{
  "id": "osc-stack-provision-agent-backend",
  "job": "Have your AI coding tool (Claude Code, Codex or any MCP client) set up the database, object storage and supporting tools your project needs, on open-source services, and hand back the connection details, without opening a cloud console. Your code runs wherever you already run it.",
  "aliases": [
    "ai agent provisions database and storage",
    "let claude code set up postgres and s3",
    "backend services for my agent-built project",
    "provision postgres and object storage from an mcp client"
  ],
  "distinctFrom": [
    {
      "stack": "deploy-agent-written-app",
      "difference": "That stack RUNS the agent's code as a My App (create-my-app). This one stops at provisioning: no create-my-app step, and the app runs anywhere."
    },
    {
      "stack": "data-pipeline-orchestration",
      "difference": "That stack schedules ETL with Airflow over MinIO and PostgreSQL. This one hands the same two services to an application, with no scheduler."
    }
  ],
  "inputs": [
    {
      "protocol": "MCP",
      "source": "an MCP client connected to https://mcp.osaas.io/mcp (operator mode: read tools via osc_call_tool, writes via osc_write_tool)"
    }
  ],
  "outputs": [
    {
      "protocol": "postgresql",
      "consumer": "the user's app, wherever it runs",
      "reachability": "public TCP endpoint (IP:port) when created with public access. All 14 birme-osc-postgresql instances in the author's workspace report publicAccess=true (list-service-instances, 2026-10-09); create-database defaults to internal-only unless publicAccess: true is passed.",
      "credentialHandling": "the password is stored as a service secret. The agent reads generated credentials with describe-service-instance; a person who needs the value gets a short-lived download link from download-service-secret (expires after 1 hour, up to 3 downloads) instead of having it pasted into chat"
    },
    {
      "protocol": "S3 over HTTPS",
      "consumer": "the user's app, wherever it runs",
      "reachability": "HTTPS instance URL (https://{tenant}-{name}.minio-minio.auto.prod-se.osaas.io), read 2026-10-08"
    }
  ],
  "recommendedPath": {
    "chain": [
      {
        "step": 1,
        "serviceId": "birme-osc-postgresql",
        "role": "relational database",
        "requiredConfig": ["name", "PostgresPassword"],
        "requiresCredential": true,
        "note": "Create it with create-service-instance (serviceId birme-osc-postgresql). If you use the create-database tool instead (type postgres), pass opts.publicAccess: true when the app runs outside OSC: create-database defaults publicAccess to false (internal-only), read 2026-10-09. PostgresUser defaults to 'postgres'; PostgresDb defaults to the user name. If the project needs vector search, use pgvector-pgvector in this step instead (same required fields: name, PostgresPassword). Then call wait-for-service-ready before handing back the connection URL.",
        "mcpTool": "create-service-instance"
      },
      {
        "step": 2,
        "serviceId": "minio-minio",
        "role": "S3-compatible object storage for uploads and files",
        "requiredConfig": ["name"],
        "requiresCredential": false,
        "note": "RootUser and RootPassword are optional at create time; RootPassword, if set, needs 10+ characters with lower case, upper case and a digit. If left unset, read the generated credentials with describe-service-instance and store them with create-service-secret; never ask the user to paste them.",
        "mcpTool": "create-service-instance"
      },
      {
        "step": 3,
        "role": "hand back connection details",
        "mcpTools": [
          "list-service-instances",
          "describe-service-instance",
          "download-service-secret"
        ],
        "note": "Return DATABASE_URL (list-service-instances prints the public connection URL with the password redacted; describe-service-instance returns the credentials) and the S3 endpoint plus access keys. Write them into the user's own .env or secret store. This recipe deliberately has no parameter store and no create-my-app step."
      }
    ],
    "optionalTools": [
      {
        "serviceId": "valkey-io-valkey",
        "role": "cache or queue",
        "requiredConfig": ["name"],
        "boundary": "Internal-only by default: 29 of 30 valkey instances in the author's workspace report publicAccess=false (cluster DNS on port 6379), read 2026-10-08. create-database accepts publicAccess: true for valkey if an app outside OSC needs it; otherwise it suits an app running on OSC, which is the deploy-agent-written-app stack's job."
      },
      {
        "serviceId": "pgvector-pgvector",
        "role": "vector search alongside relational data",
        "requiredConfig": ["name", "PostgresPassword"],
        "boundary": "Public reachability NOT verified: list-service-instances returned 0 pgvector-pgvector instances in the author's workspace on 2026-10-08 and again on 2026-10-09. Treat it as reachable from an app running on OSC until a live instance shows publicAccess=true."
      }
    ],
    "tokensPerDay": 15,
    "tokensPerDayBasis": "estimate-service-cost ceiling: birme-osc-postgresql 5 (re-read 2026-10-09) + minio-minio 10 (2026-10-08). Optional: valkey-io-valkey 10, pgvector-pgvector 10 (2026-10-08).",
    "measuredWallClockSeconds": null,
    "wallClockMeasured": false,
    "gapNote": "No timed end-to-end run of this chain yet. Named gap, not a filled-in figure.",
    "agentFoundServiceUnaided": null
  },
  "configSurface": {
    "servicesInChain": 2,
    "totalRequiredFieldsAcrossChain": 3,
    "sensitiveFields": ["PostgresPassword", "RootPassword"],
    "note": "birme-osc-postgresql, minio-minio, valkey-io-valkey and pgvector-pgvector all return serviceAssociations [] (get-service-schema, 2026-10-08). Nothing is wired between them by the platform; the connection details go to the user's app."
  },
  "setup": {
    "codeRequired": false,
    "knownDeployGotcha": "Use the connection URL that list-service-instances prints, not the https instance URL, for database connections. Instance names are lower-case alphanumeric, at most 20 characters."
  },
  "cost": {
    "unit": "tokens/day",
    "ceiling": 15,
    "ceilingSource": "estimate-service-cost, 2026-10-08 (ceiling rates; observed burn is typically lower per the tool's own note)",
    "freePlanTokens": 100,
    "freePlanTokensAreOneTime": true,
    "daysToExhaustFreePlan": 6,
    "cheapestPlanCoveringContinuousUse": {
      "name": "Personal",
      "eurPerMonth": 15,
      "tokensPerDay": 40
    },
    "pricingSource": "https://www.osaas.io/pricing read 2026-10-09"
  },
  "servicesVerifiedLive": {
    "date": "2026-10-09",
    "method": "osc_call_tool get-service-schema on birme-osc-postgresql and minio-minio (2026-10-09) and on valkey-io-valkey and pgvector-pgvector (2026-10-08); list-service-instances on birme-osc-postgresql and pgvector-pgvector (2026-10-09) and on minio-minio and valkey-io-valkey (2026-10-08); estimate-service-cost on all four.",
    "catalogTotal": 196,
    "catalogTotalSource": "list-service-categories via osc_call_tool on 2026-10-09, per-category sum 10+27+13+31+64+25+19+7 = 196"
  },
  "gateCheck": {
    "gatedServiceId": "eyevinn-just-go-live",
    "usesGatedService": false,
    "note": "This stack does not name or link eyevinn-just-go-live; the P3 gate does not bind it."
  },
  "verifiedOn": "2026-10-09",
  "publishedAt": "https://www.osaas.io/for-ai-agents",
  "descriptorUrl": "https://www.osaas.io/stacks/provision-agent-backend.json"
}
