feat(run): govern registered Postgres databases via the gateway pg proxy - #104
Open
johnnyfish wants to merge 1 commit into
Open
feat(run): govern registered Postgres databases via the gateway pg proxy#104johnnyfish wants to merge 1 commit into
johnnyfish wants to merge 1 commit into
Conversation
onecli run now scans the process env and project .env files for
postgres:// URLs, matches them by host against the project's registered
database connections (GET /v1/pg/connections — host/port only, never
credentials), mints a proxy session per matched connection
(POST /v1/pg/sessions), and swaps the matched env vars for gateway proxy
URLs (aoc_pg_<token> username, dummy password) that shadow .env for
default-precedence loaders. Real credentials never enter the agent env;
every statement lands in the OneCLI activity log.
Unmatched database hosts warn ('connect it in the dashboard') and are
left untouched. A detached sidecar (hidden __pg-sidecar mode, forked
before exec so TTY semantics are preserved) heartbeats the sessions and
reaps them when the agent exits; if the sidecar dies the gateway expires
sessions by TTL. Opt out with --no-pg-proxy.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
onecli run now scans the process env and project .env files for postgres:// URLs, matches them by host against the project's registered database connections (GET /v1/pg/connections — host/port only, never credentials), mints a proxy session per matched connection (POST /v1/pg/sessions), and swaps the matched env vars for gateway proxy URLs (aoc_pg_ username, dummy password) that shadow .env for default-precedence loaders. Real credentials never enter the agent env; every statement lands in the OneCLI activity log.
Unmatched database hosts warn ('connect it in the dashboard') and are left untouched. A detached sidecar (hidden __pg-sidecar mode, forked before exec so TTY semantics are preserved) heartbeats the sessions and reaps them when the agent exits; if the sidecar dies the gateway expires sessions by TTL. Opt out with --no-pg-proxy.