feat: harden community production foundation through story 1.5
This commit is contained in:
@@ -27,6 +27,19 @@ This repository contains the Community version:
|
||||
- PostgreSQL database;
|
||||
- optional Valkey or Redis for temporary coordination state.
|
||||
|
||||
The executable Community boundary is recorded in
|
||||
[`docs/capability-inventory.json`](../capability-inventory.json). Only
|
||||
`implemented` denotes a delivered flow; `planned`, `gap`, and `blocked` do not
|
||||
count as ready. Resources, Prompts, background Tasks, and Load Runs are planned
|
||||
targets and are not advertised as implemented in the current version.
|
||||
|
||||
The verified brownfield snapshot is recorded in
|
||||
[`docs/capability-baseline/manifest.json`](../capability-baseline/manifest.json).
|
||||
It binds the inventory, required surfaces, taxonomy, bounded manual checklist,
|
||||
and sanitized results by exact SHA-256. A full pass requires
|
||||
`implemented + automated + pass`; flaky, skipped, not-run, and manual-only
|
||||
evidence remain non-pass.
|
||||
|
||||
## Documentation
|
||||
|
||||
The main documentation is currently maintained in Russian:
|
||||
@@ -38,6 +51,9 @@ The main documentation is currently maintained in Russian:
|
||||
- [MCP interface](../mcp-interface.md)
|
||||
- [Admin API](../admin-api.md)
|
||||
- [Runtime configuration](../runtime-config.md)
|
||||
- [Runtime configuration machine schema](../schemas/runtime-config.schema.json)
|
||||
- [PostgreSQL migration contract](migrations.md) ([full operator contract in Russian](../migrations.md))
|
||||
- [Migration machine sequence](../schemas/migration-sequence.json)
|
||||
- [Troubleshooting](../troubleshooting.md)
|
||||
|
||||
## License
|
||||
|
||||
@@ -0,0 +1,22 @@
|
||||
# PostgreSQL migrations
|
||||
|
||||
Crank has one append-only migration authority in `crank-registry`. The Admin and MCP services run a read-only compatibility preflight; only the one-shot `crank-migrate` process may execute DDL.
|
||||
|
||||
For an existing installation, always run: read-only `preflight`, verified PostgreSQL and artifact-storage backup, `plan --check`, controlled `apply`, then a final `preflight`. Exit code `2` from CLI preflight means migration is required; exit code `1` blocks mutation until the reported condition is resolved.
|
||||
|
||||
Source command:
|
||||
|
||||
```bash
|
||||
cargo run -p admin-api --bin crank-migrate -- plan --check
|
||||
docker compose -f deploy/community/docker-compose.yml \
|
||||
--env-file deploy/community/.env.example \
|
||||
run --rm migrate crank-migrate preflight
|
||||
```
|
||||
|
||||
The migrator reads only database configuration and retries connection for a bounded startup window. Diagnostics contain stable `code`, `stage`, nullable `version`, and `recovery`, never raw SQL, driver output, database URLs, credentials, or row data.
|
||||
|
||||
Published migrations are immutable and checksummed. Partial schema, unknown extension provenance, checksum drift, and future versions fail closed. Automatic down migrations, `--force`, destructive rollback, and arbitrary SQL input are not supported. Full N/N-1 upgrade and rollback qualification belongs to Story 7.2.
|
||||
|
||||
Version 3 adds nullable canonical Trace ID storage and partial Request/Trace indexes. New application writes provide both identities; historical rows remain honestly nullable and are never assigned fabricated traces.
|
||||
|
||||
For the complete ledger inventory, recovery table, and authoring rules, see the canonical [Russian operator contract](../migrations.md).
|
||||
Reference in New Issue
Block a user