pg-checkup
Workspace
HomeReports
Learn
OverviewQuickstartChecks referenceConnectingTools that helpSecurity & privacyFAQ
Help
File a ticketRequest a featurePricing
PrivacyTerms
Docs/Quickstart
Sign inNew checkupC

Quickstart

1. Create a read-only role

Connect as an admin and run:

create role checkup_reader login password 'choose-a-strong-password';
grant pg_monitor to checkup_reader;

Any name works except one starting with pg_, which Postgres reserves. pg_monitor is a built-in Postgres role that can read statistics views (pg_stat_activity, pg_stat_statements, and so on). It cannot read your table data and cannot write.

2. (Recommended) enable pg_stat_statements

Query-level findings need this extension.

create extension if not exists pg_stat_statements;

On self-managed Postgres you must also add pg_stat_statements to shared_preload_libraries and restart. Managed hosts usually preload it; see Connecting.

3. Run the check

Open /scan, paste postgres://checkup_reader:password@host:5432/dbname and press Run checkup. A scan takes a few seconds.

What you get

The report is a console for your database, with a sidebar listing each area we inspected: Queries, Tables, Indexes, Blocked transactions, Connections, Replication & WAL, Vacuum & bloat, Configuration, Logs & activity, Security and Extensions. Each area has interactive tables (sort, filter, click a row to expand), and each finding links to the data behind it.

  • Free: the severity summary, vital signs, your three most severe findings in full, and the first five rows of every table.
  • Full report ($9): every finding with evidence, every row of every table, a PDF to share, and CSV and markdown export.

Optional grants (more checks)

Two extra checks need a little more access. Both are optional and neither reads your table contents:

-- lets us check sequences (integer primary keys running out of numbers)
grant select on all sequences in schema public to checkup_reader;
-- measures real table bloat (cheap: uses the visibility map)
create extension if not exists pgstattuple;

Without them those checks are shown as skipped, with the reason, rather than guessed.

Connection tips

  • Use a direct connection or a session-mode pooler, not a transaction-mode pooler.
  • The database must be reachable from the internet. If access is restricted by IP address, the scan can't connect.
  • TLS: for remote hosts we try an encrypted connection first and only fall back to plaintext if the server refuses TLS (you'll get a warning). The default mode encrypts but does not verify the server certificate. Add ?sslmode=require (or stricter) to control this yourself.

When checks are skipped

If your role lacks a privilege or an extension is missing, that check is skipped and listed at the bottom of the report. The rest of the scan still runs.

PreviousOverviewNextChecks reference