Files
Mangalord/vision-manager/readonly-role.sql
fabi 27f215066d
Some checks failed
deploy / test-frontend (pull_request) Waiting to run
deploy / build-and-push (pull_request) Blocked by required conditions
deploy / deploy (pull_request) Blocked by required conditions
deploy / test-backend (pull_request) Has been cancelled
fix(vision-manager): retain analysis-enabled gate alongside memory-yield
The analysis-disabled gate (stop/inhibit vision when Admin→Settings analysis
is OFF, so stale queued jobs don't pin ~4.4GiB) was applied directly on the
host and never committed, so it was absent from main and from this branch —
merging as-is would have regressed it. Re-introduce it here so the merged
manager has BOTH gates: vision is held down if analysis is disabled OR host
memory is tight. Also grant the read-only role SELECT on app_settings.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-16 14:42:36 +02:00

37 lines
1.7 KiB
SQL

-- Read-only DB role for vision-manager.
--
-- The sidecar only needs to count pending analysis work; give it SELECT on
-- crawler_jobs and nothing else. It must NOT reuse the backend's credentials.
--
-- The Postgres service mounts no init dir and the data volume already exists,
-- so this is applied ONCE by an operator (it is idempotent):
--
-- docker compose exec -T postgres \
-- psql -U "$POSTGRES_USER" -d "$POSTGRES_DB" -v pw="<a-strong-password>" \
-- -f - < vision-manager/readonly-role.sql
--
-- Then point the manager at it (VISION_MANAGER_DATABASE_URL in .env):
-- postgres://vision_manager:<a-strong-password>@postgres:5432/<POSTGRES_DB>
--
-- The password is passed via psql's -v pw=... ; psql substitutes :'pw' as a
-- quoted literal and :"DBNAME" (psql's built-in) as the current db identifier.
-- These substitutions only happen in plain statements, NOT inside a
-- dollar-quoted DO block — hence the \gexec form below.
-- Create the LOGIN role only if it is absent (idempotent).
SELECT 'CREATE ROLE vision_manager LOGIN'
WHERE NOT EXISTS (SELECT FROM pg_roles WHERE rolname = 'vision_manager')
\gexec
-- (Re)set the password every run so rotating it is just a re-apply.
ALTER ROLE vision_manager LOGIN PASSWORD :'pw';
-- CONNECT to the current database, and read-only on the two tables we poll:
-- crawler_jobs (backlog depth + crawl-in-flight) and app_settings (the runtime
-- analysis-enabled flag — without this the manager can't tell that analysis was
-- turned off and would keep vision pinned on stale queued jobs).
GRANT CONNECT ON DATABASE :"DBNAME" TO vision_manager;
GRANT USAGE ON SCHEMA public TO vision_manager;
GRANT SELECT ON crawler_jobs TO vision_manager;
GRANT SELECT ON app_settings TO vision_manager;