Repository navigation
feat(postgres): upgrade to PostgreSQL 18 with data migration - #194
Merged
Merged
Conversation
Bumps postgres from 16 to 18. --- updated-dependencies: - dependency-name: postgres dependency-version: '18' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/docker/databases/postgre/postgres-18
branch
from
October 1, 2026 15:17
eff7bd5 to
9814051
Compare
PostgreSQL 18 cannot open a 16 data directory, and its image refuses a mount at /var/lib/postgresql/data (data now lives in /var/lib/postgresql/<major>/docker). - Mount /var/lib/postgresql on a new postgres18-data volume (compose, local runner); the 16 volume is left untouched. - databases/postgre/upgrade-major.sh: pg_dumpall with the old image, restore into the new volume with the new image; source is read only. - db-upgrade harness: per-image PostgreSQL mount, and a migration path (DB_UPGRADE_MIGRATE_SCRIPT, exit 6) used by CI for postgres majors. - ADR-005, postgres README and RUNBOOK document the procedure. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AjJSKb3q2o1MHd4gRs98tL
koydas
approved these changes
Oct 1, 2026
koydas
left a comment
Owner
There was a problem hiding this comment.
All checks green on cbdd907. postgres (databases/postgre) ran the migration path: base image (16) seeded, upgrade-major.sh dump/restore, probe read back on 18. The 16 → 17 self-test still exits 4, and smoke passes on the new /var/lib/postgresql mount. Local validation is in the PR description.
Generated by Claude Code
dependabot
Bot
deleted the
dependabot/docker/databases/postgre/postgres-18
branch
October 1, 2026 15:58
koydas
pushed a commit
that referenced
this pull request
Oct 1, 2026
- .NET 8 -> .NET 10 (#202), 4 -> 5 ADRs (ADR-005). - DB upgrade row: PostgreSQL majors go through the tested dump/restore migration (#194); the 16 -> 17 self-test is same-volume. - Migrations row: they are applied on service startup, so state "versioned, never ORM auto-create" instead of "never done at runtime". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AjJSKb3q2o1MHd4gRs98tL
koydas
added a commit
that referenced
this pull request
Oct 1, 2026
…ting at nonexistent paths (#204) * docs: lead README with the CI guarantees, not the CRUD Add a tagline and a guarantees table: DB image upgrade tests against existing volumes (with a self-test that must fail), runtime consistency between CI and Dockerfiles, versioned migrations per stack, full-stack smoke + Playwright E2E, fail-fast secrets, hardened agent endpoint. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017ywYTqfmdv1DbzxFBmwvUE * fix(gitops): remove Applications pointing at nonexistent paths client-application.yaml targeted services/client/.devops and server-application.yaml targeted services/server/.devops; neither exists. Drop both and their references in README, RUNBOOK and services/README, including the claim of an Ingress that has no manifest. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017ywYTqfmdv1DbzxFBmwvUE * docs(readme): align guarantees table with current main - .NET 8 -> .NET 10 (#202), 4 -> 5 ADRs (ADR-005). - DB upgrade row: PostgreSQL majors go through the tested dump/restore migration (#194); the 16 -> 17 self-test is same-volume. - Migrations row: they are applied on service startup, so state "versioned, never ORM auto-create" instead of "never done at runtime". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AjJSKb3q2o1MHd4gRs98tL --------- Co-authored-by: Claude <noreply@anthropic.com>
This was referenced Oct 1, 2026
Merged
koydas
added a commit
that referenced
this pull request
Oct 2, 2026
…tabase images (#208) * docs: lead README with the CI guarantees, not the CRUD Add a tagline and a guarantees table: DB image upgrade tests against existing volumes (with a self-test that must fail), runtime consistency between CI and Dockerfiles, versioned migrations per stack, full-stack smoke + Playwright E2E, fail-fast secrets, hardened agent endpoint. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017ywYTqfmdv1DbzxFBmwvUE * fix(gitops): remove Applications pointing at nonexistent paths client-application.yaml targeted services/client/.devops and server-application.yaml targeted services/server/.devops; neither exists. Drop both and their references in README, RUNBOOK and services/README, including the claim of an Ingress that has no manifest. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017ywYTqfmdv1DbzxFBmwvUE * docs(readme): align guarantees table with current main - .NET 8 -> .NET 10 (#202), 4 -> 5 ADRs (ADR-005). - DB upgrade row: PostgreSQL majors go through the tested dump/restore migration (#194); the 16 -> 17 self-test is same-volume. - Migrations row: they are applied on service startup, so state "versioned, never ORM auto-create" instead of "never done at runtime". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AjJSKb3q2o1MHd4gRs98tL * docs: lead README with the Postgres 16 to 18 upgrade that CI caught Address the #204 review findings that landed after merge: - first screen: problem-first hook, the Dependabot postgres 16 -> 18 story with its red and green runs, a Mermaid of the probe flow, a two-command try-it, and 3 badges instead of 7 - scope the upgrade guarantee to bumps made through a PR and name the floating mongo:8 / mssql 2025-latest tags - prerequisites: Node.js 26, the version the Dockerfiles ship Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017ywYTqfmdv1DbzxFBmwvUE * chore(databases): pin every database image to the version it runs today mongo:8 -> 8.3.11, postgres:18 -> 18.6 (both the exact versions those tags resolve to now) and mssql/server:2025-latest pinned by digest (2025-CU9-ubuntu-24.04). Floating tags let an upstream image change ship with no PR, so the db-upgrade harness never ran on it; with pins, Dependabot proposes the change (tag or digest) and the harness tests it. The README guarantee no longer needs the 'through a PR' qualifier. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017ywYTqfmdv1DbzxFBmwvUE --------- Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #203. Started as Dependabot's
postgres16 → 18 bump, completed with the migration it needs (ADR-004, ADR-005).Why the bare bump failed
smoke: from 18 the official image keeps data in/var/lib/postgresql/18/dockerand refuses to start with a mount at/var/lib/postgresql/data.db-upgrade(postgres): a 16 data directory cannot be opened by 18 withoutpg_upgradeor dump/restore. This is the failure the ci: regression guards for dependency upgrades (runtime drift, DB volume upgrades, grouped bumps) #184 guard is there to catch.Changes
VOLUME /var/lib/postgresql. The root compose uses a newpostgres18-datavolume, and the local runner (start.sh,databases/postgre/docker-compose.yml) uses./pgdata. The 16 volume/directory is left untouched.databases/postgre/upgrade-major.sh:pg_dumpallwith the old image, then a restore into an empty destination with the new image. The source is only read. It accepts volume names or absolute host paths. Defaults cover compose 16 → 18. The only error it tolerates is the superuser'sCREATE ROLE(that role already exists in the new cluster); any other restore error fails the run.VOLUME. A newDB_UPGRADE_MIGRATE_SCRIPTmakes the harness migrate to a new volume when the postgres major changes (exit6if the script fails). The workflow sets it forpostgres (databases/postgre)only. The 16 → 17 self-test, which must exit4, is unchanged.databases/postgre/README.md, and a new RUNBOOK section (3).Validation (local, Docker)
0. Without migration it returns4, as expected. Self-test 16 → 17 returns4. Same-major 18 → 18 with the script set stays in place and returns0.mongo:8→mongo:8returns0.upgrade-major.sh, 16 → 18 on a volume with tables, a sequence, a second login role with grants and a second database: all present and readable on 18, with data under/var/lib/postgresql/18/docker. The source volume still reportsPG_VERSION16. A non-empty destination and a missing source are both refused (exit 1). Bind-path mode was also checked.upgrade-major.sh(defaults) →docker compose up postgres→ the row andalembic_versionare readable on 18.6.alembic upgrade headpasses, and POST/GET/api/serviceswork.npm run test:consistency(10/10) are clean.Notes
upgrade-major.shonce (see the README). Without it, PG18 simply starts empty on the new volume and nothing is lost.services/services-service/.devops/secret.yamlpoints to apostgreshost that has no manifest in this repository. A cluster-side PostgreSQL, if there is one, needs its own upgrade procedure.Checklist
databases/postgre/README.md,docs/RUNBOOK.md)🤖 Generated with Claude Code
https://claude.ai/code/session_01AjJSKb3q2o1MHd4gRs98tL