Skip to main content
One YAML file, midplane.yaml, named with --config. Relative paths in it are relative to the file. Secrets never appear inline: a DSN, the mask salt, the identity and the enrollment token each name an environment variable or a file, so the config itself can be committed.
Unknown keys are errors, and so is anything that doesn’t validate: the gateway won’t start on a config it can’t fully read.

Both modes

Local mode only (midplane local)

Linked mode only (midplane gateway)

Linked databases have no policy: policies come in signed bundles from Midplane Cloud.

The policy

A database’s policy, in local mode under databases.<id>.policy, in linked mode authored in the dashboard (which shows it as JSON too). Strict: an unknown key anywhere refuses the whole policy, never part of it.
Whatever the policy says, a statement must be one statement Midplane can parse and resolve; writes need a WHERE; writes hidden inside a WITH are denied; and reads run in read-only transactions. Tested by apps/gateway/test/config.test.ts (secrets and paths, TLS off loopback, public URLs, the salt, retention, unknown keys, both modes) and the core’s corpus (packages/corpus) for what a policy means.