Skip to content

test(apa-53): ephemeral PostgreSQL qualification environment - #120

Merged
Aparnap2 merged 2 commits into
mainfrom
apa53-pr
Oct 6, 2026
Merged

Aparnap2 merged 2 commits into
mainfrom
apa53-pr

Conversation

@Aparnap2

@Aparnap2 Aparnap2 commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Dedicated ephemeral PG qualification environment for the entire PG-gated suite.

What it does:

  • fresh postgres:16-alpine on a loopback-only throwaway container (:55432), no volume
  • migrations via the repo's own mechanism
  • role bootstrap mirrors CI: claimops_app/claimops_worker NOSUPERUSER
  • NEW: fail-closed invariant — qualify.sh asserts claimops_app is NOSUPERUSER and NOBYPASSRLS before migrations; a superuser app role silently inverts every cross-tenant assertion (empirically measured), so it dies before spending a second
  • pre-suite row count must be 0 (proves 'fresh'), PG-backed pass count must be >=1 (fails on green-by-skipping)
  • SELECT 1 readiness, not pg_isready
  • deterministic teardown; verified on forced failure

Evidence: 41/41 with PG genuinely enabled, pre-suite rows 0, 20 PG-backed passes, 0 stray containers — repeatable.

Depends on #119 (merged). Shared claimops-postgres volume untouched; role-bypass guard verified against a negative (superuser) case.

opencode and others added 2 commits October 6, 2026 08:50
The PG-gated suite is normally gated on TEST_POSTGRES_DSN pointing at the
long-lived claimops-postgres container. That volume accumulates rows across
runs, and several PG-gated tests assert over whatever a tenant-scoped query
returns rather than over the rows they seeded, so their verdicts depend on
how much history the volume already holds.

infra/postgres/qualify.sh adds a self-contained alternative: its own Postgres
container on its own loopback port with no volume, so the database is
genuinely empty every run; migrations applied through the repo's own
mechanism (infra/postgres/migrations/*.sql, lexicographic, ON_ERROR_STOP=1);
the full suite run against it; deterministic teardown via an EXIT/INT/TERM
trap. Role topology mirrors .github/workflows/integration.yml (NOSUPERUSER
app/worker roles, owner runs migrations) because a superuser app role
bypasses RLS and silently inverts every cross-tenant test.

It never contacts, restarts or writes to claimops-postgres; the shared port
and container name are hard-guarded, not assumed. A run where every
PG-backed test self-skipped is reported as a failure, not a pass, and the
pre-suite row count is measured so "fresh database" is a fact rather than a
claim. `make qualify` is the entrypoint.

No test logic, no production code, and no migration is modified.
Add assert_app_role_is_rls_respecting to the qualification harness: it
verifies claimops_app is NOSUPERUSER and NOBYPASSRLS after role bootstrap
and before migrations, and dies otherwise. Empirically justified — a
superuser app role silently inverts every cross-tenant assertion.
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 253e1a51-53b5-4e93-8b1c-94567616c11c
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Aparnap2
Aparnap2 merged commit aaeeb4a into main Oct 6, 2026
5 checks passed
@Aparnap2
Aparnap2 deleted the apa53-pr branch October 6, 2026 03:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant