Everything is in the container. $this->app->make('db') for the query builder, and the same for anything a module bound in register(). Bind your own with $this->app->singleton().
$db = $this->app->make('db');

$rows = $db->table('examples')
    ->whereNull('deleted_at')
    ->where('user_id', $userId)
    ->orderByDesc('created_at')
    ->limit(20)
    ->get();

Useful bindings: db, template, cache, auth, gate, router, modules, applications, groups, content_types, widget_types, widget_areas, personal_data, discussions, searcher.

A controller also has $this->user($request), $this->render(), $this->redirect(), $this->json(), $this->session($request) and $this->seo($request).

🚨 Business rules go in a service, not a controller. Every application here puts visibility and validation in Services/ because the same rule is needed by a page, a widget, a search callback and an API endpoint — and a rule written in a controller is a rule the other three do not have.

Sign in to say whether this helped.