Replace Postgres DB_* env vars with a single DATABASE_URL on pgx - #14
Merged
Merged
Conversation
The challenge store's connection was spread across DB_HOST/PORT/USER/ PASSWORD/NAME/SSL_MODE/MAX_*_CONNECTIONS and assembled by shared/pkg/db, whose Settings/BuildConnectionString carry baggage dauth never used: a global sync.Once singleton, an unused reader/writer split, a search_path == dbname assumption, and a lib/pq keyword DSN with no password escaping. Collapse all of it into one DATABASE_URL (postgres://user:pass@host:5432/dauth?sslmode=require), stored wholly in the secret, and connect with native jackc/pgx/v5 pgxpool instead of lib/pq + database/sql. Pool sizing tunes inline via URL query params (e.g. ?pool_max_conns=10). UsePostgres() is now "DATABASE_URL is set". - config: Settings.DatabaseURL with a fail-fast scheme check; drop the shared/pkg/db import and the DB_* reads. - main: newStore opens a pgxpool.Pool (New/Ping); drop database/sql and lib/pq; log host/db from pool.Config().ConnConfig. - nonce: Postgres store holds a *pgxpool.Pool (Exec/QueryRow, pgx.ErrNoRows); test uses pgxpool against TEST_DATABASE_URL. - chart: one DATABASE_URL ExternalSecret ref at <ns>/dauth/database_url (replacing db_user/db_password); the connection leaves the ConfigMap; values' postgres block collapses to just `enabled`. - run-local.sh + README updated to DATABASE_URL. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The challenge store's Postgres connection was spread across
DB_HOST/DB_PORT/DB_USER/DB_PASSWORD/DB_NAME/DB_SSL_MODE/DB_MAX_*_CONNECTIONSand assembled byshared/pkg/db. That package carries baggage dauth never used: a globalsync.Oncesingleton, an unused reader/writer split, asearch_path == dbnameassumption, and a lib/pq keyword DSN with no password escaping.This collapses all of it into one
DATABASE_URL(postgres://user:pass@host:5432/dauth?sslmode=require), stored wholly in the secret, and connects with nativejackc/pgx/v5pgxpool instead of lib/pq +database/sql. Pool sizing tunes inline via URL query params (e.g.?pool_max_conns=10).UsePostgres()is now simply "DATABASE_URLis set".Changes
Settings.DatabaseURLwith a fail-fast scheme check; dropped theshared/pkg/dbimport and theDB_*reads.newStoreopens apgxpool.Pool(New/Ping); droppeddatabase/sqland lib/pq; logs host/db frompool.Config().ConnConfig.*pgxpool.Pool(Exec/QueryRow,pgx.ErrNoRows); test uses pgxpool againstTEST_DATABASE_URL.DATABASE_URLExternalSecret ref at<ns>/dauth/database_url(replacingdb_user/db_password); the connection leaves the ConfigMap; thepostgresvalues block collapses to justenabled.DATABASE_URL.Deploy note (flag-day)
Provision the new
<ns>/dauth/database_urlAWS secret as a full connection URL and retire the olddb_user/db_passwordkeys. Thepostgres.enabledgate is unchanged, so disabled deploys stay inert.Verification
go build/go vet/ full unit suite green;helm lint+helm templaterenderDATABASE_URLfrom…/dauth/database_url. The live Postgres test (gated onTEST_DATABASE_URL) now exercises the pgxpool path.🤖 Generated with Claude Code