Quickstart
1. Create a read-only role
Connect as an admin and run:
create role checkup_reader login password 'choose-a-strong-password';
grant pg_monitor to checkup_reader;
Any name works except one starting with pg_, which Postgres reserves. pg_monitor is a built-in Postgres role that can read statistics views (pg_stat_activity, pg_stat_statements, and so on). It cannot read your table data and cannot write.
2. (Recommended) enable pg_stat_statements
Query-level findings need this extension.
create extension if not exists pg_stat_statements;
On self-managed Postgres you must also add pg_stat_statements to shared_preload_libraries and restart. Managed hosts usually preload it; see Connecting.
3. Run the check
Open /scan, paste postgres://checkup_reader:password@host:5432/dbname and press Run checkup. A scan takes a few seconds.
What you get
The report is a console for your database, with a sidebar listing each area we inspected: Queries, Tables, Indexes, Blocked transactions, Connections, Replication & WAL, Vacuum & bloat, Configuration, Logs & activity, Security and Extensions. Each area has interactive tables (sort, filter, click a row to expand), and each finding links to the data behind it.
- Free: the severity summary, vital signs, your three most severe findings in full, and the first five rows of every table.
- Full report ($9): every finding with evidence, every row of every table, a PDF to share, and CSV and markdown export.
Optional grants (more checks)
Two extra checks need a little more access. Both are optional and neither reads your table contents:
-- lets us check sequences (integer primary keys running out of numbers)
grant select on all sequences in schema public to checkup_reader;
-- measures real table bloat (cheap: uses the visibility map)
create extension if not exists pgstattuple;
Without them those checks are shown as skipped, with the reason, rather than guessed.
Connection tips
- Use a direct connection or a session-mode pooler, not a transaction-mode pooler.
- The database must be reachable from the internet. If access is restricted by IP address, the scan can't connect.
- TLS: for remote hosts we try an encrypted connection first and only fall back to plaintext if the server refuses TLS (you'll get a warning). The default mode encrypts but does not verify the server certificate. Add
?sslmode=require(or stricter) to control this yourself.
When checks are skipped
If your role lacks a privilege or an extension is missing, that check is skipped and listed at the bottom of the report. The rest of the scan still runs.