy, access, version changes, and restore validation.
For: site-owner, administrator

## Requirements and responsibilities

- Name the team, server, hostname, owner and affected users for the Postgresql application. Record the current version and the actual business flow that must survive the change. Confirm the current dashboard form, plan eligibility, and server capacity before committing a resource change. A one-click catalog listing is discovery, not permission or proof that the connected MCP profile can install it. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html); [PostgreSQL SQL dump and restore](https://www.postgresql.org/docs/current/backup-dump.html); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- Prepare a non-sensitive test input and an acceptance record. Keep access to the app administrator and an independent observer where possible; omit secrets from AI prompts and client reports. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html); [PostgreSQL SQL dump and restore](https://www.postgresql.org/docs/current/backup-dump.html); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- For a Docker app, identify persistent volumes, bind mounts, external databases and app-level export requirements. A Docker backup briefly stops the app, and an in-place restore replaces current state. Agree a maintenance window and owner before any action that interrupts the service or overwrites data. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html); [PostgreSQL SQL dump and restore](https://www.postgresql.org/docs/current/backup-dump.html); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

## Illustrative situation

A team runs a PostgreSQL one-click workload for an internal app. It needs least-privilege access and a logical backup whose restore succeeds independently of a container snapshot.

## Choose the approach

- Expose PostgreSQL only to required application networks; public reachability is a separate approved decision. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html); [PostgreSQL SQL dump and restore](https://www.postgresql.org/docs/current/backup-dump.html); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- A stopped Docker snapshot can be useful, but a tested PostgreSQL-consistent logical dump and role plan are needed for database recovery claims. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html); [PostgreSQL SQL dump and restore](https://www.postgresql.org/docs/current/backup-dump.html); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

## Dashboard and application procedure

### 1. Identify the running database

**Where:** xCloud Docker site and PostgreSQL server

**Permissions:** Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.

**Inputs:** Template, PostgreSQL version, volume path, listen address

**Action:** Confirm the actual database template, version, storage and network exposure. Record application dependencies and current error status.

**Expected result:** A concrete instance and exposure map.

**Verify:** Compare app connection target with configured host/port without revealing passwords.

**If it fails:** If the database is publicly exposed unintentionally, restrict access before other work.

Capability: Confirm requirements and inspect resources
Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html)

### 2. Review roles and grants

**Where:** PostgreSQL role catalog and app connection config

**Permissions:** Authorized Postgresql application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** App role, database, schema, allowed operations

**Action:** List roles and privileges. Use a dedicated test/app role with only needed CONNECT, schema usage and table rights; avoid superuser shortcuts.

**Expected result:** A least-privilege access plan.

**Verify:** Run an allowed SELECT and a denied operation with the test role.

**If it fails:** If the role can modify unrelated schemas, reduce grants and retest.

Capability: Configure and test Postgresql in its application UI
Sources: [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html); [PostgreSQL SQL dump and restore](https://www.postgresql.org/docs/current/backup-dump.html)

### 3. Create a logical recovery point

**Where:** PostgreSQL pg\_dump and secure backup storage

**Permissions:** Authorized Postgresql application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Database name, dump format, storage, maintenance owner

**Action:** Using authorized database credentials and the version-appropriate client, create a pg\_dump archive or SQL dump. Protect it and separately record cluster roles required for restore.

**Expected result:** A PostgreSQL-consistent logical backup with timestamp.

**Verify:** Check dump command exit status, file size and format; never log credentials.

**If it fails:** If dump fails, fix permissions/storage and do not substitute an unverified raw copy.

Capability: Configure and test Postgresql in its application UI
Sources: [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html); [PostgreSQL SQL dump and restore](https://www.postgresql.org/docs/current/backup-dump.html)

### 4. Restore into isolation

**Where:** Separate PostgreSQL test instance

**Permissions:** Authorized Postgresql application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Dump, test roles, empty target database

**Action:** Create an empty isolated target with required roles, restore with psql for plain SQL or pg\_restore for an archive, then compare schema and selected row counts.

**Expected result:** A demonstrated database restore.

**Verify:** Run representative app read and write tests against the test DB only.

**If it fails:** If ownership or extensions fail, correct test prerequisites and update runbook.

Capability: Configure and test Postgresql in its application UI
Sources: [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html); [PostgreSQL SQL dump and restore](https://www.postgresql.org/docs/current/backup-dump.html)

### 5. Set ongoing operations

**Where:** xCloud Docker Backup and database runbook

**Permissions:** Authorized xCloud team/site operator with the discovered write scope for this exact operation and owner approval for its target and interruption.

**Inputs:** Dump cadence, volume snapshot, upgrade window

**Action:** Document both Docker snapshot scope and logical dump schedule, credential rotation, access review and upgrade rehearsal. Test recovery after version changes.

**Expected result:** A database-specific maintenance owner and recovery path.

**Verify:** Check latest dump and Completed Docker backup independently.

**If it fails:** If app and DB snapshots have different times, define reconciliation before restoring either.

Capability: Create and inspect Docker backups
Sources: [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html)

## Maintenance

- Review this task after app or template updates and at the cadence agreed with the owner. Record failures as dated observations rather than assuming host health proves service health. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html); [PostgreSQL SQL dump and restore](https://www.postgresql.org/docs/current/backup-dump.html); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- Watch access changes, backup completion, free storage and external providers. Recheck integrations after credential, DNS, mail or source-data changes. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html); [PostgreSQL SQL dump and restore](https://www.postgresql.org/docs/current/backup-dump.html); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

## Recovery decisions

- Before data recovery, identify incident time, completed backup, target and records created after the snapshot. Preserve current evidence and live data before replacement. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html); [PostgreSQL SQL dump and restore](https://www.postgresql.org/docs/current/backup-dump.html); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)
- Use the documented dashboard or application recovery procedure with the authorized owner. Repeat the task-specific limited-user check; reconcile newer records before reopening writes. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html); [PostgreSQL SQL dump and restore](https://www.postgresql.org/docs/current/backup-dump.html); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/); [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md); [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/)

## AI handoff

Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### Copyable agent brief

```text
Read exact PostgreSQL site/server, version and backup metadata. Return network exposure and storage questions. Do not request DB passwords or claim a volume snapshot is consistent; DB admin tests roles, pg_dump and isolated restore.
```

### Manual checkpoints

- Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
- An authorized Postgresql administrator must configure and test app users, content, integrations and business rules in the app.
- Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
- Reconcile data created after the chosen recovery point before any destructive restore.

## Feature coverage

- **database-ops decision, evidence and task action** (covered): The procedure identifies the authorized task boundary and observable result. Steps: step-1, step-2, step-3, step-4
- **backup, ongoing operation and recovery** (covered): Recovery and maintenance are checked in the task procedure. Steps: step-4, step-5

## Sources

- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [PostgreSQL database roles](https://www.postgresql.org/docs/current/database-roles.html) — reviewed 2026-09-30
- [PostgreSQL SQL dump and restore](https://www.postgresql.org/docs/current/backup-dump.html) — reviewed 2026-09-30
- [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/) — reviewed 2026-09-30
- [Docker backup operations and storage constraints](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/skills/sites/reference/docker-backups.md) — reviewed 2026-09-30; v4.4.2
- [xCloud One Click Apps catalog](https://xcloud.host/one-click-apps/) — reviewed 2026-09-30

## Continue

[Explore all use cases](https://xcloud.host/use-cases/)

- [Back up and recover a Docker application](https://xcloud.host/use-cases/operations/docker-backup-and-recovery/)
