fix(vector): harden backup restore parity gates

This commit is contained in:
2026-07-12 02:29:53 +02:00
parent e4db2ea5e1
commit 015c496bda
9 changed files with 300 additions and 36 deletions
+4 -3
View File
@@ -67,9 +67,10 @@ The dump contains the three allowlisted `vectors` tables, their data and ACLs, p
provision/reconcile the approved role names on the target first, and install the `vector`
extension in its `vectors` schema. The target must otherwise contain no vector tables or ledger.
Restore always names both the currently active source and a distinct target. The script compares
PostgreSQL cluster identity plus database OID, so host aliases cannot bypass the active-database
guard. It refuses a non-empty target unless `--force-nonempty` is explicit:
Restore always names both the currently active source and a target on a physically distinct
PostgreSQL cluster. The script compares PostgreSQL system identity, so host aliases or a different
database in the active cluster cannot bypass the guard. It refuses a non-empty target unless
`--force-nonempty` is explicit, and the clean restore is one transaction:
```sh
./scripts/vector-restore.sh \