feat: complete catalog sensitivity enhancements

This commit is contained in:
Codex
2026-09-04 15:11:18 +02:00
parent b891246664
commit 7b1d69a65b
72 changed files with 33866 additions and 358 deletions
+15 -6
View File
@@ -60,7 +60,8 @@ remains available only until the integrated Fleet Ledger surface passes owner ac
complete the binding fields that the chosen transport requires.
3. Enter secrets only when replacing them. They remain write-only and are never returned by the
application.
4. Run **Test connection** before any synchronization.
4. Use **Test connection** whenever you want an informational connectivity check. Its result does
not enable or disable catalog operations.
SSH uses a private key, optional key passphrase, mandatory `known_hosts`, and optional PostgreSQL
TLS CA/server name. REST prefers `POST /rpc/schema_snapshot`; when it is absent, the catalog may
@@ -71,7 +72,9 @@ capability, malformed snapshot, or connector error applies no catalog changes. S
## Synchronize authoritative schema metadata
Schema synchronization reads the external database and reconciles the installation-local catalog.
It never changes the source database. The available synchronization scopes are **tables**,
It never changes the source database. Every synchronization attempts a fresh connection when it
runs; an unreachable server or rejected credential fails that run without changing catalog data.
The available synchronization scopes are **tables**,
**columns**, **relationships**, and **all**, but the UI exposes them at different levels:
| Location | Action | Effective scope |
@@ -88,10 +91,10 @@ The selection requirement in the tables and columns views controls whether the a
be used; it is not always the same as the synchronization target. The **Sync all** button in the
tables view is the direct shortcut for the full-database scope.
Before starting any synchronization, run **Test connection**. Synchronization is rejected when
the binding is unreachable or its tested version is older than the current binding configuration.
Only one catalog operation can be active for a database at a time; explicit cleanup shares this
exclusion.
Connection tests are informational and are never a synchronization prerequisite. Each
synchronization tests its own access while reading the schema; an unavailable connection fails
that operation with a connector error. Only one catalog operation can be active for a database at
a time; explicit cleanup shares this exclusion.
### What a synchronization does
@@ -167,6 +170,12 @@ starting generation. Changing a flag affects future generations only; existing g
descriptions are not regenerated. Real and substituted samples remain transient and are not persisted
or returned to the browser.
The database-level **Copy generated descriptions to all columns** action applies every non-empty
AI-generated column description to the corresponding curated **Description** field in one atomic
operation. It skips empty generated descriptions, reports copied and skipped counts, and retains the
generated text. Because this can replace reviewed descriptions, the interface requires explicit
confirmation before applying it.
The decisions behind this surface are [ADRs 0001–0011](../adr/0001-postgres-metadata-catalog.md)
and the detailed acceptance record is
[AI catalog description generation acceptance](../testing/2026-08-29-ai-catalog-description-generation-acceptance.md).