fix(hosting): bundled PostgreSQL for one-click installs (#3159); version 1.0.0-aws.1 - #3147
Merged
Merged
Conversation
Throwaway pre-release so the AWS Marketplace AMI (#3004) can be built from published images. A later 1.0.0 candidate supersedes it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
SQLite reached end-of-support on 2026-09-01. Every one-click channel runs
docker-compose.hosted.yml through start.sh --hosted (or the compose file
alone), so the default changes there.
- docker-compose.hosted.yml: `postgres` service (postgres:16-alpine,
postgres-data volume, pg_isready healthcheck, *default-logging,
no-new-privileges, platform network only). Backend and scheduler wait
for it healthy. POSTGRES_PASSWORD is required to render.
DATABASE_URL=${DATABASE_URL-<bundled url>}: unset uses the bundled
server, set-but-empty keeps SQLite.
- start.sh ensure_hosted_database: generates POSTGRES_PASSWORD (refuses if
the postgres-data volume exists without one); with no DATABASE_URL in
the shell or .env, writes the bundled URL on a fresh install and
`DATABASE_URL=` when trinity.db exists, then prints the
SQLITE_TO_POSTGRES.md pointer while the install stays on SQLite. Runs
after the data-switch guard and before compose pull.
- Packer provision pre-pulls postgres:16-alpine (DO and AWS).
- Parity test allowlists the hosted-only service, volume, depends_on and
DATABASE_URL lines; CI compose render exports POSTGRES_PASSWORD.
- Docs: HOST-022, SQLITE_TO_POSTGRES.md hosted section, DEPLOYMENT.md,
.env.example, DO and AWS listings, DO deploy guide, topology table.
Live ACs (droplet boot, 4 GB RSS, nightly .dump on a droplet, mp-submit)
remain on the issue.
Refs #3159
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
obasilakis
force-pushed
the
chore/release-1.0.0-aws.1
branch
from
October 1, 2026 14:29
c20e88c to
3d79e01
Compare
Contributor
|
merge-train: on this train. I made two mechanical changes:
Recorded, not blocking:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two changes, one review, before the
v1.0.0-aws.1RC tag:docker-compose.hosted.yml. SQLite reached end-of-support on 2026-09-01 (Define SQLite end-of-support date + Postgres migration release notes #1278).VERSIONand the DigitalOcean installer's default tag (pinned bytest_2380_installer_release_pin.py) set to1.0.0-aws.1. After merge,v1.0.0-aws.1is tagged ondevsopublish-images.ymlpublishes the images the AWS AMI (feat: AWS one-click — Marketplace free AMI (Launch from Website) + CloudFormation Launch Stack link #3004) is built from. The hyphen makes it a pre-release:latestdoes not move, nothing merges tomain.Changes (#3159)
docker-compose.hosted.yml:postgresservice (postgres:16-alpine, volumepostgres-data,*default-logging,no-new-privileges, TCPpg_isreadyhealthcheck, no published port), ontrinity-platform-networkonly. Backend and schedulerdepends_on: postgres: service_healthy.POSTGRES_PASSWORDis required (:?).DATABASE_URL=${DATABASE_URL-postgresql://trinity:${POSTGRES_PASSWORD}@postgres:5432/trinity}.start.shensure_hosted_database(hosted only; after the HOST-015 data-switch guard, beforecompose pull).packer/digitalocean/scripts/01-provision.shpre-pullspostgres:16-alpine(the AWS AMI reuses the script).test_2280_hosted_compose_parity.pyallowlists the hosted-only service, volume,depends_onedges andDATABASE_URLlines by name. CI compose render (container-security.yml) and the local render tests (test_2528,test_ent580) supplyPOSTGRES_PASSWORD.requirements/infrastructure.md),SQLITE_TO_POSTGRES.mdhosted section,DEPLOYMENT.md,.env.example, DO + AWS listings, DO deploy guide, network topology table inarchitecture.md.Decisions
DATABASE_URLin the shell or.env(any line, even empty, counts as decided) AND no<TRINITY_DATA_PATH or ./trinity-data>/trinity.db. Thenstart.shwrites the bundled URL.start.shwritesDATABASE_URL=(empty), which keeps SQLite, and prints theSQLITE_TO_POSTGRES.mdpointer on every run.POSTGRES_PASSWORDis still generated so the file renders; the postgres container runs idle (~45 MiB measured on an empty init). An existingDATABASE_URLis never rewritten.-with no colon. Unset → bundled PostgreSQL (compose-only consumers get Postgres); set-but-empty → SQLite. A manual update that skipsstart.shhas noPOSTGRES_PASSWORDand fails to render before it can switch the database. feat: community one-click paths — "Deploy on Hostinger" button + Dokploy template (Coolify queued at 1,000 stars) #2283 (compose-only channels) is still open, so no compose-only SQLite installs exist yet.postgres-datavolume exists and.envhas noPOSTGRES_PASSWORD,start.shrefuses (the image applies the password only at init).postgresql-client-17; pg_dump 17 dumps a 16 server. A test pins client major ≥ hosted server major.Test plan
pytest tests/unit/test_3159_hosted_postgres.py tests/unit/test_2280_hosted_compose_parity.py tests/unit/test_2528_compose_file_sets.py tests/unit/test_ent580_marketplace_admin_claim.py:91 passedgrep -rlE "start\.sh|docker-compose.hosted|01-provision|firstboot" tests/unit) + new file: all pass excepttest_2582_portal_uploads.py::test_read_inbox_populates_mime_from_the_extension, which fails identically onorigin/dev(local mimetypes).tests/unit:20159 passed; the remaining failures (IPv6/SSRF suites, route census, error-code header, 2582 mime: 24 failed, 2 errors) reproduce identically on a cleanorigin/devcheckout with local Python 3.11.bash -nonstart.shand01-provision.sh.docker compose --env-file /dev/null -f docker-compose.hosted.yml config(Compose v2.39.4): withoutPOSTGRES_PASSWORD→required variable POSTGRES_PASSWORD is missing a value; with it andDATABASE_URLunset →DATABASE_URL: postgresql://trinity:…@postgres:5432/trinityon backend + scheduler; with.envDATABASE_URL=→DATABASE_URL: ""; postgres networks['trinity-platform']; hosted + override renders.postgres:16-alpinestarts underno-new-privileges:trueand answers over TCP.Unverified here (live ACs, stay on #3159)
/health200, Alembic upgrade in the backend log, no/data/trinity.db. A full hosted-stack boot was not run locally: the hosted file's fixed container names collide with the running local stack..dumpproduced on a booted droplet.mp-submit.sh.Fixes #3159
Refs #3004
🤖 Generated with Claude Code