App workflow Metabase + Docker workloads

Deploy Metabase for internal reporting

Confirm source database access and security requirements before publishing dashboards. Check the named site's prerequisites, task result, backup scope and recovery handoff with xCloud.

Read this guide as Markdown

Requirements and responsibilities

Illustrative situation

An operations team wants a Metabase dashboard against its order database. It must avoid giving analysts write privileges or broader table access than needed.

Choose the approach

Dashboard and application procedure

Follow these steps yourself, or use the scoped AI handoff below for supported hosting operations.

Step 1 of 5

Define report and data scope

Where
Analytics owner and source database
Permissions
Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
Inputs
Required tables, freshness, authorized viewer group
Action
Write one concrete reporting question and list the minimum schemas and rows needed. Identify the database owner and approved network path.
Expected result
A narrow reporting contract.
Verify
Compare requested data with internal access policy.
If it fails
If sensitive tables are not needed, exclude them from the connection role.

Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries · Metabase database connections

Step 2 of 5

Deploy Metabase

Where
xCloud One-Click Apps dashboard
Permissions
Authorized xCloud site owner with dashboard rights for the exact setting, backup, staging or restore action and a reviewed target.
Inputs
Template, Docker server, HTTPS hostname
Action
Install the current Metabase template on a compatible server and secure first administrator access.
Expected result
A reachable Metabase admin UI.
Verify
Inspect app version, HTTPS and site ID.
If it fails
If the app starts but cannot persist settings, inspect its application database/storage.

Sources: xCloud One Click Apps catalog · xCloud agent capability boundaries

Step 3 of 5

Create a read-only connection

Where
Source DB admin and Metabase Admin → Databases
Permissions
Authorized Metabase application administrator or delegated role with rights for this task; hosting access alone is insufficient.
Inputs
Dedicated DB role, host, database, allowed schemas
Action
Grant the connector minimum SELECT rights, then add the database in Metabase with the least-privilege credentials. Keep secrets out of reports.
Expected result
A connection that can read only intended data.
Verify
Run a query against allowed table and verify an unauthorized table is denied.
If it fails
If Metabase cannot connect, check network and DB grants; do not grant superuser access as a shortcut.

Sources: Metabase database connections · Metabase data permissions

Step 4 of 5

Set Metabase group rights

Where
Metabase Admin → Permissions
Permissions
Authorized Metabase application administrator or delegated role with rights for this task; hosting access alone is insufficient.
Inputs
Analyst and viewer groups, collections
Action
Limit data and collection permissions, including All Users defaults. Give viewers only the saved report they need.
Expected result
A viewer sees the report without unrestricted query access.
Verify
Sign in as a viewer and inspect visible tables/questions.
If it fails
If hidden data is reachable, fix DB role and Metabase group permissions together.

Sources: Metabase database connections · Metabase data permissions

Step 5 of 5

Validate and protect reports

Where
Metabase question/dashboard and xCloud backup
Permissions
Authorized xCloud team/site operator with the discovered write scope for this exact operation and owner approval for its target and interruption.
Inputs
Known order count, date range, app backup
Action
Build one saved question, compare its result to a source-system count and add it to a dashboard. Check completed app backup and owner for schema changes.
Expected result
A correct sample dashboard with recovery ownership.
Verify
Repeat count after a controlled source update and verify freshness.
If it fails
If numbers disagree, investigate filters, time zone and sync before distributing the dashboard.

Sources: Back up and restore Docker apps · Docker backup operations and storage constraints · Metabase database connections

Maintenance

Recovery decisions

AI handoff

Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.

Supported scope

  • Confirm requirements and inspect resources mcp · read

    Discover the connected profile and operation schema first; only teams granted to the connection are visible.

    Checkpoint: Confirm exact team, server and site identity. Use dashboard_url returned by the resource; do not invent a dashboard link.

    Operation identifiers and scopes to discover

    teams.index, servers.show, sites.show

    Scopes: read:servers, read:sites

    xCloud MCP documentation and connection profiles · xCloud agent capability boundaries

Copyable agent brief

Manual checkpoints

  • Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
  • An authorized Metabase administrator must configure and test app users, content, integrations and business rules in the app.
  • Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
  • Reconcile data created after the chosen recovery point before any destructive restore.
Feature coverage

Sources

Continue

Explore all use cases