g1t/services/actions/migrations/0003_settings_access.sql

38 lines1,635 bytesCodeBlame
1-- Secrets and variables become one list, as Vercel's environment variables
2-- are: each row is a key, its type (secret or config), the environments it
3-- applies to and who reads it. A key may have one row per environment, so
4-- the unique (owner, kind, name) constraint goes; the service keeps a
5-- key's rows from overlapping. Existing rows keep working as before: every
6-- environment, read by workflows and deployments.
7
8CREATE TABLE settings_v2 (
9 id TEXT PRIMARY KEY,
10 -- repository or workspace.
11 scope TEXT NOT NULL,
12 -- The repository's id, or the workspace's slug.
13 owner TEXT NOT NULL,
14 -- secret or variable (shown as Config). A variable may become a secret;
15 -- a secret never becomes a variable.
16 kind TEXT NOT NULL,
17 name TEXT NOT NULL,
18 -- A secret's is sealed, bound to the row's id.
19 value TEXT NOT NULL,
20 updated_at TEXT NOT NULL,
21 -- workflows and deployments, comma-separated.
22 available_to TEXT NOT NULL DEFAULT 'workflows,deployments',
23 -- The environments it applies to, comma-separated (production, preview,
24 -- or a workflow job's `environment:`). Empty is every environment.
25 environments TEXT NOT NULL DEFAULT '',
26 -- A workspace's row: the repositories it reaches, as a JSON array of
27 -- names. Null is every repository.
28 repositories TEXT,
29 -- Where to rotate it, or who to ask.
30 note TEXT,
31 updated_by TEXT
32);
33
34INSERT INTO settings_v2 (id, scope, owner, kind, name, value, updated_at)
35 SELECT id, scope, owner, kind, name, value, updated_at FROM settings;
36DROP TABLE settings;
37ALTER TABLE settings_v2 RENAME TO settings;
38CREATE INDEX settings_by_owner ON settings (owner, name);