Skip to content

ci: wire ephemeral Postgres into go-tests so RLS suites actually run - #336

Merged
sakibsadmanshajib merged 2 commits into
mainfrom
feat/ci-test-db
Jul 16, 2026
Merged

sakibsadmanshajib merged 2 commits into
mainfrom
feat/ci-test-db

Conversation

@sakibsadmanshajib

@sakibsadmanshajib sakibsadmanshajib commented Jul 16, 2026 •

Copy link
Copy Markdown
Owner

Summary

Closes the blind spot that hid the Repository.Transition 42P18 bug found in PR #333: HIVE_TEST_DB_URL-gated RLS suites (rag, artifacts, agenttask, egress) existed but had no database in CI, so they always skipped silently and nothing ever caught real bugs in that code path.

  • Adds a pgvector/pgvector:pg17 service to the go-tests job. Version pin: no supabase/config.toml or other in-repo Postgres version pin exists, so this tracks Supabase's current default managed major (17) as the closest available reference — bump the tag if that default changes. pgvector/pgvector (not the plain postgres image) because 20260625_01_enable_pgvector.sql needs the vector extension pre-built; otherwise it's a drop-in postgres image.
  • New step, gated to the control-plane and edge-api matrix legs only: bootstraps the Supabase-managed objects those migrations assume already exist on a real project (hive_app/auditor_ro/authenticated/supabase_auth_admin roles, the auth schema, minimal auth.uid()/auth.jwt() stand-ins) via a new CI-only .github/ci/test-db-bootstrap.sql, then applies every supabase/migrations/*.sql file in order, then runs the four target packages with HIVE_TEST_DB_URL set and -v so the job log shows individual PASS lines, not just a package-level ok.
  • The existing go test ./... step is untouched (no HIVE_TEST_DB_URL there), so nothing already green changes behavior — this PR only adds new coverage, it doesn't touch the existing required-check baseline.

Job log evidence (this exact reproduction, verified locally before pushing with the workflow's literal commands against a scratch pgvector/pgvector:pg17 container)

ok  	.../apps/control-plane/internal/agenttask	1.242s   (32 tests, incl. TestRepository_RLS_ActiveTaskStillHiddenAcrossTenants, TestPoller_*)
ok  	.../apps/control-plane/internal/egress	0.279s   (27 tests, incl. TestPgxRepository_RLS_*)
ok  	.../apps/control-plane/internal/rag	0.359s   (24 tests, incl. TestRepo_RLS_*)
ok  	.../apps/edge-api/internal/artifacts	0.872s   (29 tests, incl. TestRepo_RLS_*)

All previously---- SKIP'd RLS tests in these four packages now show --- PASS individually — this PR's own CI run will show the same live.

Pre-existing bugs found while replaying every migration from scratch for the first time ever (none fixed here — CI wiring only, no product-code changes per scope)

  1. Worked around in this PR (documented inline in the workflow): 20260516_04_phase19_audit_log.sql and 20260625_06_audit_cold_archive_manifest.sql both create a table named public.audit_cold_archive_manifest with different column shapes. The later file's CREATE TABLE IF NOT EXISTS silently no-ops against the earlier (stale) shape on any from-scratch replay, so a later ALTER in that same file fails against columns that don't exist. Worked around with a CI-only DROP TABLE immediately before that one migration file — applies only to this run's throwaway database, never a real environment. This may indicate the same defect is live wherever this migration history was ever applied fresh (a new environment, a disaster-recovery rebuild) — flagging for a real fix and for someone with prod access to check \d public.audit_cold_archive_manifest there.
  2. Not touched, flagged only (this PR's live-DB step doesn't run these packages, so nothing here newly breaks CI):
    • apps/control-plane/internal/marketplace's marketplace_entries table has no GRANT to hive_app at all in 20260716_01_marketplace_catalog.sql (permission denied for table marketplace_entries, SQLSTATE 42501).
    • apps/control-plane/tests/compliance's TestAuditRetention_ColdArchiveManifestExists checks for a partition_name column that hasn't existed since the schema evolved to the richer shape.
    • apps/control-plane/internal/tenants has two failures (TestSwitch_Allowed_UpdatesMetadataAndAudits, TestSwitch_NonMember_403CrossTenant) whose audit-log-write assertions don't match what's actually persisted against a real database.

Test plan

  • Bootstrap + all 61 migrations apply cleanly against a scratch Postgres (given the one documented workaround above)
  • apps/control-plane/internal/agenttask, egress, rag, and apps/edge-api/internal/artifacts all run and PASS for real (not skipped) — verified locally with the exact workflow commands
  • YAML syntax validated (python3 -c "import yaml; yaml.safe_load(...)")
  • This PR's own CI run — will confirm the job log shows the same PASS lines live

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Tests

    • Added automated database-backed testing for control-plane and edge API components.
    • Added coverage for row-level security behavior against a PostgreSQL test environment.
    • Improved test setup reliability by automatically preparing required authentication and authorization data.
  • Chores

    • Updated continuous integration workflows to provision and configure isolated PostgreSQL databases for relevant test runs.
    • Added safeguards to handle known database migration compatibility issues during CI.

Closes the blind spot that hid the Repository.Transition 42P18 bug
(PR #333): HIVE_TEST_DB_URL-gated suites (rag, artifacts, agenttask,
egress) existed but had no database in CI, so they always skipped
silently and nothing ever caught it.

Adds a pgvector/pgvector:pg17 service to the go-tests job (pinned to
Postgres 17, the closest available reference to Supabase's current
default managed major -- no in-repo config.toml or other pin exists;
pgvector image chosen over plain postgres since
20260625_01_enable_pgvector.sql needs the vector extension pre-built).
A new step, gated to the control-plane and edge-api matrix legs only,
bootstraps the Supabase-managed objects those migrations assume exist
on a real project (hive_app/auditor_ro/authenticated/
supabase_auth_admin roles, the auth schema, minimal auth.uid()/
auth.jwt() stand-ins) via a new CI-only .github/ci/test-db-bootstrap.sql,
then applies every supabase/migrations/*.sql file in order, then runs
the four target packages with HIVE_TEST_DB_URL set and -v so the job
log shows individual PASS lines, not just a package-level ok. The
existing go test ./... step is untouched (no HIVE_TEST_DB_URL there),
so nothing already green changes behavior.

While replaying every migration from scratch for the first time ever,
found a genuine pre-existing schema defect unrelated to this PR:
20260516_04_phase19_audit_log.sql and 20260625_06_audit_cold_archive_
manifest.sql both create a table named public.audit_cold_archive_
manifest with different column shapes; the later file's CREATE TABLE
IF NOT EXISTS silently no-ops against the earlier (stale) shape, so a
later ALTER in that same file fails against columns that don't exist.
Per scope (CI wiring only, no product-code changes), this is worked
around with a CI-only DROP TABLE immediately before that one migration
file, clearly commented, applied only to this run's throwaway
database -- never a real environment. Tracked separately for a real
fix; flagging in the PR description that this may indicate the same
defect is live wherever this migration history was ever applied fresh.

Verified locally end to end against a scratch container with the
exact workflow commands before pushing: bootstrap + all 61 migrations
apply cleanly (given the one documented workaround), and
apps/control-plane/internal/{agenttask,egress,rag} plus
apps/edge-api/internal/artifacts all run and pass for real, not skip.

Also discovered (out of scope, not fixed, flagged separately):
apps/control-plane/internal/marketplace's marketplace_entries table has
no GRANT to hive_app at all in 20260716_01_marketplace_catalog.sql;
apps/control-plane/tests/compliance's
TestAuditRetention_ColdArchiveManifestExists checks for a
partition_name column that hasn't existed since the schema evolved;
and apps/control-plane/internal/tenants has two failures whose audit
log write assertions don't match what's actually persisted against a
real database. None of these are touched by this PR (this PR's new
live-DB step only runs the four named packages); each is a real,
separate, pre-existing bug this same blind spot was hiding.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@cursor

cursor Bot commented Jul 16, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@coderabbitai

coderabbitai Bot commented Jul 16, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@sakibsadmanshajib, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 47 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 9a3ee488-d33c-4a6d-9b47-2fbcc66e1a87

📥 Commits

Reviewing files that changed from the base of the PR and between 03ef739 and f60ee21.

📒 Files selected for processing (1)
  • .github/workflows/ci.yml
📝 Walkthrough

Walkthrough

Adds an ephemeral PostgreSQL service to selected CI matrix legs, bootstraps Supabase-compatible auth objects and migrations, exports HIVE_TEST_DB_URL, and runs module-specific RLS-focused Go tests.

Changes

RLS CI database testing

Layer / File(s) Summary
Supabase-compatible test objects
.github/ci/test-db-bootstrap.sql
Defines CI-only roles, the auth schema, auth.users, auth.uid(), and auth.jwt() compatibility functions.
Ephemeral database and RLS test execution
.github/workflows/ci.yml
Starts PostgreSQL for control-plane and edge-api, applies the bootstrap and Supabase migrations, exports HIVE_TEST_DB_URL, and runs RLS test packages.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant GoTests
  participant Postgres
  participant BootstrapSQL
  participant SupabaseMigrations
  participant RLSGoTests
  GoTests->>Postgres: start pgvector/pg17 service
  GoTests->>BootstrapSQL: apply CI auth objects
  GoTests->>SupabaseMigrations: apply migration chain
  GoTests->>RLSGoTests: run with HIVE_TEST_DB_URL
  RLSGoTests->>Postgres: execute RLS-focused tests
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main CI change: wiring ephemeral Postgres into go-tests to run RLS suites.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/ci-test-db

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/ci.yml:
- Around line 71-75: Update the Postgres health check command in the service
options to include the host argument -h 127.0.0.1 with pg_isready, ensuring
readiness is validated over TCP rather than the local Unix socket.
- Around line 151-155: Update the non-control-plane branch of the CI test matrix
to run the edge-api RLS tests under internal/rag in addition to the existing
internal/artifacts tests. Preserve the control-plane command unchanged and
include the repository_rls_test.go coverage through the appropriate
./internal/rag/... package pattern.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: f8850dcc-9b8c-478a-939d-c63528d4f2bb

📥 Commits

Reviewing files that changed from the base of the PR and between 0c42b5d and 03ef739.

📒 Files selected for processing (2)
  • .github/ci/test-db-bootstrap.sql
  • .github/workflows/ci.yml

Comment thread .github/workflows/ci.yml
Comment thread .github/workflows/ci.yml
CodeRabbit: pg_isready without -h checks the Unix socket, which the
Postgres entrypoint's temporary init-phase instance answers before
restarting for real on TCP -- a false-ready health check that can
race CI steps against connection-refused. Add -h 127.0.0.1.

Also: edge-api's non-control-plane branch only ran internal/artifacts,
silently skipping apps/edge-api/internal/rag's own RLS suite
(repository_rls_test.go, separate from control-plane's rag package).
Added it. Verified both fixes locally: reproduced the exact race by
omitting -h (confirms the finding), then confirmed clean with it;
edge-api's rag RLS tests (incl. TestRepo_RLS_SearchChunksCannotReadOtherTenantChunks)
now pass for real alongside artifacts.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@sakibsadmanshajib

Copy link
Copy Markdown
Owner Author

Both fixed in f60ee21:

  1. -h 127.0.0.1 added to the health check — reproduced the exact race locally (omitting it, my own verification hit "database system is shutting down" then a cascaded migration failure), confirmed clean with the fix.
  2. edge-api branch now also runs ./internal/rag/... — confirmed TestRepo_RLS_SearchChunksCannotReadOtherTenantChunks and the rest of that suite pass for real.

@sakibsadmanshajib
sakibsadmanshajib merged commit 3b3a079 into main Jul 16, 2026
18 of 19 checks passed
@github-actions
github-actions Bot deleted the feat/ci-test-db branch July 16, 2026 15:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant