feat: implement metadata catalog database management

This commit is contained in:
Codex
2026-08-27 22:43:54 +02:00
parent 705af3aeb2
commit 79c4c925b5
86 changed files with 12566 additions and 135 deletions
+25
View File
@@ -0,0 +1,25 @@
DO $bootstrap$
DECLARE
runtime_password text := trim(both E'\r\n' from pg_read_file('/run/secrets/catalog_runtime_password'));
BEGIN
IF runtime_password = '' THEN
RAISE EXCEPTION 'catalog runtime password is empty';
END IF;
IF NOT EXISTS (
SELECT 1 FROM pg_catalog.pg_roles WHERE rolname = 'thothii_catalog_runtime'
) THEN
EXECUTE format(
'CREATE ROLE thothii_catalog_runtime LOGIN PASSWORD %L',
runtime_password
);
END IF;
END
$bootstrap$;
GRANT CONNECT ON DATABASE thothii_catalog TO thothii_catalog_runtime;
GRANT USAGE ON SCHEMA public TO thothii_catalog_runtime;
ALTER DEFAULT PRIVILEGES IN SCHEMA public
GRANT SELECT, INSERT, UPDATE, DELETE ON TABLES TO thothii_catalog_runtime;
ALTER DEFAULT PRIVILEGES IN SCHEMA public
GRANT USAGE, SELECT ON SEQUENCES TO thothii_catalog_runtime;
+2
View File
@@ -96,7 +96,9 @@ RUN ln -s /opt/venv /app/harness/.venv
# Backend: dist + node_modules (stesso Node major 24 + glibc bookworm → compatibili)
COPY --from=backend-build /src/backend/dist /app/backend/dist
COPY --from=backend-build /src/backend/node_modules /app/backend/node_modules
COPY backend/scripts/ssh-askpass.mjs /app/backend/scripts/ssh-askpass.mjs
COPY backend/package*.json /app/backend/
RUN chmod 0755 /app/backend/scripts/ssh-askpass.mjs
# Runtime Pi is installed only from the committed lockfile. The image exposes its immutable
# executable directly, so no host Pi installation or writable global npm directory is needed.