Skip to content

Service drivers

The driver set is closed. A declaration naming a driver outside it is refused with unknown_service_driver, listing the drivers Onebox can run and directing you to a daemon workload.

That is deliberate: inventing an image from a name produces a container that starts and stores nothing durable.

The runtime and connection tables are generated from the private driver catalogue. The guidance and limitations below remain deliberately authored in the generator: they are product explanations, not facts the catalogue can prove.

DriverImage repositoryPortData pathURL schemeHealth check
clickhouseclickhouse/clickhouse-server8123/var/lib/clickhousehttpavailable
mariadbmariadb3306/var/lib/mysqlmysqlavailable
meilisearchgetmeili/meilisearch7700/meili_datahttpavailable
miniominio/minio9000/datas3available
mongodbmongo27017/data/dbmongodbavailable
mysqlmysql3306/var/lib/mysqlmysqlavailable
natsnats4222/datanatsnone
postgrespostgres5432/var/lib/postgresql/datapostgresavailable
rabbitmqrabbitmq5672/var/lib/rabbitmqamqpavailable
redisredis6379/dataredisavailable
valkeyvalkey/valkey6379/dataredisavailable
DriverTypical useConnection parts
clickhouseAnalytical databaseurl host port user password database
mariadbRelational databaseurl host port user password database
meilisearchSearchurl host port password
minioS3-compatible object storageurl host port user password
mongodbDocument databaseurl host port user password database
mysqlRelational databaseurl host port user password database
natsMessaging, JetStreamurl host port password
postgresRelational databaseurl host port user password database
rabbitmqMessage brokerurl host port user password
redisCache, queueurl host port user password
valkeyCache, queueurl host port user password

A part the driver does not have — a database on a cache — is omitted rather than written empty. Every driver has a password part; redis and valkey have a user part because Redis 6+ authenticates the built-in default user, and a URL with an empty username fails AUTH outright.

services:
postgres: 17

The image, a durable volume, a health check (every driver but nats), a credential generated on the target, and the connection details your application reads.

  • The service outlives every release. Its own Compose project; no deploy and no rollback stops it or removes its volume.
  • The credential is generated on the server, once. Not in your project, the generated runtime, or the digest. Never rotated by a re-apply.
  • The version binds into the release digest, so a database upgrade under an untouched application cannot pass unnoticed.
services:
postgres:
version: 17
settings:
max_connections: 200

A setting is applied through the mechanism its driver actually reads. One the driver has no way to apply is refused with service_settings_unsupported, rather than silently ignored.

Run it as a daemon workload and you own it: the image, the credential, the volumes, the backup. See Add a database for the comparison.