Skip to content

fix: restore database connectivity and streamline work processing - #176

Merged
f0rr0 merged 3 commits into
nextfrom
f0rr0/fix-database-tls
Sep 28, 2026
Merged

f0rr0 merged 3 commits into
nextfrom
f0rr0/fix-database-tls

Conversation

@f0rr0

@f0rr0 f0rr0 commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Production deployments were failing before migrations because the database driver did not trust Supabase's certificate. Use Supabase's root certificate with verification enabled, and use the same pg driver and connection settings for runtime, migrations, account setup, and cron configuration.

Reduce work projection overhead while preserving PR attribution, separate branches, force-push handling, frozen history, and refresh timing:

  • Store compact commit file statistics as a PostgreSQL generated column instead of re-extracting them from patches on every read.
  • Filter current branch generations in the SQL join and return their ordered memberships together, removing two reads and repeated metadata/JavaScript filtering.
  • Combine two equivalent worker schedules into the same twelve execution slots per hour; remove the unused database driver.

Validation: 304 tests, typecheck, lint, both Knip modes, and production build passed. A historical database comparison produced identical evidence and all 334 work items across 1,375 commits and 401 branches; all 305 repository scopes also matched. Checked inactive/irrelevant branches, stale heads/lineages, empty generations, membership ordering, null/empty file facts, retention, and metadata updates. All 120 previously sampled saved snapshots remained unchanged. Fresh database, upgrade, repeat migration, and generated-column update checks passed; Drizzle reports no schema drift.

On that local historical copy, base projection reads fell from ten to eight. PostgreSQL response bytes fell from 5.35 MB to 4.75 MB (~11%), measured at the connection in three identical runs. The compact-statistics read improved from ~414 ms to ~32 ms. The generated column added ~1.9 MB to the original 79 MB commit table. These are query-level measurements, not a monthly egress guarantee. The generated migration briefly locks/rewrites the commit table; no tables or evidence are removed.

Ran the actual migration and setup scripts against disposable PostgreSQL with real cron and Vault extensions. Verified repeated/concurrent cron configuration, removal of disabled/old jobs, full rollback on injected failure, account reauthorization/history retention, identity and active-sync rejection, and atomic credential updates. Removed unused cron job-ID bookkeeping and the redundant connection wrapper.

The latest build connected to the local historical database successfully; unrelated public GitHub embed requests returned 403 and used their existing fallback. Verified read-only Supabase connections separately under Bun and Node, including certificate validation. No production migrations or deployment were run manually.

@vercel

vercel Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
f0rr0-github-io Ready Ready Preview Sep 28, 2026 11:52pm UTC

@f0rr0 f0rr0 changed the title fix: trust Supabase certificates in database connections fix: restore database connectivity and streamline work processing Sep 28, 2026
@f0rr0
f0rr0 merged commit f468a09 into next Sep 28, 2026
4 checks passed

This branch was successfully deployed

1 active deployment
Preview — b04897ee Deployed Sep 28, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant