Skip to content

Document the missing-GRANT gap in production apply paths - #40

Open
aersam wants to merge 1 commit into
mainfrom
grant-guard-docs
Open

aersam wants to merge 1 commit into
mainfrom
grant-guard-docs

Conversation

@aersam

@aersam aersam commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Docs-only follow-up to #39. Adds guidance to docs/database-layout.md and README.md explaining that pgdb testdb's "permissions files apply last, genuinely" guarantee is specific to how ensure_testdb() re-derives the whole schema every run -- a production apply path built on pgdevkit.migrate (forward-only, each file runs exactly once, as whatever shared role connects) doesn't get that guarantee for free. Points at execute_sql_script/created_table_names/missing_privileges (added in #39) as the primitives for building a guard against it, referencing the real incident this generalizes from (bmsuisse/PgMigrator#31307, ADO work item #30294).

No code changes -- CI won't run (README.md/docs are in paths-ignore), and there's no version bump since nothing published changes.

Test plan

  • N/A (prose only)

🤖 Generated with Claude Code

Claude Session: eb39e5a4-58aa-5f93-8d7b-8c71961197aa

pgdb testdb's "permissions files apply last" guarantee doesn't
transfer to a forward-only production migration runner, which applies
each file exactly once, ever, as whatever role it connects as -- a
recurring real-world bug class (see bmsuisse/PgMigrator#31307).
Points at execute_sql_script/created_table_names/missing_privileges
(added in #39) as the primitives for building a guard against it.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@aersam
aersam marked this pull request as ready for review September 28, 2026 20:57

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant