Skip to content

Releases: capydatabase/pgsquash-engine

Release list

v0.11.0

Choose a tag to compare

@idominikosgr idominikosgr released this 09 Sep 18:06
v0.11.0
04f58bc

Fixed

  • The development stack could not start PostgreSQL at all. postgres:18
    images place the cluster in a major-version subdirectory below a single mount
    at /var/lib/postgresql; the compose files still mounted the data volume at
    /var/lib/postgresql/data (the pre-18 convention), so the entrypoint aborted
    and the container restart-looped. The primary database and the dev-environment
    stack now mount at /var/lib/postgresql. The 15/16/17 services in
    compose.testing.yaml correctly keep the old path.
  • The pgsquash service is a one-shot CLI - it runs a command and exits - but
    carried restart: unless-stopped and a healthcheck, which crash-looped it
    under docker compose up. It is now restart: "no" with no healthcheck, and
    the files document docker compose run --rm pgsquash <command> as the way to
    drive it.
  • Build arguments defaulted to ${BUILD_DATE:-$(date -u ...)} and
    ${GIT_COMMIT:-$(git rev-parse ...)}. Compose does not run subshells, so
    those command substitutions were baked into the image as literal strings.
    They are static defaults (unknown) now; CI passes real values.
  • docker/postgres/Dockerfile referenced ${PG_VERSION} in its LABEL
    without re-declaring the argument inside the stage, so
    org.pgsquash.postgres.version was always empty.
  • pgAdmin could never start. PGADMIN_EMAIL defaulted to
    admin@pgsquash.localhost (and admin@pgsquash.local in the dev-environment
    stack); pgAdmin rejects reserved domains outright - "the part after the
    @-sign is a special-use or reserved name" - and exits, so the container
    restart-looped forever. The default is now admin@pgsquash.dev, in the
    compose files and in .env.example.
  • pgAdmin also published the wrong port: it cannot bind the privileged port 80
    under no-new-privileges and silently falls back to 8080, so the published
    mapping pointed at a port nothing was listening on. PGADMIN_LISTEN_PORT is
    now pinned to 8080 and the mapping matches.
  • Removed the ./docker/pgadmin/servers.json bind mount. That file has never
    existed in the repository, so Docker created an empty directory at the
    source path and mounted it over pgAdmin's config file.
  • Docker-based validation could never reach the Docker daemon. The socket is
    root:root mode 0660 and the image runs as uid 10001, so
    docker/validation/with-validation.yml - whose entire purpose is
    Docker-driven validation - got "permission denied". That service now runs as
    user: "0:0". Mounting the socket already confers host-root, so this gives
    away nothing the mount had not; no-new-privileges and cap_drop: [ALL]
    stay on. The core and dev-environment stacks keep their non-root uid (they
    mount ~/.ssh into /home/pgsquash) and now say so where the socket is
    mounted.

Changed

  • Every Dockerfile and Compose file was rebuilt on current Docker conventions
    (Engine 29 / Compose 5 / BuildKit 0.33).
    The main Dockerfile is now a
    proper multi-stage build (basedepsbuildruntime) behind a
    # syntax=docker/dockerfile:1 frontend, which the file previously lacked
    entirely. It uses a read-only bind mount of the source
    instead of COPY . . and BuildKit cache mounts for the module and build
    caches, and it takes its Go toolchain from golang:1.27.1-trixie rather than
    installing an out-of-date Go tarball into Ubuntu with wget. Everything that
    ships is staged into /out by the build stage. CGO stays enabled and the
    image is deliberately not cross-compiled, because pg_query_go links
    libpg_query. The runtime user is now a numeric uid/gid (10001).
  • docker-compose.yml, docker-compose.testing.yml and
    docker-compose.tools.yml are now compose.yaml, compose.testing.yaml and
    compose.tools.yaml - the canonical filenames, so the core stack needs no
    -f flag. Obsolete version: keys, hard-coded container_names and the
    fixed 172.20.0.0/16 subnet are gone; services gained no-new-privileges,
    cap_drop: [ALL] where the workload allows it, rotating local log drivers,
    memory limits, init: true, and healthchecks with start_interval so a
    database is marked healthy as soon as it is ready. Published ports are bound
    to 127.0.0.1 instead of every interface, and pgAdmin and Filebrowser now sit
    behind a tools profile so they do not start by default.
  • The overlays under docker/ (dev-environment/full-stack.yml,
    engine/quick-start.yml, validation/with-validation.yml) got the same
    treatment. Their filenames are unchanged, since they are always invoked with
    -f and are referenced by name from the READMEs.

Known issues

  • docker/api-server/ (its Dockerfile and docker-compose.yml) builds
    ./cmd/api-server, which no longer exists in this repository. It has been
    left untouched rather than modernized or deleted - it is dead as it stands.

v0.10.0

Choose a tag to compare

@idominikosgr idominikosgr released this 02 Sep 09:17

Added

  • pgsquash validate-external for applying a migration path to a caller-owned
    empty PostgreSQL database, capturing a portable catalog snapshot, and
    comparing a second build against it. The command refuses non-empty databases,
    supports DSNs through an environment variable, and emits the stable
    pgsquash.external-validation.v1 JSON contract.
  • Public catalog snapshot types and comparison helpers in pkg/validation.
  • Catalog signatures for sequences, custom types and domains, relation and
    function ownership, row-security flags, policy roles, grants, and comments.

Changed

  • Migration execution now honors context cancellation for compatibility SQL and
    every migration statement.
  • CLI diagnostics use stderr so JSON output on stdout remains machine-readable.
  • Release automation now publishes only native GitHub archives and checksums;
    obsolete Homebrew and container-registry publication paths were removed.
  • Project documentation now describes the engine as a standalone OSS component
    and documents CapyDB-managed validation.

Removed

  • The unused GitHub App/webhook package and its authentication dependencies.
  • The managed subscription feature catalog and features CLI command; these
    described the retired hosted product rather than an OSS engine capability.
  • Archived CapySquash platform manifests, Docker publishing, and self-analysis
    workflows from the engine repository.