go.mod's 'go 1.25.0' directive (auto-set by go mod tidy because
testcontainers-go v0.42.0 requires it) made the runner's bundled
golangci-lint (built on Go 1.24) refuse to load the config.
Pin to v2.12.2, the latest at time of writing, which is built on
Go 1.25.
Also: previous gofmt commit had subject 'style: gofmt -w' which our
custom commitlint regex rejects (style isn't in the type allowlist).
Squashed into this commit so the PR's commits all pass commitlint.
Refs: M4.1
PLATFORM_ARCHITECTURE.md §5c schema, end-to-end:
enums: tenant_status (demo/trial/active/frozen/archived),
tenant_kind (customer/demo), idp_kind (oidc/saml),
tenant_project_status (active/archived)
tables: tenants id/slug/name/status/kind/plan/erp_id/
stripe_id/trial_ends_at/contract_dates/
sales_owner
tenant_projects sub-tenancy (GCP-Project style); opt-in via
product manifest.supports_projects=true
tenant_products tenant ↔ product matrix + JSONB config
tenant_idp_config enterprise SSO (OIDC/SAML metadata + verified)
api_keys argon2 hash + prefix + scopes + revoked_at;
single source of truth across all products
audit_log Retraced-compatible: actor/action/target/
product/metadata; indexed for cross-product
filtering (PRODUCT_INTEGRATION_SPEC.md §8.4)
triggers: updated_at auto-bump on every mutable table.
fks: ON DELETE CASCADE for owned rows; SET NULL for audit_log so
forensic history outlives the tenant delete.
cmd/migrate (new binary):
golang-migrate as a library with the migrations embedded via
migrations/embed.go → embed.FS. Sub-commands: up / down / version /
force. Ships as a self-contained binary; in prod it's the Orca init
container per IMPLEMENTATION_PLAN.md §1.7.
Dockerfile builds both binaries; the migrate one runs as the init step.
Tests (require Docker; gated by -short):
TestMigrate_upDownRoundTrip schema → 6 tables + 4 enums; down→empty;
up-after-down succeeds (round-trip clean)
TestSeed_canInsertAndQuery insert across every table; FK cascade
works; audit_log SET-NULL keeps the row
TestSlugConstraint tenant.slug regex rejects too-short /
leading dash / trailing dash / uppercase /
underscore
Makefile:
make migrate-up / down / down-all / version / create NAME=...
make test-short → skip integration when Docker isn't around
make build-migrate → just the migrator binary
The handler-layer in-memory store is unchanged; M4.2 swaps it for the
pgx-backed implementation against this schema.
Refs: M4.1
PLATFORM_ARCHITECTURE.md §5c schema, end-to-end:
enums: tenant_status (demo/trial/active/frozen/archived),
tenant_kind (customer/demo), idp_kind (oidc/saml),
tenant_project_status (active/archived)
tables: tenants id/slug/name/status/kind/plan/erp_id/
stripe_id/trial_ends_at/contract_dates/
sales_owner
tenant_projects sub-tenancy (GCP-Project style); opt-in via
product manifest.supports_projects=true
tenant_products tenant ↔ product matrix + JSONB config
tenant_idp_config enterprise SSO (OIDC/SAML metadata + verified)
api_keys argon2 hash + prefix + scopes + revoked_at;
single source of truth across all products
audit_log Retraced-compatible: actor/action/target/
product/metadata; indexed for cross-product
filtering (PRODUCT_INTEGRATION_SPEC.md §8.4)
triggers: updated_at auto-bump on every mutable table.
fks: ON DELETE CASCADE for owned rows; SET NULL for audit_log so
forensic history outlives the tenant delete.
cmd/migrate (new binary):
golang-migrate as a library with the migrations embedded via
migrations/embed.go → embed.FS. Sub-commands: up / down / version /
force. Ships as a self-contained binary; in prod it's the Orca init
container per IMPLEMENTATION_PLAN.md §1.7.
Dockerfile builds both binaries; the migrate one is invoked separately
as the init step.
Tests (require Docker; gated by -short):
TestMigrate_upDownRoundTrip schema → 6 tables + 4 enums; down→empty;
up-after-down succeeds (round-trip clean)
TestSeed_canInsertAndQuery insert across every table; FK cascade
works; audit_log SET-NULL keeps the row
TestSlugConstraint tenant.slug regex rejects too-short /
leading dash / trailing dash / uppercase /
underscore
Makefile:
make migrate-up / down / down-all / version / create NAME=...
make test-short → skip integration when Docker isn't around
make build-migrate → just the migrator binary
The handler-layer in-memory store is unchanged; M4.2 swaps it for the
pgx-backed implementation against this schema.
Refs: M4.1
Minimal Go service: /healthz + /v1/tenants/by-slug/:slug + /v1/tenants/:id with an in-memory store seeded with the acme tenant. Stdlib-only; pgx + JWT validation land in M4.1 follow-up.