g1t/services/identity/migrations/0025_workspace_soft_delete.sql

24 lines1,331 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member1-- Deleting a workspace is soft. Its row stays, with when, by whom and
2-- until when it can be restored, and every read that resolves a workspace
3-- leaves it out: nobody's memberships list it, its tokens are refused and
4-- its pages are not found. Its members and tokens are kept as they were, so
5-- a restore by g1t's staff brings it back whole. The row holding its slug
6-- keeps the slug from anyone else meanwhile. Once purge_after passes, the
7-- scheduled purge removes it as deleting always did (src/deletion.rs).
8--
9-- `deleted_went` is what went with it, counted when it was deleted (JSON:
10-- repositories, projects, members), for staff deciding on a restore.
11--
12-- `protected`: a workspace that can never be deleted, by anyone. It is
13-- kept on the row as well as in PROTECTED_WORKSPACES, so a rename does not
14-- take the protection away.
15ALTER TABLE workspaces ADD COLUMN deleted_at TEXT;
16ALTER TABLE workspaces ADD COLUMN deleted_by TEXT;
17ALTER TABLE workspaces ADD COLUMN purge_after TEXT;
18ALTER TABLE workspaces ADD COLUMN deleted_went TEXT;
19ALTER TABLE workspaces ADD COLUMN protected INTEGER NOT NULL DEFAULT 0;
20
21CREATE INDEX IF NOT EXISTS workspaces_purge_after ON workspaces (purge_after) WHERE deleted_at IS NOT NULL;
22
23-- Flagon's workspace runs g1t.
24UPDATE workspaces SET protected = 1 WHERE slug = 'flagon-io';