fix: keep migration objects on stable role
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 38s
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 38s
This commit is contained in:
parent
749461b97b
commit
d2a7fe3151
3 changed files with 17 additions and 3 deletions
|
|
@ -57,7 +57,9 @@ This is an operator cutover, not an application startup step:
|
||||||
1. Scale the live SQLite Deployment to zero and verify no pod holds the PVC.
|
1. Scale the live SQLite Deployment to zero and verify no pod holds the PVC.
|
||||||
2. Snapshot or copy the SQLite file without modifying it.
|
2. Snapshot or copy the SQLite file without modifying it.
|
||||||
3. Apply `deploy/tenant-engine-migration.yaml` with the new immutable image and
|
3. Apply `deploy/tenant-engine-migration.yaml` with the new immutable image and
|
||||||
wait for success.
|
wait for success. The Job sets role to the stable
|
||||||
|
`tenant_engine_migrate` group before DDL; short-lived OpenBao login roles
|
||||||
|
must never own schema objects that outlive their lease.
|
||||||
4. Run the transfer under the migration-role URL:
|
4. Run the transfer under the migration-role URL:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
|
|
|
||||||
|
|
@ -28,6 +28,8 @@ spec:
|
||||||
- tenant-engine-migrate
|
- tenant-engine-migrate
|
||||||
- --url-file
|
- --url-file
|
||||||
- /var/run/secrets/postgres-migration/url
|
- /var/run/secrets/postgres-migration/url
|
||||||
|
- --role
|
||||||
|
- tenant_engine_migrate
|
||||||
env:
|
env:
|
||||||
- name: TENANT_ENGINE_MIGRATION_DATABASE_URL_FILE
|
- name: TENANT_ENGINE_MIGRATION_DATABASE_URL_FILE
|
||||||
value: /var/run/secrets/postgres-migration/url
|
value: /var/run/secrets/postgres-migration/url
|
||||||
|
|
|
||||||
|
|
@ -17,21 +17,31 @@ def main() -> None:
|
||||||
default="/app/migrations/postgres/0001_tenant_store.sql",
|
default="/app/migrations/postgres/0001_tenant_store.sql",
|
||||||
help="SQL migration file",
|
help="SQL migration file",
|
||||||
)
|
)
|
||||||
|
parser.add_argument(
|
||||||
|
"--role",
|
||||||
|
default=os.getenv("TENANT_ENGINE_MIGRATION_ROLE", ""),
|
||||||
|
help="stable group role that must own objects created by a leased login",
|
||||||
|
)
|
||||||
args = parser.parse_args()
|
args = parser.parse_args()
|
||||||
if not args.url_file:
|
if not args.url_file:
|
||||||
parser.error("--url-file or TENANT_ENGINE_MIGRATION_DATABASE_URL_FILE is required")
|
parser.error("--url-file or TENANT_ENGINE_MIGRATION_DATABASE_URL_FILE is required")
|
||||||
|
|
||||||
try:
|
try:
|
||||||
import psycopg
|
import psycopg
|
||||||
|
from psycopg import sql as psycopg_sql
|
||||||
except ImportError as exc: # pragma: no cover - deployment guard
|
except ImportError as exc: # pragma: no cover - deployment guard
|
||||||
raise RuntimeError("install tenant-engine[postgres] to run migrations") from exc
|
raise RuntimeError("install tenant-engine[postgres] to run migrations") from exc
|
||||||
|
|
||||||
dsn = Path(args.url_file).read_text(encoding="utf-8").strip()
|
dsn = Path(args.url_file).read_text(encoding="utf-8").strip()
|
||||||
if not dsn:
|
if not dsn:
|
||||||
raise RuntimeError("migration database URL file is empty")
|
raise RuntimeError("migration database URL file is empty")
|
||||||
sql = Path(args.migration).read_text(encoding="utf-8")
|
migration_sql = Path(args.migration).read_text(encoding="utf-8")
|
||||||
with psycopg.connect(dsn, autocommit=True) as connection:
|
with psycopg.connect(dsn, autocommit=True) as connection:
|
||||||
connection.execute(sql)
|
if args.role:
|
||||||
|
connection.execute(
|
||||||
|
psycopg_sql.SQL("SET ROLE {}").format(psycopg_sql.Identifier(args.role))
|
||||||
|
)
|
||||||
|
connection.execute(migration_sql)
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
if __name__ == "__main__":
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue