# Configure Isolated Database Branches with mirrord

Shared databases make migration testing and development experiments difficult to isolate. This skill helps configure mirrord branches with separate connections, controlled data copying, and validation guidance.

## Install

```bash
npx skillstore add metalbear-co/mirrord-db-branching
```

## Metadata

- Status: approved
- Slug: metalbear-co-mirrord-db-branching
- Version: 2.7
- Author version: 2.7
- Skillstore revision: r1
- Version status: invalid
- Tree hash: 23c7139189cecd185b971fdcb55cbb9329b2e433ac9bb698f9872d5f3c3e350e
- Author: metalbear-co
- GitHub username: metalbear-co
- License: MIT
- Repository: https://github.com/metalbear-co/skills/tree/a0ad7ca50ffb241a1c4f9c6a05d17661d5d658a5/skills/mirrord-db-branching
- Ref: bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: confirmation\_required
- Manual install advisory: allowed
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: env\_access, external\_commands, network, filesystem
- Quality score: 38
- Quality tier: warning
- Public page: https://skillstore.pages.dev/skills/metalbear-co-mirrord-db-branching
- Manifest: https://skillstore.pages.dev/api/skills/metalbear-co-mirrord-db-branching/manifest

## Capabilities

- Generate mirrord configurations for SQL databases, MongoDB, Redis, DynamoDB, Spanner, S3, and custom container services.
- Map connection variables through environment references, Kubernetes Secrets, ConfigMaps, and supported cloud secret managers.
- Explain empty, schema, full, and engine-specific filtered copy options.
- Configure Flyway, Liquibase, or container migrations for supported SQL engines.
- Explain AWS RDS and GCP Cloud SQL IAM settings, plus DynamoDB authentication requirements.
- Guide configuration validation, branch status checks, branch removal, and troubleshooting.

## Use Cases

- Test Application Migrations: Prepare a PostgreSQL or MySQL branch with the required schema and migration history before testing application changes.
- Build Focused Test Datasets: Configure engine-specific filters to copy approved records into temporary branches for integration tests.
- Standardize Branch Configuration: Review engine prerequisites, IAM sources, generic image policies, and storage settings for shared development clusters.

## Prompt Templates

### Create an Empty PostgreSQL Branch

```
Generate a minimal PostgreSQL 16 branch configuration using DATABASE_URL as the variable name. Start empty and explain the prerequisites and validation command.
```

### Copy Selected Test Records

```
Configure a PostgreSQL schema branch for app_db using DATABASE_URL. Copy users only where email ends with @test.com, and explain compatible copy modes.
```

### Prepare Branch Migrations with IAM

```
Configure PostgreSQL branching for AWS RDS IAM with Flyway migrations from ./migrations. Preserve migration history when copying schema and reference credentials without displaying values.
```

### Review a Generic Branch Design

```
Review my generic branch configuration against the bundled schema. Check approved images, copy Job readiness, secret-backed parameters, unique branch IDs, and version compatibility. Propose changes without executing workloads.
```

## Limitations

- Remote branching requires compatible mirrord tooling, a licensed Team or Enterprise operator, and enabled engine features.
- Local Redis branches start empty and require a working container runtime or Redis server.
- Bundled schema and prose can differ across versions; validate generated configurations with the installed mirrord CLI.
- Branching does not automatically sanitize copied data or guarantee secure credentials, network isolation, or transport encryption.

## Best Practices

- Confirm engine versions and connection variable names, then validate every generated configuration with mirrord verify-config.
- Use secret references and approved images; keep credential values out of prompts, configurations, and diagnostic output.
- Prefer empty or narrowly filtered copies, unique branch IDs, and limited lifetimes for authorized test data.

## Anti Patterns

- Copying full production datasets when schema or approved test records would suffice.
- Assuming SQL table filters still apply when the copy mode is all.
- Reusing sample administrator passwords or printing remote environment values during troubleshooting.

## Security Audit

- Audited at: 2026-09-29T21:35:48.738\+00:00
- Summary: All 400 presented static matches are false positives involving documentation, configuration references, or Kubernetes variable expansion. Two semantic risks remain: credential-bearing diagnostic output and a predictable administrator password in a generic branch example. The analyzer reports 59 additional matches outside this catalog; they still require manual review before automatic publication. Static review was capped at 400/459 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

## Stats

- Views: 0
- Downloads: 3
- Favorites: 0
- Popularity score: 0
