mirror of
https://github.com/zvx-echo6/central.git
synced 2026-08-26 17:31:39 +00:00
v0.14.5: migration 042 re-asserts central ownership of config.monitoring_areas
During the v0.14.0 prod deploy (2026-06-12) migration 042 was applied as `sudo -u postgres`, leaving config.monitoring_areas + its SERIAL sequence owned by postgres while the `central` app role expects ownership-based access. We patched prod inline at the time with ALTER ... OWNER TO central, but the migration FILE was never updated -- so a fresh install (dev clone, eventual prod rebuild) would hit the same footgun. Append two idempotent ALTERs (table + sequence OWNER TO central) so 042 is self-healing. No-op when already central-owned. No new fields/event-types/ behavior, no migration re-apply, nothing to deploy (live prod table is already central-owned via the earlier inline fix). Test: test_grants_table_and_sequence_ownership_to_central asserts both ALTERs are present (whitespace-insensitive, matching the existing static checks). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
c1c3d2576d
commit
4bbe7d61a6
2 changed files with 17 additions and 0 deletions
|
|
@ -46,3 +46,13 @@ WHERE id = true
|
||||||
AND monitor_east IS NOT NULL
|
AND monitor_east IS NOT NULL
|
||||||
AND monitor_west IS NOT NULL
|
AND monitor_west IS NOT NULL
|
||||||
ON CONFLICT (name) DO NOTHING;
|
ON CONFLICT (name) DO NOTHING;
|
||||||
|
|
||||||
|
-- Ownership fix (v0.14.5). During the v0.14.0 prod deploy (2026-06-12) this
|
||||||
|
-- migration was applied as `sudo -u postgres`, so the table + its SERIAL
|
||||||
|
-- sequence ended up owned by postgres while the `central` app role expects
|
||||||
|
-- ownership-based access (it could read but not manage the new config table).
|
||||||
|
-- We patched prod inline with these same ALTERs; making them part of the file
|
||||||
|
-- keeps fresh installs self-healing. Idempotent: a no-op when already owned by
|
||||||
|
-- central. (See central-manual-migration-owner-role.)
|
||||||
|
ALTER TABLE config.monitoring_areas OWNER TO central;
|
||||||
|
ALTER SEQUENCE config.monitoring_areas_id_seq OWNER TO central;
|
||||||
|
|
|
||||||
|
|
@ -38,3 +38,10 @@ def test_does_not_drop_old_columns_in_v0_14_0():
|
||||||
upper = _NORM.upper()
|
upper = _NORM.upper()
|
||||||
assert "DROP COLUMN" not in upper
|
assert "DROP COLUMN" not in upper
|
||||||
assert "DROP TABLE" not in upper
|
assert "DROP TABLE" not in upper
|
||||||
|
|
||||||
|
|
||||||
|
def test_grants_table_and_sequence_ownership_to_central():
|
||||||
|
# v0.14.5: applied-as-postgres left the table/sequence postgres-owned; the
|
||||||
|
# file now re-asserts central ownership so fresh installs are self-healing.
|
||||||
|
assert "ALTER TABLE config.monitoring_areas OWNER TO central" in _NORM
|
||||||
|
assert "ALTER SEQUENCE config.monitoring_areas_id_seq OWNER TO central" in _NORM
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue