Detach legacy RunLog D1 inventories - #1206
Conversation
📝 WalkthroughWalkthroughThe change detaches legacy RunLog D1 projection tables from account deletion/export, retention, runtime queries, and entitlement mocks. The tables remain rollback copies until migration ChangesRunLog projection detachment
Estimated code review effort: 3 (Moderate) | ~20 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
🔎 Preview deployed: https://kody-pr-1206.kody-a99.workers.dev Worker: Mocks:
|
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/contributing/architecture/data-storage.md`:
- Around line 217-222: Update the account-erasure flow to continue purging
deleted-user rows from the legacy projection tables workflow_runs,
user_package_run_successes, and user_activation_milestones until migration 0137
drops them. Add an explicit pre-drop per-user purge or retain these tables in
the existing deletion coverage, and ensure the coverage stops only after the
physical tables are removed.
In `@packages/worker/src/account/data-targets.ts`:
- Around line 74-84: Remove the user-scoped tables from
accountQuiescentDetachedD1ProjectionTables so workflow_runs,
user_package_run_successes, and user_activation_milestones remain covered by
deletion, export, and retention until their physical drop; use only a
non-user-owned sanitized rollback artifact if rollback data is needed.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 75fec259-6f5e-476d-9952-38f2671b8847
📒 Files selected for processing (17)
docs/contributing/architecture/data-storage.mddocs/contributing/architecture/entitlements.mddocs/contributing/architecture/run-records.mdpackages/worker/src/account/data-targets.node.test.tspackages/worker/src/account/data-targets.tspackages/worker/src/account/export.node.test.tspackages/worker/src/account/user-owned-surfaces.node.test.tspackages/worker/src/account/user-owned-surfaces.tspackages/worker/src/admin/user-usage-data.node.test.tspackages/worker/src/app/account-deletion.node.test.tspackages/worker/src/app/account-retention-dispositions.node.test.tspackages/worker/src/app/account-retention-dispositions.tspackages/worker/src/app/retention.node.test.tspackages/worker/src/app/retention.tspackages/worker/src/entitlements/entitlements.node.test.tspackages/worker/src/entitlements/service.tspackages/worker/src/mcp/capabilities/admin/admin-capabilities.node.test.ts
💤 Files with no reviewable changes (4)
- packages/worker/src/app/account-retention-dispositions.ts
- packages/worker/src/admin/user-usage-data.node.test.ts
- packages/worker/src/mcp/capabilities/admin/admin-capabilities.node.test.ts
- packages/worker/src/app/retention.ts
| by retention. Legacy D1 projection tables (`workflow_runs`, | ||
| `user_package_run_successes`, `user_activation_milestones`) are quiescent | ||
| rollback copies outside account deletion/export inventory; migration-only | ||
| `0137` drops the physical tables. Pre-drop D1 Time Travel bookmark for | ||
| database `8c1014d1-6b41-4695-a0a2-159071f0f919`: | ||
| `0000116d-000000d2-000050bd-c7ecd5892a189df7cda145af746bc9c9`. See |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift
🧩 Analysis chain
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
rg -n -C 8 \
'workflow_runs|user_package_run_successes|user_activation_milestones' \
packages/worker/src/account packages/worker/src/app packages/worker/migrationsRepository: kentcdodds/kody
Length of output: 38361
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
echo "== docs references =="
sed -n '190,235p' docs/contributing/architecture/data-storage.md
sed -n '318,345p' docs/contributing/architecture/data-storage.md
sed -n '1488,1512p' docs/contributing/architecture/data-storage.md
echo
echo "== data-targets around quiescent tables =="
sed -n '60,95p' packages/worker/src/account/data-targets.ts
echo
echo "== user-owned-surfaces run_log notes =="
sed -n '110,129p' packages/worker/src/account/user-owned-surfaces.ts
echo
echo "== account-related references =="
rg -n -C 5 'accountQuiescentDetachedD1ProjectionTables|legacy projection|workflow_runs|user_package_run_successes|user_activation_milestones|delete .*account|account deletion|retention' packages/worker/src/account packages/worker/src/app docs/contributing/architecture/data-storage.md
echo
echo "== account deletion code outline candidates =="
rg -n 'deleteAccount|clearAll|DELETED|deleted|account.*delete|durable storage|D1|workflow_runs|user_package_run_successes|user_activation_milestones' packages/worker/src/account packages/worker/src/app -g '!*.test.*' -g '!*.node.test.*' | head -n 250Repository: kentcdodds/kody
Length of output: 50372
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
echo "== definitions and array consumers =="
rg -n -C 5 'accountQuiescentDetachedD1ProjectionTables|accountUserDataTargets|buildUserScopedTargetMatch|userOwnedD1Surfaces|D1Table|D1Target|deleteAll|clearAllRows|account deletion|deleteByUserId' packages/worker/src/account packages/worker/src/app packages/worker/src -g '!*.test.*' -g '!*.node.test.*'
echo
echo "== account data-targets full relevant area =="
