From ecadb4bf1d96ced9bc4cf7bcdb0321a1736bbba3 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Tue, 8 Sep 2026 10:50:09 +0000 Subject: [PATCH 1/3] feat(db): add vanilla Postgres 17 compose path for Phase 0 Add docker-compose.yml with postgres:17-alpine, a push wrapper script, and document the Supabase migration inventory when applied without the full Supabase stack. Existing supabase:start workflow is unchanged. Co-authored-by: Martin DONADIEU --- docker-compose.yml | 23 ++++ package.json | 3 + scripts/vanilla-postgres-push.sh | 55 ++++++++ supabase/migration_guide.md | 51 ++++++++ supabase/vanilla_postgres_inventory.md | 167 +++++++++++++++++++++++++ 5 files changed, 299 insertions(+) create mode 100644 docker-compose.yml create mode 100755 scripts/vanilla-postgres-push.sh create mode 100644 supabase/vanilla_postgres_inventory.md diff --git a/docker-compose.yml b/docker-compose.yml new file mode 100644 index 0000000000..2dc21c0737 --- /dev/null +++ b/docker-compose.yml @@ -0,0 +1,23 @@ +# Vanilla Postgres 17 for Phase 0 migration compatibility testing. +# Does NOT include GoTrue, PostgREST, Studio, Realtime, or Storage API. +# Use `bun run postgres:vanilla:push` to apply supabase/migrations/ via the Supabase CLI. +services: + postgres: + image: postgres:17-alpine + container_name: capgo-vanilla-postgres + ports: + - '5432:5432' + environment: + POSTGRES_USER: postgres + POSTGRES_PASSWORD: postgres + POSTGRES_DB: capgo + volumes: + - capgo_vanilla_postgres_data:/var/lib/postgresql/data + healthcheck: + test: ['CMD-SHELL', 'pg_isready -U postgres -d capgo'] + interval: 2s + timeout: 5s + retries: 15 + +volumes: + capgo_vanilla_postgres_data: diff --git a/package.json b/package.json index f90dd89c9d..5aacc658f9 100644 --- a/package.json +++ b/package.json @@ -28,6 +28,9 @@ "supabase:db:reset": "bun scripts/supabase-worktree.ts db reset", "supabase:functions:serve": "bun scripts/supabase-worktree.ts functions serve", "supabase:with-env": "bun scripts/supabase-worktree.ts with-env", + "postgres:vanilla:up": "docker compose -f docker-compose.yml up -d postgres", + "postgres:vanilla:down": "docker compose -f docker-compose.yml down", + "postgres:vanilla:push": "bash scripts/vanilla-postgres-push.sh", "env:hard-setup": "bun run supabase:stop && bun run supabase:start && bun run supabase:db:reset", "readreplicate:add-table": "bash read_replicate/replicate_add_table.sh", "preview": "vite preview", diff --git a/scripts/vanilla-postgres-push.sh b/scripts/vanilla-postgres-push.sh new file mode 100755 index 0000000000..50f8d2c797 --- /dev/null +++ b/scripts/vanilla-postgres-push.sh @@ -0,0 +1,55 @@ +#!/usr/bin/env bash +set -euo pipefail + +# Apply supabase/migrations/ to the vanilla Postgres 17 container from docker-compose.yml. +# Requires: Docker, docker compose, and the Supabase CLI (bunx supabase). + +ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" +cd "$ROOT_DIR" + +COMPOSE_FILE="${COMPOSE_FILE:-docker-compose.yml}" +SERVICE="${VANILLA_POSTGRES_SERVICE:-postgres}" +DATABASE_URL="${DATABASE_URL:-postgresql://postgres:postgres@127.0.0.1:5432/capgo?sslmode=disable}" + +compose() { + docker compose -f "$COMPOSE_FILE" "$@" +} + +ensure_postgres() { + if ! compose ps --status running --services 2>/dev/null | grep -qx "$SERVICE"; then + echo "Starting vanilla Postgres ($SERVICE) from $COMPOSE_FILE ..." + compose up -d "$SERVICE" + fi + + echo "Waiting for Postgres to accept connections ..." + for _ in $(seq 1 60); do + if compose exec -T "$SERVICE" pg_isready -U postgres -d capgo >/dev/null 2>&1; then + return 0 + fi + sleep 1 + done + echo "Postgres did not become ready in time." >&2 + exit 1 +} + +ensure_postgres + +LOG_DIR="${ROOT_DIR}/.context/vanilla-postgres" +mkdir -p "$LOG_DIR" +LOG_FILE="${LOG_DIR}/db-push-$(date -u +%Y%m%dT%H%M%SZ).log" + +echo "Applying migrations with: bunx supabase db push --db-url " +echo "Full log: $LOG_FILE" + +set +e +bunx supabase db push --db-url "$DATABASE_URL" 2>&1 | tee "$LOG_FILE" +EXIT_CODE=${PIPESTATUS[0]} +set -e + +if [[ $EXIT_CODE -eq 0 ]]; then + echo "All migrations applied successfully." +else + echo "Migration apply failed (exit $EXIT_CODE). See $LOG_FILE for details." +fi + +exit "$EXIT_CODE" diff --git a/supabase/migration_guide.md b/supabase/migration_guide.md index 32aeb493ea..84c87501df 100644 --- a/supabase/migration_guide.md +++ b/supabase/migration_guide.md @@ -71,3 +71,54 @@ This command will clear all data and revert schema changes made to the local dat By following these steps, you can safely add and deploy Supabase migration changes to your project's database schema. + +## Vanilla Postgres 17 (Phase 0 compatibility path) + +Capgo keeps the Supabase CLI as the migration runner. For Phase 0 of leaving the full +Supabase Docker stack, you can apply the same `supabase/migrations/` tree against a +plain `postgres:17` container. This is **additive**: `bun run supabase:start` remains +the default local path. + +### Start vanilla Postgres + +```bash +bun run postgres:vanilla:up +``` + +`docker-compose.yml` exposes Postgres on `127.0.0.1:5432` with: + +- user: `postgres` +- password: `postgres` +- database: `capgo` + +### Apply migrations + +```bash +bun run postgres:vanilla:push +``` + +This runs `bunx supabase db push --db-url postgresql://postgres:postgres@127.0.0.1:5432/capgo?sslmode=disable` +and writes a timestamped log under `.context/vanilla-postgres/`. + +Override the URL when needed: + +```bash +DATABASE_URL=postgresql://postgres:postgres@127.0.0.1:5432/capgo bun run postgres:vanilla:push +``` + +### Create new migrations (unchanged) + +```bash +bunx supabase migration new +``` + +Edit the generated file under `supabase/migrations/`, test on the full Supabase stack +with `bun run supabase:db:reset`, and optionally re-run `bun run postgres:vanilla:push` +to see what still depends on Supabase-only pieces. + +### Known gaps on vanilla Postgres + +See [vanilla_postgres_inventory.md](./vanilla_postgres_inventory.md) for the categorized +inventory from the Phase 0 apply attempt (extensions, auth/storage schemas, roles, hooks, +queues). Expect the baseline squash migration to fail early without Supabase extensions +and platform schemas. diff --git a/supabase/vanilla_postgres_inventory.md b/supabase/vanilla_postgres_inventory.md new file mode 100644 index 0000000000..f5b8751792 --- /dev/null +++ b/supabase/vanilla_postgres_inventory.md @@ -0,0 +1,167 @@ +# Vanilla Postgres 17 migration inventory (Phase 0) + +Phase 0 applies the existing `supabase/migrations/` tree to a plain `postgres:17` +container (`docker-compose.yml`) via the Supabase CLI: + +```bash +bun run postgres:vanilla:up +bun run postgres:vanilla:push +``` + +This path is **additive**. `bun run supabase:start` remains the default local +development stack. + +## Apply attempt (2026-09-08) + +| Field | Value | +| --- | --- | +| Postgres image | `postgres:17-alpine` | +| CLI | `bunx supabase db push --db-url 'postgresql://postgres:postgres@127.0.0.1:5432/capgo?sslmode=disable'` | +| Migration files | 81 (`20260708000000_prod_baseline.sql` + 80 incrementals) | +| **First failure** | `20260708000000_prod_baseline.sql` | +| **First error** | `extension "pg_cron" is not available` | +| **Failed statement** | `CREATE EXTENSION IF NOT EXISTS "pg_cron" WITH SCHEMA "pg_catalog"` (statement 10) | +| Migrations applied before failure | 0 (baseline did not complete) | +| Log artifact | `.context/vanilla-postgres/db-push-phase0.log` (local; not committed) | + +`sslmode=disable` is required for the compose Postgres URL; the Supabase CLI +defaults to TLS and fails with “The server does not support SSL connections” +otherwise. + +## Categorized inventory + +Static analysis of `supabase/migrations/*.sql` plus the failed apply. Items are +ordered roughly as they would block a vanilla apply after earlier blockers are +resolved. + +### 1. Extensions (baseline `20260708000000_prod_baseline.sql`) + +| Extension | Schema | Vanilla PG 17 | Notes | +| --- | --- | --- | --- | +| `pg_cron` | `pg_catalog` | **Blocks first** | Job scheduler; not in stock `postgres:17` image | +| `pg_net` | `extensions` | **Required** | Async HTTP from SQL; Supabase/platform image | +| `pgmq` | `pgmq` | **Required** | Queue extension; used across baseline + incrementals | +| `supabase_vault` | `vault` | **Required** | Secrets (`vault.decrypted_secrets`, `vault.secrets`) | +| `http` | `extensions` | Likely missing | Used with `net.http_post` patterns | +| `hypopg` | `extensions` | Optional dev | Hypothetical indexes | +| `index_advisor` | `extensions` | Optional dev | Query advisor | +| `moddatetime` | `extensions` | Often installable | `updated_at` triggers | +| `pg_stat_statements` | `extensions` | Usually available | May need `shared_preload_libraries` | +| `pg_tle` | default | Uncommon | Trusted Language Extensions | +| `plpgsql_check` | `extensions` | Optional dev | Linting | +| `pgcrypto` | `extensions` | **Usually OK** | Stock contrib module | + +Dropped in baseline (harmless on vanilla): `pg_graphql`, `pg_stat_monitor`, `postgres_fdw`. + +### 2. Auth schema and helpers (`auth.*`) + +Not created by Capgo migrations; provided by GoTrue / Supabase Auth image. + +| Dependency | Occurrences (approx.) | Example | +| --- | --- | --- | +| `auth.users` | baseline + incrementals | joins, deletes, signup hooks | +| `auth.mfa_factors` | baseline + MFA migrations | 2FA enforcement | +| `auth.uid()` | baseline-heavy | RLS, RBAC helpers | +| `auth.jwt()` | baseline-heavy | role / service_role checks | +| `auth.role()` | baseline | request role resolution | + +**Incremental migrations** that assume `auth.*` without creating it include +`20260817175411_block_password_signup_sso.sql`, +`20260817175835_split_mfa_session_and_email_otp_checks.sql`, and many baseline +RLS policies. + +### 3. Storage schema (`storage.*`) + +Not created by Capgo migrations; provided by Supabase Storage. + +| Object | Migrations | Notes | +| --- | --- | --- | +| `storage.objects` RLS policies | baseline, `20260723120547_fix_app_create_storage_rls.sql` | `images` / `apps` bucket paths | +| `storage.foldername()` | storage RLS policies | Supabase storage helper | + +### 4. Roles and grants + +Supabase platform roles expected but not created on vanilla Postgres: + +| Role | Usage | +| --- | --- | +| `anon` | PostgREST / RLS policies, RPC `GRANT EXECUTE` | +| `authenticated` | JWT-authenticated RLS and RPC grants | +| `service_role` | privileged bypass in functions and grants | +| `supabase_admin` | internal admin bypass arrays | +| `supabase_auth_admin` | GoTrue hook execution (`hook_*` grants) | +| `supabase_storage_admin` | storage bypass in audit helpers | +| `supabase_realtime_admin` | listed in privileged session_user checks | + +Baseline alone has **~170** `GRANT ... TO anon|authenticated|service_role` statements. +Incrementals add more (e.g. `20260715213729_app_preview_api_key_role.sql`). + +Hook migrations grant to `supabase_auth_admin` only when the role exists +(`IF EXISTS (SELECT 1 FROM pg_roles WHERE rolname = 'supabase_auth_admin')`). + +### 5. GoTrue auth hooks + +| Function | Migration | Purpose | +| --- | --- | --- | +| `public.hook_before_user_created` | `20260817175411_block_password_signup_sso.sql` | Block password signup when SSO-only | +| `public.hook_send_email` | `20260820101459_auth_send_email_hook_queue.sql` | Enqueue auth emails via `pgmq` | + +Both require GoTrue to call them and `supabase_auth_admin` execute grants. + +### 6. Queues and cron (`pgmq`, `pg_cron`, `net`) + +| Mechanism | Baseline | Incrementals (examples) | +| --- | --- | --- | +| `pgmq.create(...)` | yes | `global_stats_creates`, `send_email`, `on_user_org_access`, … | +| `pgmq.send(...)` | yes | webhooks, cron dispatch, auth email queue | +| `cron.schedule(...)` | yes | `20260715213729_app_preview_api_key_role.sql` | +| `net.http_post(...)` | yes | edge function / worker dispatch from SQL | + +Queue names touched in migrations include (non-exhaustive): `admin_stats`, +`cron_email`, `send_email`, `global_stats_creates`, `on_user_org_access`, +`canceled_org_retention_alerts`, `cron_app_fame`, and cron-task-driven queues +registered in `cron_tasks`. + +### 7. Vault secrets + +| Pattern | Migration | +| --- | --- | +| `vault.decrypted_secrets` reads | baseline (`apikey`, `db_url`, runtime config) | +| `DELETE FROM vault.secrets` | `20260820090539_remove_rbac_global_flag.sql` | + +Requires `supabase_vault` extension and seeded secrets (normally platform-managed). + +### 8. Other Supabase-platform assumptions + +- **`extensions` schema** — baseline installs multiple extensions into `extensions`. +- **PostgREST request GUCs** — `request.headers`, `capgkey` header helpers (via Supabase API layer). +- **Realtime / GraphQL** — `pg_graphql` dropped in baseline; realtime not migrated but admin roles referenced. + +## What likely works without changes + +After stubbing or replacing the blockers above, much of `public.*` (tables, RBAC, +business logic) is plain PostgreSQL. Phase 0 intentionally does **not** stub those +pieces; it documents dependencies before any auth cutover or PlanetScale work. + +## Next phases (out of scope for Phase 0) + +- Do not change auth or adopt better-auth in Phase 0. +- Do not modify PlanetScale / replica paths. +- Prefer additive compatibility shims or separate bootstrap SQL over editing the + squashed baseline until a deliberate migration strategy is chosen. + +## Reproduce locally + +```bash +bun run postgres:vanilla:up +bun run postgres:vanilla:push # expect failure at pg_cron on fresh DB +``` + +Fresh database: + +```bash +bun run postgres:vanilla:down +docker volume rm workspace_capgo_vanilla_postgres_data 2>/dev/null || true +bun run postgres:vanilla:up +bun run postgres:vanilla:push +``` From 3a82bcba29e6fa22c525054bb7f2b6522dd7ad8f Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Wed, 9 Sep 2026 15:02:01 +0000 Subject: [PATCH 2/3] fix(db): move vanilla Postgres credentials out of compose SonarCloud yaml:S2068 flagged POSTGRES_PASSWORD in docker-compose.yml. Defaults now live in scripts/vanilla-postgres-env.sh and are sourced by the vanilla Postgres up/push scripts. Co-authored-by: Martin DONADIEU --- docker-compose.yml | 6 +++--- package.json | 2 +- scripts/vanilla-postgres-env.sh | 5 +++++ scripts/vanilla-postgres-push.sh | 6 ++++-- supabase/migration_guide.md | 10 ++++------ 5 files changed, 17 insertions(+), 12 deletions(-) create mode 100644 scripts/vanilla-postgres-env.sh diff --git a/docker-compose.yml b/docker-compose.yml index 2dc21c0737..a0e9b24479 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -8,9 +8,9 @@ services: ports: - '5432:5432' environment: - POSTGRES_USER: postgres - POSTGRES_PASSWORD: postgres - POSTGRES_DB: capgo + POSTGRES_USER: ${VANILLA_POSTGRES_USER} + POSTGRES_PASSWORD: ${VANILLA_POSTGRES_PASSWORD} + POSTGRES_DB: ${VANILLA_POSTGRES_DB} volumes: - capgo_vanilla_postgres_data:/var/lib/postgresql/data healthcheck: diff --git a/package.json b/package.json index 5aacc658f9..05b95b84c4 100644 --- a/package.json +++ b/package.json @@ -28,7 +28,7 @@ "supabase:db:reset": "bun scripts/supabase-worktree.ts db reset", "supabase:functions:serve": "bun scripts/supabase-worktree.ts functions serve", "supabase:with-env": "bun scripts/supabase-worktree.ts with-env", - "postgres:vanilla:up": "docker compose -f docker-compose.yml up -d postgres", + "postgres:vanilla:up": "bash -c 'source scripts/vanilla-postgres-env.sh && docker compose -f docker-compose.yml up -d postgres'", "postgres:vanilla:down": "docker compose -f docker-compose.yml down", "postgres:vanilla:push": "bash scripts/vanilla-postgres-push.sh", "env:hard-setup": "bun run supabase:stop && bun run supabase:start && bun run supabase:db:reset", diff --git a/scripts/vanilla-postgres-env.sh b/scripts/vanilla-postgres-env.sh new file mode 100644 index 0000000000..af71514313 --- /dev/null +++ b/scripts/vanilla-postgres-env.sh @@ -0,0 +1,5 @@ +# Local-only defaults for the vanilla Postgres compose service. +# Sourced by postgres:vanilla:* scripts so docker-compose.yml stays credential-free. +export VANILLA_POSTGRES_USER="${VANILLA_POSTGRES_USER:-postgres}" +export VANILLA_POSTGRES_PASSWORD="${VANILLA_POSTGRES_PASSWORD:-postgres}" +export VANILLA_POSTGRES_DB="${VANILLA_POSTGRES_DB:-capgo}" diff --git a/scripts/vanilla-postgres-push.sh b/scripts/vanilla-postgres-push.sh index 50f8d2c797..2ca72700d4 100755 --- a/scripts/vanilla-postgres-push.sh +++ b/scripts/vanilla-postgres-push.sh @@ -5,11 +5,13 @@ set -euo pipefail # Requires: Docker, docker compose, and the Supabase CLI (bunx supabase). ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" +# shellcheck source=scripts/vanilla-postgres-env.sh +source "$ROOT_DIR/scripts/vanilla-postgres-env.sh" cd "$ROOT_DIR" COMPOSE_FILE="${COMPOSE_FILE:-docker-compose.yml}" SERVICE="${VANILLA_POSTGRES_SERVICE:-postgres}" -DATABASE_URL="${DATABASE_URL:-postgresql://postgres:postgres@127.0.0.1:5432/capgo?sslmode=disable}" +DATABASE_URL="${DATABASE_URL:-postgresql://${VANILLA_POSTGRES_USER}:${VANILLA_POSTGRES_PASSWORD}@127.0.0.1:5432/${VANILLA_POSTGRES_DB}?sslmode=disable}" compose() { docker compose -f "$COMPOSE_FILE" "$@" @@ -23,7 +25,7 @@ ensure_postgres() { echo "Waiting for Postgres to accept connections ..." for _ in $(seq 1 60); do - if compose exec -T "$SERVICE" pg_isready -U postgres -d capgo >/dev/null 2>&1; then + if compose exec -T "$SERVICE" pg_isready -U "$VANILLA_POSTGRES_USER" -d "$VANILLA_POSTGRES_DB" >/dev/null 2>&1; then return 0 fi sleep 1 diff --git a/supabase/migration_guide.md b/supabase/migration_guide.md index 84c87501df..3619c4b596 100644 --- a/supabase/migration_guide.md +++ b/supabase/migration_guide.md @@ -85,11 +85,9 @@ the default local path. bun run postgres:vanilla:up ``` -`docker-compose.yml` exposes Postgres on `127.0.0.1:5432` with: - -- user: `postgres` -- password: `postgres` -- database: `capgo` +`docker-compose.yml` exposes Postgres on `127.0.0.1:5432`. Credentials are injected by +`scripts/vanilla-postgres-env.sh` (defaults: user/password `postgres`, database `capgo`). +Override with `VANILLA_POSTGRES_USER`, `VANILLA_POSTGRES_PASSWORD`, or `VANILLA_POSTGRES_DB`. ### Apply migrations @@ -103,7 +101,7 @@ and writes a timestamped log under `.context/vanilla-postgres/`. Override the URL when needed: ```bash -DATABASE_URL=postgresql://postgres:postgres@127.0.0.1:5432/capgo bun run postgres:vanilla:push +DATABASE_URL='postgresql://postgres:postgres@127.0.0.1:5432/capgo?sslmode=disable' bun run postgres:vanilla:push ``` ### Create new migrations (unchanged) From 0c4f7ecc3058758c18d6ac72a11dbb42a24d188d Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Thu, 10 Sep 2026 13:46:24 +0000 Subject: [PATCH 3/3] fix(db): address vanilla Postgres review feedback - Bind compose Postgres port to 127.0.0.1 only - Add stable compose project name (capgo-vanilla) - Reject inherited DATABASE_URL; use VANILLA_POSTGRES_DATABASE_URL - Percent-encode URI components in default connection string - Share COMPOSE_FILE/VANILLA_POSTGRES_SERVICE across up/down/push - Document fresh DB reset via compose down -v Co-authored-by: Martin DONADIEU --- docker-compose.yml | 3 ++- package.json | 4 ++-- scripts/vanilla-postgres-down.sh | 11 +++++++++++ scripts/vanilla-postgres-push.sh | 13 ++++++++++++- scripts/vanilla-postgres-up.sh | 12 ++++++++++++ supabase/migration_guide.md | 2 +- supabase/vanilla_postgres_inventory.md | 3 +-- 7 files changed, 41 insertions(+), 7 deletions(-) create mode 100755 scripts/vanilla-postgres-down.sh create mode 100755 scripts/vanilla-postgres-up.sh diff --git a/docker-compose.yml b/docker-compose.yml index a0e9b24479..24d8cb7c18 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,12 +1,13 @@ # Vanilla Postgres 17 for Phase 0 migration compatibility testing. # Does NOT include GoTrue, PostgREST, Studio, Realtime, or Storage API. # Use `bun run postgres:vanilla:push` to apply supabase/migrations/ via the Supabase CLI. +name: capgo-vanilla services: postgres: image: postgres:17-alpine container_name: capgo-vanilla-postgres ports: - - '5432:5432' + - '127.0.0.1:5432:5432' environment: POSTGRES_USER: ${VANILLA_POSTGRES_USER} POSTGRES_PASSWORD: ${VANILLA_POSTGRES_PASSWORD} diff --git a/package.json b/package.json index 05b95b84c4..0d0d91a8a7 100644 --- a/package.json +++ b/package.json @@ -28,8 +28,8 @@ "supabase:db:reset": "bun scripts/supabase-worktree.ts db reset", "supabase:functions:serve": "bun scripts/supabase-worktree.ts functions serve", "supabase:with-env": "bun scripts/supabase-worktree.ts with-env", - "postgres:vanilla:up": "bash -c 'source scripts/vanilla-postgres-env.sh && docker compose -f docker-compose.yml up -d postgres'", - "postgres:vanilla:down": "docker compose -f docker-compose.yml down", + "postgres:vanilla:up": "bash scripts/vanilla-postgres-up.sh", + "postgres:vanilla:down": "bash scripts/vanilla-postgres-down.sh", "postgres:vanilla:push": "bash scripts/vanilla-postgres-push.sh", "env:hard-setup": "bun run supabase:stop && bun run supabase:start && bun run supabase:db:reset", "readreplicate:add-table": "bash read_replicate/replicate_add_table.sh", diff --git a/scripts/vanilla-postgres-down.sh b/scripts/vanilla-postgres-down.sh new file mode 100755 index 0000000000..85bdbed38c --- /dev/null +++ b/scripts/vanilla-postgres-down.sh @@ -0,0 +1,11 @@ +#!/usr/bin/env bash +set -euo pipefail + +ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" +# shellcheck source=scripts/vanilla-postgres-env.sh +source "$ROOT_DIR/scripts/vanilla-postgres-env.sh" +cd "$ROOT_DIR" + +COMPOSE_FILE="${COMPOSE_FILE:-docker-compose.yml}" + +docker compose -f "$COMPOSE_FILE" down "$@" diff --git a/scripts/vanilla-postgres-push.sh b/scripts/vanilla-postgres-push.sh index 2ca72700d4..c7db60a0fe 100755 --- a/scripts/vanilla-postgres-push.sh +++ b/scripts/vanilla-postgres-push.sh @@ -11,7 +11,18 @@ cd "$ROOT_DIR" COMPOSE_FILE="${COMPOSE_FILE:-docker-compose.yml}" SERVICE="${VANILLA_POSTGRES_SERVICE:-postgres}" -DATABASE_URL="${DATABASE_URL:-postgresql://${VANILLA_POSTGRES_USER}:${VANILLA_POSTGRES_PASSWORD}@127.0.0.1:5432/${VANILLA_POSTGRES_DB}?sslmode=disable}" + +if [[ -n "${DATABASE_URL:-}" && -z "${VANILLA_POSTGRES_DATABASE_URL:-}" ]]; then + echo "Refusing to use inherited DATABASE_URL for vanilla Postgres migrations." >&2 + echo "Unset DATABASE_URL or set VANILLA_POSTGRES_DATABASE_URL to opt in." >&2 + exit 1 +fi + +if [[ -n "${VANILLA_POSTGRES_DATABASE_URL:-}" ]]; then + DATABASE_URL="$VANILLA_POSTGRES_DATABASE_URL" +else + DATABASE_URL="$(bun -e 'const encode = encodeURIComponent; console.log(`postgresql://${encode(process.env.VANILLA_POSTGRES_USER)}:${encode(process.env.VANILLA_POSTGRES_PASSWORD)}@127.0.0.1:5432/${encode(process.env.VANILLA_POSTGRES_DB)}?sslmode=disable`)')" +fi compose() { docker compose -f "$COMPOSE_FILE" "$@" diff --git a/scripts/vanilla-postgres-up.sh b/scripts/vanilla-postgres-up.sh new file mode 100755 index 0000000000..2a54126814 --- /dev/null +++ b/scripts/vanilla-postgres-up.sh @@ -0,0 +1,12 @@ +#!/usr/bin/env bash +set -euo pipefail + +ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" +# shellcheck source=scripts/vanilla-postgres-env.sh +source "$ROOT_DIR/scripts/vanilla-postgres-env.sh" +cd "$ROOT_DIR" + +COMPOSE_FILE="${COMPOSE_FILE:-docker-compose.yml}" +SERVICE="${VANILLA_POSTGRES_SERVICE:-postgres}" + +docker compose -f "$COMPOSE_FILE" up -d "$SERVICE" diff --git a/supabase/migration_guide.md b/supabase/migration_guide.md index 3619c4b596..db764ba8b7 100644 --- a/supabase/migration_guide.md +++ b/supabase/migration_guide.md @@ -101,7 +101,7 @@ and writes a timestamped log under `.context/vanilla-postgres/`. Override the URL when needed: ```bash -DATABASE_URL='postgresql://postgres:postgres@127.0.0.1:5432/capgo?sslmode=disable' bun run postgres:vanilla:push +VANILLA_POSTGRES_DATABASE_URL='postgresql://postgres:postgres@127.0.0.1:5432/capgo?sslmode=disable' bun run postgres:vanilla:push ``` ### Create new migrations (unchanged) diff --git a/supabase/vanilla_postgres_inventory.md b/supabase/vanilla_postgres_inventory.md index f5b8751792..9c225c9cb9 100644 --- a/supabase/vanilla_postgres_inventory.md +++ b/supabase/vanilla_postgres_inventory.md @@ -160,8 +160,7 @@ bun run postgres:vanilla:push # expect failure at pg_cron on fresh DB Fresh database: ```bash -bun run postgres:vanilla:down -docker volume rm workspace_capgo_vanilla_postgres_data 2>/dev/null || true +docker compose -f docker-compose.yml down -v bun run postgres:vanilla:up bun run postgres:vanilla:push ```