🚑 fix(deploy): normalize schema ownership before migrations

Production deploy failed at migrate with «must be owner of table
identity_organization»: the table (and others created/imported outside the
migration role) were not owned by custocrm_schema, which migration_user must
belong to to run AddField/AlterField. This is a pre-existing condition that
surfaced on the administration migration and recurred across pipelines
(#922, #937, #938) — not caused by the calls feature.

Fix makes deploy self-healing: before running migrate, reassign ownership of
all public-schema objects (tables, sequences, functions) to custocrm_schema
under the postgres superuser. Idempotent and safe on every deploy.

- deploy/postgres/reassign-schema-ownership.sql: reassign public-schema
  ownership to custocrm_schema (verified against PG16)
- compose.yaml: mount the SQL into the postgres container
- deploy/cli/lib/deploy.sh: run the normalization step once postgres is
  healthy, before the one-shot migrate
This commit is contained in:
Andrey committed 2026-07-31 12:53:51 +03:00
1 parent e78eb9f17d
commit c4d11a8543
3 files changed
+82

No files matched your search

+19
View File
@@ -17,6 +17,9 @@ cmd_deploy() {
_wait_healthy postgres 60 || die "deploy: postgres did not become healthy" 1
_wait_healthy redis 30 || die "deploy: redis did not become healthy" 1
log "deploy: normalizing schema ownership for migrations"
_normalize_schema_ownership || die "deploy: schema ownership normalization failed" 1
log "deploy: running one-shot init (migrate)"
run_compose run --rm init || die "deploy: init (migrate) failed" 1
@@ -96,6 +99,22 @@ _wait_running() {
return 1
}
_normalize_schema_ownership() {
# Приводит владение объектов public-схемы к роли custocrm_schema, в которую
# входит migration-user. Идемпотентно: безопасно на каждом деплое. Без этого
# миграции от migration-user падают на таблицах, созданных не им
# («must be owner of table …»). Выполняется под суперпользователем POSTGRES_USER.
local env_file pg_user pg_db
env_file="$(instance_env_file)"
pg_user="$(env_get "$env_file" POSTGRES_USER)"
pg_db="$(env_get "$env_file" POSTGRES_DB)"
[[ -n "$pg_user" ]] || { log_err "POSTGRES_USER not set"; return 1; }
[[ -n "$pg_db" ]] || { log_err "POSTGRES_DB not set"; return 1; }
run_compose exec -T postgres \
psql -v ON_ERROR_STOP=1 -U "$pg_user" -d "$pg_db" \
-f /custocrm-reassign-ownership.sql >/dev/null
}
_first_json_service_state() {
local line
IFS= read -r line || return 0