Skip to main content
Glama

Manage Lakebase branches

manage_lakebase_branch
Destructive

Manage Lakebase autoscaling branches and compute endpoints: create, update, delete, undelete, and list copy-on-write Postgres branches with point-in-time branching.

Instructions

Manage Lakebase autoscaling branches (copy-on-write Postgres branches) and their compute endpoints.

Branch actions: list (project), get, create (project, branch id, optional source_branch, source_branch_time for point-in-time, source_branch_lsn, spec), update (spec, e.g. {"is_protected": true}), delete (soft unless purge=true; the default branch is refused unless allow_default_branch=true), undelete. Endpoint actions: list_endpoints, get_endpoint, create_endpoint (endpoint id + spec with endpoint_type), update_endpoint (e.g. CU limits, {"disabled": true}), delete_endpoint. get_operation polls a long-running operation. Writes return status 'pending' unless wait_seconds.

Safety classification: list, get, list_endpoints, get_endpoint, get_operation = READ_ONLY; create, update, undelete, create_endpoint, update_endpoint = WRITE; delete, delete_endpoint = DESTRUCTIVE.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
specNoBranchSpec fields (create/update, e.g. {"ttl": "86400s"}, {"no_expiry": true}, {"is_protected": true}) or EndpointSpec fields (create_endpoint/update_endpoint, e.g. {"endpoint_type": "ENDPOINT_TYPE_READ_WRITE", "autoscaling_limit_min_cu": 0.5, "autoscaling_limit_max_cu": 2}). Unknown fields are rejected.
purgeNodelete: hard delete (irreversible). Default is a soft delete restorable with action='undelete'.
actionYesBranch lifecycle, plus compute endpoints (*_endpoint) of a branch.
branchNoBranch id or full name 'projects/<p>/branches/<b>'.
confirmNoSet to true ONLY after the user has reviewed the plan returned by a previous call with status 'confirmation_required'. Required for destructive/security-sensitive actions.
dry_runNoIf true, validate and return the planned change without executing it.
projectNoProject id or 'projects/<id>'.
endpointNoEndpoint id or full endpoint name.
page_sizeNoMax items to return (server caps this).
page_tokenNonext_page_token from a previous response.
update_maskNoComma-separated field paths to update. Default: derived from the keys of `spec` (autoscaling resources use 'spec.<field>' paths).
show_deletedNolist: include soft-deleted branches.
wait_secondsNoSeconds to wait for a long-running create/update/delete to finish. 0 (default) returns immediately with status 'pending'. Capped by DBX_MCP_MAX_WAIT_SECONDS and the tool timeout.
source_branchNocreate: parent branch id/name to branch from (default: the project's default branch).
operation_nameNoAutoscaling operation name returned by a previous call (for action='get_operation').
source_branch_lsnNocreate: Postgres LSN of the parent branch to branch from.
source_branch_timeNocreate: point in time of the parent branch (RFC3339, e.g. 2025-01-31T12:00:00Z).
allow_default_branchNodelete: permit deleting the project's default branch (refused otherwise).

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
dataNo
pageNo
planNo
toolYes
actionNo
safetyNo
statusNosuccess
summaryYes
warningsNo
next_stepsNoSuggested follow-up calls.
request_idNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations it discloses a full safety taxonomy (READ_ONLY/WRITE/DESTRUCTIVE per action), reversibility of soft delete via undelete, the default-branch refusal, the 'pending' async status and wait_seconds semantics, and the confirm/dry_run flow. This is far richer than what readOnlyHint/destructiveHint already convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Dense but tightly organized into branch actions, endpoint actions, and a safety classification line, with the goal statement front-loaded. Every clause carries information an agent needs; there is no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For an 18-parameter multi-action tool with an output schema present, the description covers action scoping, async semantics, confirmation, and destructive guards. Nothing an agent needs to invoke it correctly is missing, and return values need not be explained given the output schema.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds value by grouping which parameters belong to which action alongside the per-action behaviors they trigger. It does not restate the spec field formats those parameters already document, so it stops at 4 rather than 5.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The first sentence names the specific resource ('Lakebase autoscaling branches (copy-on-write Postgres branches) and their compute endpoints') and the description then enumerates every action, so an agent knows exactly what the tool covers. It clearly separates itself from siblings like manage_lakebase_database and generate_lakebase_credential by scoping to branch/endpoint lifecycle.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It maps every action to the parameters it consumes and states the conditions that gate risky actions ('soft unless purge=true; the default branch is refused unless allow_default_branch=true'). What is missing is explicit routing against sibling tools (e.g. when to prefer manage_lakebase_database), so it stops short of the top score.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.