fix: [outline] align database ownership before migrations
The ``pre_deploy`` hook reassigns every object of the outline database (tables, sequences, views, materialized views, standalone types, functions, procedures) to the application role before the container runs its migrations. Historical provisioning or restores running as the ``postgres`` superuser leave objects owned by ``postgres``, so any later ``ALTER`` on them fails with "must be owner of ..." and puts outline in a crash-loop at migration time. Seen on elabore.coop when upgrading 1.6.1 -> 1.10.0: migration ``20260714000000-add-mcp-to-search-queries-source.js`` failed on ``enum_search_queries_source``. Extensions are excluded from the realignment (they are managed by the ``postgres`` charm). The hook is idempotent, silent when there is no drift, and blocks the deployment (``exit 1``) if any drift remains, so the problem surfaces at deploy time instead of as a cryptic crash-loop.
This commit is contained in:
@@ -42,6 +42,28 @@ outline:
|
||||
|
||||
We monkey-patch odoo in order to make it work, be sure to use latest version in 14.0 of galicea openIDConnection module
|
||||
|
||||
* Database ownership alignment
|
||||
|
||||
The =pre_deploy= hook ensures that every object of the database
|
||||
(tables, sequences, views, materialized views, standalone types,
|
||||
functions, procedures) is owned by the application role before the
|
||||
container starts and runs its migrations.
|
||||
|
||||
Historical provisioning or restores executed as the =postgres=
|
||||
superuser leave objects owned by =postgres=, which makes any later
|
||||
=ALTER= on these objects fail with "must be owner of ..." and puts
|
||||
outline in a crash-loop at migration time. This was seen on
|
||||
2026-09-11 when upgrading elabore.coop from 1.6.1 to 1.10.0:
|
||||
migration =20260714000000-add-mcp-to-search-queries-source.js=
|
||||
failed on =enum_search_queries_source=. The same drift was found
|
||||
on every managed server (lokavaluto.fr, lagemme.org, moneko.org).
|
||||
|
||||
Extensions are excluded from the realignment (they are managed by
|
||||
the =postgres= charm). The hook is idempotent and silent when
|
||||
there is no drift, and blocks the deployment (=exit 1=) if the
|
||||
realignment fails, so the problem is visible at deploy time instead
|
||||
of as a cryptic crash-loop.
|
||||
|
||||
* Building a new image
|
||||
|
||||
We use the official image with an added patch due to 2 bugs:
|
||||
|
||||
Reference in New Issue
Block a user