basecut.yml file defines what Basecut extracts, how traversal is bounded, how PII is anonymized, and where output is written.
Complete Example
Top-Level Fields
from
from defines the starting rows.
- Use
table: usersforpublic.users. - Use
table: schema.tablefor non-public schemas. wheresupports named params (:id), values go inparams.
traverse
virtual_foreign_keys
Use virtual_foreign_keys when related tables are enforced in application code
but not declared as database FK constraints.
Single-column (compact) form:
- Virtual FK edges are traversed the same way as real FKs during extraction.
- Bare table names are normalized to
public.<table>. - Compact endpoints must be
table.columnorschema.table.column. from.columnsandto.columnsmust have the same number of columns.- Duplicate virtual FK definitions are rejected.
limits.rows
Cycle handling: When tables form circular foreign key relationships (cycles), Basecut automatically caps the combined row count for the cycle group based on the sum of effective table limits. For example, if three tables in a cycle each have
per_table: 1000, the cycle budget is 3000 total rows. Adjust per_table or add individual tables entries to control cycle sizes.
anonymize
Shorthand:
mode: autoenables built-in PII auto-detection plus explicitrules.mode: manualapplies only explicitrules.mode: offdisables anonymization.- Table-grouped rule keys can be unqualified (
users) forpublic.users. excluded_domains(top-level) is an optional list of email domains that bypass anonymization. Emails matching these domains (case-insensitive, exact match) are left unchanged, whether the email strategy was set via explicit rules or auto-detection. Useful for preserving internal/test emails like@yourcompany.com.- Per-rule
params.excluded_domainsoverrides the global list for that specific rule. If present (even as an empty list), the globalexcluded_domainsare ignored for that rule. A rule withoutparams.excluded_domainsinherits the global list.
output
String shorthand:
- For
provider: s3,bucketis required. - For Cloudflare R2, use
provider: s3+endpointand setregion: auto.