Service dashboards: Postgres, Redis, NATS and more
See every service your app uses on one card: status, size, backups and its connection URL, then browse Postgres, Redis, NATS or ClickHouse data, read-only.
Last updated 2026-10-09
On this page
The Services tab shows one card per database or service your app uses, from PostgreSQL and Redis to NATS, ClickHouse and Prometheus. Each card says whether the service is running, how big it is, when it was last backed up, and how to connect. Where ox can read the service, a Browse button opens a read-only view of its data.
What a service card shows
- Status: Running, Stopped or Failed. A failed service shows the reason on the card, and Logs opens its log.
- Version, memory, disk and connections, when the service reports them.
- Backup: when the last daily backup ran, or Off. Backups and restore covers restoring one.
- Connection: the variable your app reads, like
DATABASE_URL. Its value stays hidden until you click the eye, and that click is written to your audit log, the same as on the Variables tab. The copy button copies the revealed value. - More: backups, variables, logs, and a link to this page for that service.
Browse a service's data
The Browse button names what it opens: tables, keys, indexes, streams, collections or metrics. Every view reads only, shows a bounded page of rows, and cuts long values. Some kinds also have a query box:
| Kind | What you see | Query box |
|---|---|---|
| PostgreSQL | Tables, their size and rows, and activity | Read-only SQL |
| MySQL, MariaDB, SQLite | Tables, their size and rows | None yet |
| ClickHouse | Tables with engine, rows and size | One SELECT, SHOW, DESCRIBE or EXPLAIN, run with readonly=1, 5 seconds and 500 rows at most |
| Redis, Valkey | Keys and their values | Read-only commands |
| Memcached | Hit rate, items and connections | None |
| Prometheus, VictoriaMetrics | Scrape targets, series count and metric names | One instant PromQL query, 5 seconds and 500 series at most |
| NATS | JetStream streams with messages, size and consumers | None. Messages are never read. |
| Meilisearch, Typesense, Elasticsearch, OpenSearch | Indexes and document counts | A search |
| Neo4j | Labels and their nodes | Read-only Cypher |
| Qdrant, Chroma | Collections, point counts and sample points | Read-only point queries (Qdrant) |
A few pages can also change data, like deleting a Redis key or cancelling a Postgres query. Those stay off until you press Allow changes, which lasts 15 minutes, and every change is written to your audit log.
Why services stay private
ox binds every service to 127.0.0.1, so only your app and ox on the same server reach it. Many of these services, like Prometheus, Memcached and Chroma, have no password at all, and a public port would hand your data to anyone. ox never opens a service's port to the internet, and does not proxy a service's own admin UI. When you need one, run it as a custom service and give it a domain with its own login.
Add a service ox does not build in
Any service with a Linux binary or an apt package can run as a custom service: a [services.<name>] entry with a run command. It gets a card like any other. ox knows which service it is from its tool, packages or run, and explore = "nats" names the browser when none of those does.
[services.bus]
run = "nats-server -js -a 127.0.0.1 -p $PORT -sd $SERVICE_DATA_DIR --auth $SERVICE_PASSWORD"
packages = ["nats-server"]
provides = { NATS_URL = "nats://${password}@${host}:${port}" }The 50 most common services
A built-in type is a type in ox.toml; a custom service is a run entry as above. Opens is what its Browse button shows; Card means the card and its connection details only.
| Service | Opens | How ox runs it |
|---|---|---|
| PostgreSQL | Tables | Built-in type: a database on the shared cluster or a private one, with tables, read-only SQL and activity. |
| MySQL (MariaDB) | Tables | Built-in type served by MariaDB, private only, with a table browser and activity. |
| SQLite | Tables | A file the app keeps in [storage] keep: ox lists its tables and backs it up with SQLite's own backup. |
| Valkey | Keys | Custom service from apt valkey-server: the Redis key browser reads it. |
| Redis | Keys | Built-in type: an index on the shared instance or a private one, with a key browser and a command console. |
| MongoDB | Card | No server package for Ubuntu 26.04 yet, so ox cannot run it; use PostgreSQL's jsonb meanwhile. |
| MariaDB | Tables | The mysql type runs MariaDB: same table browser. |
| OpenSearch | Indexes | The Elasticsearch explorer reads it; there is no install path on Ubuntu 26.04 yet. |
| Elasticsearch | Indexes | Index list and a read-only search; the vendor apt repo is its only install path, which ox does not add. |
| Memcached | Keys | Custom service from apt memcached: hit rate, items and connections. It has no auth, so it stays on 127.0.0.1. |
| RabbitMQ | Card | Custom service from apt rabbitmq-server: the card and the connection details; its management UI has no safe path yet. |
| Prometheus | Metrics | Custom service: scrape targets, series names and a read-only PromQL box. It has no auth, so it stays on 127.0.0.1. |
| Grafana | Card | Only in the vendor apt repo, which ox does not add; point a domain at it yourself once that changes. |
| InfluxDB | Card | Ubuntu ships 1.6, which is old: the card only. VictoriaMetrics is the better pick. |
| Neo4j | Graph | Built-in type: label counts, a node browser and read-only Cypher. |
| ClickHouse | Tables | Custom service: table list with rows and size, and read-only SQL with readonly=1 on every request. |
| Cassandra | Card | Multi-node by design and heavy on memory: ox does not claim it. |
| Meilisearch | Indexes | Custom service: index list with document counts and a search box, with the generated master key. |
| Qdrant | Collections | Built-in type: collections, point counts and sample points. |
| pgvector | Tables | Wired into the postgres type: vectors show in the Postgres browser. |
| Typesense | Indexes | Collections and a search box; its .deb is not on apt or GitHub, so there is no install path yet. |
| Chroma | Collections | Custom service: collections with counts and a peek. It has no auth by default, so it stays on 127.0.0.1. |
| Kafka | Card | A JVM tarball only: ox does not claim it. NATS JetStream or Redis streams fit one server. |
| MinIO | Card | No Linux binaries since 2025-10; SeaweedFS is the S3 store ox runs. |
| SeaweedFS | Card | Custom service from its GitHub release: the card and the S3 connection details. |
| NATS | Streams | Custom service from apt nats-server: JetStream streams with messages, bytes and consumers, read over its own protocol. |
| PostGIS | Tables | Ubuntu ships it for PostgreSQL 18; ox does not create the extension yet. |
| TimescaleDB | Tables | Needs a preload that touches every project on a shared cluster, so private mode only, and not wired yet. |
| PgBouncer | Card | Custom service from apt: the card and the connection details. |
| Mailpit | Card | Custom service: the card. Captured mail can hold secrets, so its UI stays on 127.0.0.1. |
| Keycloak | Card | A Java zip that wants about 1 GB: ox does not claim it. Zitadel or Ory Kratos fit. |
| Loki | Card | Custom service: the card and the push URL. ox's own log explorer already reads the journal. |
| VictoriaMetrics | Metrics | Custom service: series names and read-only PromQL through its Prometheus API. |
| Weaviate | Card | Custom service from its GitHub release: the card and the connection details. |
| Mosquitto | Card | Custom service from apt: the card. Set allow_anonymous false and a password file. |
| Celery | Workers | A worker, not a service: its page lists workers and their tasks over the Redis broker. |
| DuckDB | Card | A file the app keeps: [storage] keep backs it up; ox has no DuckDB browser yet. |
| Temporal | Card | Custom service in dev-server mode: the card and the frontend address. |
| Zitadel | Card | Custom service on PostgreSQL: the card. Its console is reached through a domain you set. |
| Ory Kratos | Card | Custom service: the card. Only its public API goes on a domain, never the admin API. |
| OpenBao | Card | Custom service: the card. ox never stores its unseal keys. |
| Centrifugo | Card | Custom service: the card; keep its admin UI off. |
| ntfy | Card | Custom service: the card. Start it with auth-default-access deny-all. |
| PocketBase | Card | Custom service: the card. Its admin UI has no safe path yet. |
| Gitea | Card | Custom service: the card, with registration off. |
| Postfix | Card | Custom service: the card. Many providers block port 25, so an email API is usually simpler. |
| Garage | Card | Its binaries have no verified fetch path; SeaweedFS is the S3 store ox runs. |
| Redpanda | Card | Only its CLI is on GitHub: no install path. |
| Supabase | Card | Docker Compose only: ox does not claim it. PostgreSQL plus an auth service covers it. |
| SQL Server | Card | No package for Ubuntu 26.04 and it needs 2 GB: ox does not claim it. |
When a service does not start, Troubleshooting lists the messages ox prints, and Logs shows its own output.