sed -n '1,180p' packages/worker/src/account/data-targets.ts
echo
echo "== migration 0137 schema/drop =="
fd -e sql . packages/worker/migrations | rg '0137|0136' || true
for f in packages/worker/migrations/0137*.sql packages/worker/migrations/0136*.sql; do
if [ -f "$f" ]; then
echo "--- $f ($(wc -l < "$f") lines) ---"
head -n 220 "$f"
fi
doneRepository: kentcdodds/kody
Length of output: 50372
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
echo "== 0137 drops / related cleanup =="
for f in packages/worker/migrations/0137*.sql packages/worker/migrations/0136*.sql packages/worker/migrations/0138*.sql; do
[ -f "$f" ] || continue
echo "--- $f ($(wc -l < "$f") lines) ---"
rg -n -C 4 'workflow_runs|user_package_run_successes|user_activation_milestones|DROP TABLE|DROP INDEX|CREATE TRIGGER|DELETE FROM|ON DELETE CASCADE' "$f" || true
done
echo
echo "== buildUserScopedTargetMatch implementation =="
sed -n '450,620p' packages/worker/src/account/data-targets.ts
echo
echo "== account deletion D1 section =="
sed -n '1000,1090p' packages/worker/src/app/account-deletion.ts
echo
echo "== retention dispositions relevant lines =="
sed -n '1,110p' packages/worker/src/app/account-retention-dispositions.tsRepository: kentcdodds/kody
Length of output: 10074
Keep legacy projection rows in user-account erasure until migration 0137.
workflow_runs, user_package_run_successes, and user_activation_milestones still hold rows for deleted users until the destructive migration drops the physical tables, because account deletion/export and retention inventory no longer touch them. Add an explicit pre-drop purge for these per-user rows, or keep them covered until the physical drop.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docs/contributing/architecture/data-storage.md` around lines 217 - 222,
Update the account-erasure flow to continue purging deleted-user rows from the
legacy projection tables workflow_runs, user_package_run_successes, and
user_activation_milestones until migration 0137 drops them. Add an explicit
pre-drop per-user purge or retain these tables in the existing deletion
coverage, and ensure the coverage stops only after the physical tables are
removed.
Source: Coding guidelines
| /** | ||
| * Legacy RunLog D1 projection tables kept as quiescent rollback copies after | ||
| * the RunLog authority application deploy. Deploy 2 detaches account | ||
| * deletion/export inventory and the hourly D1 workflow_runs retention lane; | ||
| * migration-only `0137` drops the physical tables. | ||
| */ | ||
| export const accountQuiescentDetachedD1ProjectionTables = [ | ||
| 'workflow_runs', | ||
| 'user_package_run_successes', | ||
| 'user_activation_milestones', | ||
| ] as const |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift
Keep these user-scoped tables in deletion and export coverage.
These tables remain present and contain user_id rows. Detaching deletion, export, and retention leaves deleted-user RunLog data in durable storage with no scheduled cleanup. Keep deletion and export coverage until the physical drop. If rollback data is required, store only a sanitized artifact that is not user-owned.
As per coding guidelines, “Every signed-in user must have a fully isolated personal assistant, including separate packages, jobs, secrets, values, memories, remote connectors, email inboxes, and durable storage.”
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/worker/src/account/data-targets.ts` around lines 74 - 84, Remove the
user-scoped tables from accountQuiescentDetachedD1ProjectionTables so
workflow_runs, user_package_run_successes, and user_activation_milestones remain
covered by deletion, export, and retention until their physical drop; use only a
non-user-owned sanitized rollback artifact if rollback data is needed.
Source: Coding guidelines
Migration-only follow-up to the RunLog authority cutover (#1205) and inventory detach (#1206). Drops quiescent workflow_runs, user_package_run_successes, and user_activation_milestones with their indexes. Pre-drop Time Travel bookmark recorded in the migration header. Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Intent
Deploy the final application-side inventory and retention cleanup before the migration-only D1 drop. This keeps the old Worker compatible when the later deploy applies migration 0137 before Worker code.
Summary
workflow_runs,user_package_run_successes, anduser_activation_milestonesfrom account deletion/export D1 targetsTesting
0000116d-000000d2-000050bd-c7ecd5892a189df7cda145af746bc9c9System changes
No D1 tables are dropped in this PR. Physical rollback copies remain until the migration-only follow-up deploy.
Conductor report
STATUS: in-progress
What shipped: inventory/retention detachment is pushed; CI/AI review and deployment pending.
Risk self-assessment: medium — deletion/export and retention inventories change, but physical tables and Time Travel recovery remain.
Merged/deployed: no / no.
Scope spill: none. This is deploy 2 of 3; deploy 3 is migration-only 0137 and will stop for conductor review.
Summary by CodeRabbit
Data Management
Documentation
Entitlements & Administration