Skip to content

ReferenceThe 22 checks

Database connections

Data location checkdatabase-connections

What it reads

The database hosts in env files, Compose files and connection settings in the folders under secrets.paths. Only the host and port are kept, never the user or password.

Does it need root?

It needs root for part of what it reads. Other users' files and /root can be read only by root. Without root, that part is skipped and never counted as passed. Run sudo kiyesi scan to include it.

When it passes

The report lists it as passed, in these words:

  • count database hosts checked, none outside home
  • No database connection settings found

What it can find

InfoReported as likely

Database host is in place, outside home

The region in the host's name places this database in place. Names can mislead, so this is likely, not confirmed.

Fix
Move the database to a region inside home, or check with the provider where it is