Files
tenant-registry/migrations/0001_init.down.sql
T
sharang 80181855bc feat(schema): M4.1 — full tenant_registry schema + migrate binary
PLATFORM_ARCHITECTURE.md §5c schema, end-to-end:

  enums:    tenant_status (demo/trial/active/frozen/archived),
            tenant_kind (customer/demo), idp_kind (oidc/saml),
            tenant_project_status (active/archived)

  tables:   tenants            id/slug/name/status/kind/plan/erp_id/
                               stripe_id/trial_ends_at/contract_dates/
                               sales_owner
            tenant_projects    sub-tenancy (GCP-Project style); opt-in via
                               product manifest.supports_projects=true
            tenant_products    tenant ↔ product matrix + JSONB config
            tenant_idp_config  enterprise SSO (OIDC/SAML metadata + verified)
            api_keys           argon2 hash + prefix + scopes + revoked_at;
                               single source of truth across all products
            audit_log          Retraced-compatible: actor/action/target/
                               product/metadata; indexed for cross-product
                               filtering (PRODUCT_INTEGRATION_SPEC.md §8.4)

  triggers: updated_at auto-bump on every mutable table.
  fks:      ON DELETE CASCADE for owned rows; SET NULL for audit_log so
            forensic history outlives the tenant delete.

cmd/migrate (new binary):
  golang-migrate as a library with the migrations embedded via
  migrations/embed.go → embed.FS. Sub-commands: up / down / version /
  force. Ships as a self-contained binary; in prod it's the Orca init
  container per IMPLEMENTATION_PLAN.md §1.7.

Dockerfile builds both binaries; the migrate one is invoked separately
as the init step.

Tests (require Docker; gated by -short):
  TestMigrate_upDownRoundTrip   schema → 6 tables + 4 enums; down→empty;
                                up-after-down succeeds (round-trip clean)
  TestSeed_canInsertAndQuery    insert across every table; FK cascade
                                works; audit_log SET-NULL keeps the row
  TestSlugConstraint            tenant.slug regex rejects too-short /
                                leading dash / trailing dash / uppercase /
                                underscore

Makefile:
  make migrate-up / down / down-all / version / create NAME=...
  make test-short  → skip integration when Docker isn't around
  make build-migrate  → just the migrator binary

The handler-layer in-memory store is unchanged; M4.2 swaps it for the
pgx-backed implementation against this schema.

Refs: M4.1
2026-05-19 12:01:16 +02:00

22 lines
888 B
SQL

-- M4.1 down — reverse of 0001_init.up.sql.
-- Forward-only in prod (column drops require two releases); the down
-- migration exists for testcontainers round-trips + dev tear-downs.
DROP TRIGGER IF EXISTS tenant_idp_config_touch_updated_at ON tenant_idp_config;
DROP TRIGGER IF EXISTS tenant_products_touch_updated_at ON tenant_products;
DROP TRIGGER IF EXISTS tenant_projects_touch_updated_at ON tenant_projects;
DROP TRIGGER IF EXISTS tenants_touch_updated_at ON tenants;
DROP FUNCTION IF EXISTS touch_updated_at();
DROP TABLE IF EXISTS audit_log;
DROP TABLE IF EXISTS api_keys;
DROP TABLE IF EXISTS tenant_idp_config;
DROP TABLE IF EXISTS tenant_products;
DROP TABLE IF EXISTS tenant_projects;
DROP TABLE IF EXISTS tenants;
DROP TYPE IF EXISTS tenant_project_status;
DROP TYPE IF EXISTS idp_kind;
DROP TYPE IF EXISTS tenant_kind;
DROP TYPE IF EXISTS tenant_status;