fix: migrate as durable database owner
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 37s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 37s
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a028f0-a42f-7582-89a8-ebaad7343834
This commit is contained in:
parent
7a57d9a30f
commit
4143f7c004
5 changed files with 52 additions and 6 deletions
|
|
@ -3,8 +3,11 @@
|
|||
from __future__ import annotations
|
||||
|
||||
import os
|
||||
import re
|
||||
from pathlib import Path
|
||||
|
||||
POSTGRES_IDENTIFIER = re.compile(r"^[a-z_][a-z0-9_]*$")
|
||||
|
||||
|
||||
def database_target(default: str | Path | None = None) -> str | Path:
|
||||
"""Return the configured database target, preferring a mounted secret file."""
|
||||
|
|
@ -33,3 +36,13 @@ def database_target(default: str | Path | None = None) -> str | Path:
|
|||
"or SBOM_NEXUS_DATABASE_PATH"
|
||||
)
|
||||
return default
|
||||
|
||||
|
||||
def migration_role() -> str | None:
|
||||
"""Return the durable PostgreSQL role that must own migrated objects."""
|
||||
role = os.getenv("SBOM_NEXUS_MIGRATION_ROLE")
|
||||
if not role:
|
||||
return None
|
||||
if not POSTGRES_IDENTIFIER.fullmatch(role):
|
||||
raise RuntimeError("SBOM_NEXUS_MIGRATION_ROLE must be a PostgreSQL identifier")
|
||||
return role
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue