Repository navigation
PostgreSQL Semantic Gateway 1.0.0
PostgreSQL Semantic Gateway 1.0.0
The first stable release of postgresem: a PostgreSQL-native semantic gateway
for agents and applications, with governed queries and ingestion instead of a
raw-SQL public interface.
Highlights
- Stable LSQ/LSM, Semantic Snapshot, MCP, CLI, error, migration, and audit
contracts, with documented compatibility, support, and deprecation policies. - Deterministic typed compilation, immutable model publication, catalog drift
detection, and anchored aggregation that preserves the declared business
grain rather than multiplying measures through fan-out joins. - PostgreSQL GRANT/RLS enforcement, guarded query execution, governed
insert/upsert, durable audit, idempotent replay, and role-bound reconciliation. - Stdio and authenticated HTTP MCP, plus Docker, Compose, Podman, and Quadlet
deployment paths. - Meaning Lab, one real-PostgreSQL demo comparing schema-only candidate
queries with explicit business semantics for recognized revenue, SKU revenue,
and MRR. It also demonstrates governed writes, retries, reconciliation,
tenant RLS, and rejection boundaries. English is the default; Japanese is
selectable. The optional OpenAI planner requires explicit user configuration;
the default comparisons are authored scenarios, not fabricated agent output.
Upgrade requirement
Apply migrations through 0011_mutation_reconcile_writer_role before
deploying the new binary. Reconciliation now requires the recorded writer
role as well as the principal. The old role-unbound overload is removed;
do not recreate it during rollback. Cross-version reconciliation at this
schema boundary fails closed. Unused time and PEM/ASN.1 dependencies have
also been removed.
Release evidence and limitations
This release uses the explicitly approved
v1.0.0-only maintainer exception.
The automated source review and remediation evidence
is accepted for corrected source c8a2ca7. Independent third-party review,
reviewed-image evidence, and two 28-day non-fixture pilots are waived, not
completed; field outcomes are not measured. Subsequent changes are restricted
to the documented release-governance paths. Runtime authorization, technical
qualification, artifact signing, SBOM, and provenance controls remain in place.
The exception does not carry forward to later stable releases.
Downloads
Binary archives are available for Linux and macOS, each on amd64 and arm64.
The assets include native Linux binary/image runtime evidence and signed
SHA256SUMS. The multi-architecture container image is
ghcr.io/rioriost/postgresem:1.0.0.
Immutable image:
ghcr.io/rioriost/postgresem@sha256:3b79ad1976f9f87cef54c0195b1fdb71d48542c971cb155345a98232802bf330.
Release commit:
a9315827861ec4b807bdbf5ff4ce92fe3900b808.
Follow release verification
before running an archive or image. Pin the verified container digest for
deployment.
Changelog
| English guide
| Japanese guide
| Changes since v0.7.0