pr_01m47d15m3e54sn21z27rpy5n9/services/actions/migrations/0003_settings_access.sql

39 lines1,724 bytesCodeBlame
1-- Secrets and variables become one list, as Vercel's environment variables
2-- are: each row is a key, its type (secret or config), the environments it
3-- applies to and who reads it. A key may have one row per environment, so
4-- the unique (owner, kind, name) constraint goes; the service keeps a
5-- key's rows from overlapping. Existing rows keep working exactly as before:
6-- every environment, read by workflows alone, so nothing reaches
7-- deployments until someone says it should.
8
9CREATE TABLE settings_v2 (
10 id TEXT PRIMARY KEY,
11 -- repository or workspace.
12 scope TEXT NOT NULL,
13 -- The repository's id, or the workspace's slug.
14 owner TEXT NOT NULL,
15 -- secret or variable (shown as Config). A variable may become a secret;
16 -- a secret never becomes a variable.
17 kind TEXT NOT NULL,
18 name TEXT NOT NULL,
19 -- A secret's is sealed, bound to the row's id.
20 value TEXT NOT NULL,
21 updated_at TEXT NOT NULL,
22 -- workflows and deployments, comma-separated.
23 available_to TEXT NOT NULL DEFAULT 'workflows,deployments',
24 -- The environments it applies to, comma-separated (production, preview,
25 -- or a workflow job's `environment:`). Empty is every environment.
26 environments TEXT NOT NULL DEFAULT '',
27 -- A workspace's row: the repositories it reaches, as a JSON array of
28 -- names. Null is every repository.
29 repositories TEXT,
30 -- Where to rotate it, or who to ask.
31 note TEXT,
32 updated_by TEXT
33);
34
35INSERT INTO settings_v2 (id, scope, owner, kind, name, value, updated_at, available_to)
36 SELECT id, scope, owner, kind, name, value, updated_at, 'workflows' FROM settings;
37DROP TABLE settings;
38ALTER TABLE settings_v2 RENAME TO settings;
39CREATE INDEX settings_by_owner ON settings (owner, name);