postgres's runtime carries the client it provisions through

Its provisioner runs DDL by shelling out to psql, which the runtime base has no
reason to hold. Every create failed with ENOENT and retried for ever.
This commit is contained in:
2026-09-13 01:26:23 +02:00
parent 594295f009
commit 6ebf51d312
+7
View File
@@ -22,6 +22,13 @@ RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts provisioner/ind
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
FROM ${RUNTIME_BASE}
# **This module talks to its database through psql, so psql has to be here.** The client is how
# postgres's provisioner runs DDL — it does not carry a driver — and the runtime base holds only
# what every module needs. Root to install it, then back to the base's unprivileged user: a
# provisioner holding the superuser password has no business also being root in its container.
USER root
RUN apk add --no-cache postgresql-client
USER node
COPY --from=build /app/modules/postgres/dist /app/modules/postgres/dist
# What a tool host should load from this module: its event consumer and its tools, which are
# separate entrypoints because they are loaded by different things. The provisioner is the third,