Skip to content

Replace Postgres DB_* env vars with a single DATABASE_URL on pgx - #14

Merged
elffjs merged 1 commit into
mainfrom
postgres-database-url
Jun 25, 2026
Merged

elffjs merged 1 commit into
mainfrom
postgres-database-url

Conversation

@elffjs

@elffjs elffjs commented Jun 25, 2026

Copy link
Copy Markdown
Member

What

The challenge store's Postgres connection was spread across DB_HOST / DB_PORT / DB_USER / DB_PASSWORD / DB_NAME / DB_SSL_MODE / DB_MAX_*_CONNECTIONS and assembled by shared/pkg/db. That package carries baggage dauth never used: a global sync.Once singleton, an unused reader/writer split, a search_path == dbname assumption, and a lib/pq keyword DSN with no password escaping.

This collapses all of it into one DATABASE_URL (postgres://user:pass@host:5432/dauth?sslmode=require), stored wholly in the secret, and connects with native jackc/pgx/v5 pgxpool instead of lib/pq + database/sql. Pool sizing tunes inline via URL query params (e.g. ?pool_max_conns=10). UsePostgres() is now simply "DATABASE_URL is set".

Changes

  • config: Settings.DatabaseURL with a fail-fast scheme check; dropped the shared/pkg/db import and the DB_* reads.
  • main: newStore opens a pgxpool.Pool (New/Ping); dropped database/sql and lib/pq; logs host/db from pool.Config().ConnConfig.
  • nonce: the Postgres store holds a *pgxpool.Pool (Exec/QueryRow, pgx.ErrNoRows); test uses pgxpool against TEST_DATABASE_URL.
  • chart: one DATABASE_URL ExternalSecret ref at <ns>/dauth/database_url (replacing db_user/db_password); the connection leaves the ConfigMap; the postgres values block collapses to just enabled.
  • run-local.sh + README updated to DATABASE_URL.

Deploy note (flag-day)

Provision the new <ns>/dauth/database_url AWS secret as a full connection URL and retire the old db_user / db_password keys. The postgres.enabled gate is unchanged, so disabled deploys stay inert.

Verification

go build / go vet / full unit suite green; helm lint + helm template render DATABASE_URL from …/dauth/database_url. The live Postgres test (gated on TEST_DATABASE_URL) now exercises the pgxpool path.

🤖 Generated with Claude Code

The challenge store's connection was spread across DB_HOST/PORT/USER/
PASSWORD/NAME/SSL_MODE/MAX_*_CONNECTIONS and assembled by shared/pkg/db,
whose Settings/BuildConnectionString carry baggage dauth never used: a
global sync.Once singleton, an unused reader/writer split, a
search_path == dbname assumption, and a lib/pq keyword DSN with no
password escaping.

Collapse all of it into one DATABASE_URL
(postgres://user:pass@host:5432/dauth?sslmode=require), stored wholly in
the secret, and connect with native jackc/pgx/v5 pgxpool instead of
lib/pq + database/sql. Pool sizing tunes inline via URL query params
(e.g. ?pool_max_conns=10). UsePostgres() is now "DATABASE_URL is set".

- config: Settings.DatabaseURL with a fail-fast scheme check; drop the
  shared/pkg/db import and the DB_* reads.
- main: newStore opens a pgxpool.Pool (New/Ping); drop database/sql and
  lib/pq; log host/db from pool.Config().ConnConfig.
- nonce: Postgres store holds a *pgxpool.Pool (Exec/QueryRow,
  pgx.ErrNoRows); test uses pgxpool against TEST_DATABASE_URL.
- chart: one DATABASE_URL ExternalSecret ref at <ns>/dauth/database_url
  (replacing db_user/db_password); the connection leaves the ConfigMap;
  values' postgres block collapses to just `enabled`.
- run-local.sh + README updated to DATABASE_URL.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@elffjs
elffjs merged commit 3a070ae into main Jun 25, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant