Skip to content

feat: manage global roles and ownership - #637

Open
Goldziher wants to merge 14 commits into
pgplex:mainfrom
Goldziher:codex/global-state-authority
Open

Goldziher wants to merge 14 commits into
pgplex:mainfrom
Goldziher:codex/global-state-authority

Conversation

@Goldziher

@Goldziher Goldziher commented Oct 9, 2026 •

Copy link
Copy Markdown

Hi there. This is a codex driven PR. I hope this is acceptable - its very large, but tested locally on my end to ensure its working and does what it needs. Up to this point the human written component. AI text below:


Adds an opt-in global TOML manifest for roles, memberships, explicit ownership, and database-wide default privileges while keeping schema SQL as the ordinary object source. Planning is read-only, fingerprints the selected catalog and authority state, validates the complete transition before mutation, and applies deterministic PostgreSQL 15–18 semantics including SET-only membership, current-owner execution, schema-specific CREATE authority, multi-grantor refusal, and zero-drift replanning.

Validation: go test -count=1 ./internal/globalstate; go test -count=1 -timeout=10m ./cmd/apply -run '^TestReview'; PostgreSQL 15/16/17/18 authority matrix; go test -count=1 -timeout=20m ./...; go vet ./....


Closes #627
Closes #628
Closes #629
Closes #630
Closes #631
Closes #632
Closes #633
Closes #634
Closes #635
Closes #636

Copilot AI balanced review requested due to automatic review settings October 9, 2026 11:19

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@greptile-apps

greptile-apps Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 0/5

[Critical impact] Adds declarative management of PostgreSQL roles, memberships, and ownership.

Fix execution roles, ownership lookup, and transition checks before merging.

Findings

  1. P1 Concurrent index creation fails ▶
  2. P1 Transfers lose needed permissions ▶
  3. P1 Routine ownership never settles ▶
  4. P1 Valid membership plans are refused ▶
  5. P1 Schema owner cannot alter tables ▶
  6. P1 Exported SQL loses role changes ▶
  7. P1 Retired roles fail after changes ▶

Summary

Adds an opt-in TOML manifest for roles, memberships, ownership, and database-wide default privileges.

  • Saved plans include a selected global-state fingerprint and authority checks.
  • Schema inspection reads more catalogs directly.
  • Ownership lookup, execution roles, SQL exports, and transition checks need fixes before merging.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart TD
  A[Schema SQL and global TOML] --> B[Read target catalogs]
  B --> C[Build schema and global changes]
  C --> D[Check authority and save fingerprints]
  D --> E[Validate saved fingerprints]
  E --> F[Apply role and membership changes]
  F --> G[Apply schema groups with execution role]
  G --> H[Apply ownership and default privileges]
  H --> I[Apply final permission reductions]
Loading

Reviews (1) · Last reviewed commit: "fix: validate schema owner executor auth..." · Reviewed by Greptile

Comment thread cmd/apply/apply.go
Comment thread internal/globalstate/diff.go Outdated
Comment thread internal/globalstate/state.go Outdated
Comment thread internal/globalstate/diff.go Outdated
Comment thread cmd/plan/plan.go Outdated
Comment thread internal/plan/plan.go
Comment thread internal/globalstate/diff.go Outdated
@tianzhou

tianzhou commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Thanks for taking the initiative. For feature like this, I will take the stab myself and use your context as reference.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment