# Microsoft SQL Server

Microsoft SQL Server target for executing queries on an MSSQL database.

## YAML Parameters

```typescript
interface YAMLParameters {
  /** The hostname or IP address of the MSSQL server */
  host: string;
  /** The human-readable ID of the target */
  target: string;
  /** The name of the target */
  name?: string;
  /** The port of the MSSQL server. Default: 1433 */
  port?: string;
  /** The default database name */
  database?: string;
  /** SSL connection mode. Default: REQUIRE, which encrypts but does NOT validate the server certificate (vulnerable to MITM); full certificate validation requires ca_certificate. */
  ssl_mode?: "DISABLE" | "REQUIRE" | "VERIFY_FULL";
  /** PEM-encoded CA certificate (required when ssl_mode is VERIFY_FULL) */
  ca_certificate?: string;
  /** MSSQL authentication credentials */
  auth?: MssqlAuthYaml;
  /** SSH proxy target for tunneling to private MSSQL servers */
  proxy?: string;
  /** Access permissions for the target */
  permissions?: PermissionsYaml;
  /** Indicates if this target is disabled (default: false) */
  disabled?: boolean;
  /** The list of tags associated with the target */
  tags?: string[];
  /** Defines how the target can be used (as deployment target, proxy, or both) */
  use_as?: UseAsYaml;
  /** Note for this resource */
  note?: string;
  /** YAML note for AI agents operating on this resource */
  agent_note?: string;
  type?: "MSSQL";
}
```

## Type Definitions

```typescript
interface MssqlAuthYaml {
  /** The MSSQL username */
  username?: string;
  /** The MSSQL password */
  password?: string;
}

interface PermissionsYaml {
  /** Access level for other workspace members */
  others?: "DENIED" | "READ_ONLY" | "USE_ONLY" | "BLIND" | "RUN_ONLY" | "READ_WRITE" | "MANAGE" | "DEFAULT" | "ALLOWED" | "STAGE" | "COMMIT";
  /** List of specific users with their access levels */
  users?: object;
  /** List of user groups with their access levels */
  groups?: object;
  /** List of pipelines allowed to access this resource */
  pipelines?: AllowedPipelineYaml[];
  /** List of sandboxes allowed to access this resource */
  sandboxes?: AllowedSandboxYaml[];
}

interface AllowedPipelineYaml {
  /** When true, allow all pipelines to access this resource */
  all?: "DENIED" | "READ_ONLY" | "USE_ONLY" | "BLIND" | "RUN_ONLY" | "READ_WRITE" | "MANAGE" | "DEFAULT" | "ALLOWED" | "STAGE" | "COMMIT";
  /** Project name containing the allowed pipeline */
  project?: string;
  /** Pipeline identifier that is allowed to access this resource */
  pipeline?: string;
  /** Access level granted to the pipeline */
  access?: "DENIED" | "READ_ONLY" | "USE_ONLY" | "BLIND" | "RUN_ONLY" | "READ_WRITE" | "MANAGE" | "DEFAULT" | "ALLOWED" | "STAGE" | "COMMIT";
}

interface AllowedSandboxYaml {
  /** When true, allow all sandboxes to access this resource */
  all?: "DENIED" | "READ_ONLY" | "USE_ONLY" | "BLIND" | "RUN_ONLY" | "READ_WRITE" | "MANAGE" | "DEFAULT" | "ALLOWED" | "STAGE" | "COMMIT";
  /** Project name containing the allowed sandbox */
  project?: string;
  /** Sandbox identifier that is allowed to access this resource */
  sandbox?: string;
  /** Access level granted to the sandbox */
  access?: "DENIED" | "READ_ONLY" | "USE_ONLY" | "BLIND" | "RUN_ONLY" | "READ_WRITE" | "MANAGE" | "DEFAULT" | "ALLOWED" | "STAGE" | "COMMIT";
}

interface UseAsYaml {
  /** Whether the target can be used as a deployment target (default: on) */
  target?: boolean | "on" | "off";
  /** Whether the target can be used as a proxy (default: on) */
  proxy?: boolean | "on" | "off";
}

```

## YAML Examples

### Microsoft SQL Server target with full certificate validation

```yaml
- target: production_mssql
  type: MSSQL
  name: Production MSSQL
  host: mssql.example.com
  port: "1433"
  database: app
  ssl_mode: VERIFY_FULL
  ca_certificate: |-
    -----BEGIN CERTIFICATE-----
    MIIDdzCCAl+gAwIBAgIEexampleCAcertificateENCODEDinPEMformat
    -----END CERTIFICATE-----
  auth:
    username: app_user
    password: $password
  proxy: my_ssh_bastion
  tags:
    - mssql
    - production

```

### Minimal

```yaml
- target: production_mssql
  type: MSSQL
  host: mssql.example.com
  auth:
    username: app_user
    password: $password

```


---
Original source: https://buddy.works/docs/yaml/yaml-targets/mssql