Connect PostgreSQL
Connect a PostgreSQL database with a read-only user, optionally through an SSH tunnel or PrivateLink, and choose between cached and live query modes.
The PostgreSQL connector reads tables and views from one or more schemas. Kimo never writes to your database: it only needs SELECT on the objects you want to model, plus access to information_schema to discover columns and keys.
Create a read-only user
Run the following as a superuser or the owner of the schema. Replace the password and schema names with your own. Using a dedicated role makes it easy to audit and revoke Kimo’s access later.
CREATE ROLE kimo_reader WITH LOGIN PASSWORD 'change-me';GRANT CONNECT ON DATABASE app TO kimo_reader;GRANT USAGE ON SCHEMA public, billing TO kimo_reader;GRANT SELECT ON ALL TABLES IN SCHEMA public, billing TO kimo_reader;-- Keep future tables readable tooALTER DEFAULT PRIVILEGES IN SCHEMA public, billing GRANT SELECT ON TABLES TO kimo_reader;Add the source in Kimo
- 1Open Connectors → Add source → PostgreSQL
Give the source a name people will recognize, such as "Production DB (replica)".
- 2Enter connection details
Host, port (default
5432), database, user and password. Kimo requires TLS; choose verify-full and paste your CA certificate if your provider uses a private CA. - 3Pick schemas and tables
Kimo lists every schema the user can see. Select the ones to sync; you can add more later without re-authenticating.
- 4Choose a query mode
See the table below. You can switch modes at any time; switching to cached triggers a full initial sync.
| Mode | How it works | Use when |
|---|---|---|
| Cached (default) | Incremental syncs into Kimo’s columnar cache every 15 min. | Most analytics; protects your primary from heavy queries. |
| Live | Queries are pushed down to Postgres at view time. | Read replicas, small tables, data that must never leave the network. |
| Hybrid | Large fact tables cached, small dimension tables live. | Big event tables joined to frequently edited reference data. |
Private networks
If the database is not reachable from the internet, use one of three options. SSH tunnel: Kimo connects through a bastion host with a key it generates for you. AWS PrivateLink / GCP Private Service Connect: available on Business and Enterprise. Kimo Agent: a small container you run inside your network that opens an outbound-only connection, ideal for on-prem databases.
docker run -d --name kimo-agent --restart unless-stopped \ -e KIMO_AGENT_TOKEN=agt_live_3f9c… \ -e KIMO_REGION=eu \ ghcr.io/kimo/agent:2.14Troubleshooting
| Error | Likely cause |
|---|---|
28P01 password authentication failed | Wrong password, or pg_hba.conf rejects the IP. |
42501 permission denied for table | Missing GRANT SELECT or default privileges. |
timeout expired | Firewall: allowlist Kimo egress IPs or use the agent. |
SSL off | Server does not accept TLS; enable ssl = on. |
Impact on your database
Kimo is designed to be a polite guest. Incremental syncs read only rows whose cursor moved, run with a statement_timeout of 5 minutes and use at most two concurrent connections per source by default. On the first sync, large tables are read in primary-key ranges of 50,000 rows so no single query holds locks for long. If you can, point Kimo at a read replica: replication lag of a few seconds is invisible on dashboards and your primary never sees analytics traffic.
application_name = kimois set automatically, so you can filter Kimo sessions inpg_stat_activity.- Raise or lower concurrency under Source → Advanced → Max connections.
- Logical replication (CDC) is available on Enterprise for tables that change faster than every 5 minutes.
