Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a05e2e-805b-7042-a750-71f473bceea2
1.3 KiB
1.3 KiB
Storage operations
Production uses one SQLite writer on persistent ReadWriteOnce storage.
Production serve disables automatic migration and refuses schema drift or an
in-memory database.
approval-engine migrate --db /data/approvals.sqlite
approval-engine verify --db /data/approvals.sqlite
approval-engine backup --db /data/approvals.sqlite --output /backup/approval.sqlite
Migration is repeatable and sets an explicit PRAGMA user_version. Backup uses
SQLite's online backup API, verifies PRAGMA integrity_check, writes mode 0600,
and refuses to overwrite a target.
Restore is a stopped-single-writer operation:
- Stop the StatefulSet and confirm no approval-engine or migration process has the PVC open.
- Preserve the failed database and its
-wal/-shmcompanions for analysis. - Copy the verified backup to a new database path with owner 10001 and mode 0600. Do not merge a backup with old WAL files.
- Run
verify, thenmigrateif the release schema is newer, thenverifyagain. - Start exactly one replica and prove approval/entry/outbox counts, readiness, claim retrieval, and idempotent audit drain before reopening callers.
Approval mutation and outbox insertion share BEGIN IMMEDIATE and one commit;
a failed outbox insert rolls the mutation back. Delivery occurs afterward and
does not roll back a committed mutation.