Skip to content

Fail closed when the design-time migration connection is unset or insecure #318

Description

@mforce

Parent: #244
Epic: #15
Severity: Low
Execution mode: AFK

What to build

Remove the public postgres/postgres fallback from AppDbContextDesignTimeFactory. Design-time EF commands currently connect to a predictable local database when CLUCKWORK_MIGRATIONS_CONNECTION is absent and always skip the production TLS floor. That makes an operator typo capable of targeting the wrong database and encourages a known credential.

Require an explicit migration connection. Permit plaintext only for an explicitly acknowledged loopback development target; non-loopback design-time connections must validate server identity using the same connection-string normalization and TLS rules as production migrations.

Acceptance criteria

  • An unset or blank CLUCKWORK_MIGRATIONS_CONNECTION fails immediately with a clear message that does not print a connection string.
  • No default username, password, host, or database remains in the factory.
  • A non-loopback connection weaker than VerifyCA or VerifyFull fails before EF connects.
  • Any local plaintext escape hatch is explicit, development-only, and rejects non-loopback hosts.
  • Unit tests cover missing config, loopback opt-in, URI normalization, weak remote TLS, and VerifyFull.
  • Migration documentation shows placeholder-only commands and never embeds credentials.

Blocked by

None.

Activity

  1. added
    bugSomething isn't working
    sliceThin vertical work item
    area:apiAPI/endpoint layer
    .NETPull requests that update .NET code
    on Jul 31, 2026
  2. added 4 commits that reference this issue on Aug 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    .NETPull requests that update .NET codearea:apiAPI/endpoint layerbugSomething isn't workingepic-1.5sliceThin vertical work item

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions