# Tasks RLS handover examples

These files support the article. Run database commands only against a disposable
PostgreSQL database. The role running migrations must own the schema and be
allowed to manage its tables, policies, and grants.

## Inputs

- Ptah Compat 0.11.4, published Linux amd64 release; PostgreSQL 16.15.
- `db/schema.hcl` is the complete proposed tasks schema.
- `init-db.sql` is the project's local role bootstrap. Its embedded password is
  a development fixture, not a production credential.
- `original/` holds the upstream HCL and RLS SQL used for the handover control.
- `TASKS-LICENSE.txt` accompanies the source files copied from dmikalova/tasks.
  The HCL modification moves the original policies and grants into desired state;
  the bootstrap modification updates a comment. Source revisions are recorded in
  `verified.json`.
- `snippets/` contains the exact policy and configuration excerpts shown in the
  article. The policy is part of `db/schema.hcl`, not a standalone schema.

## Repeat the article example

Install the published `ptah-compat` binary and PostgreSQL client. From this
`examples/` directory, set `DATABASE_URL` to an empty disposable database, then:

```sh
psql "$DATABASE_URL" -v ON_ERROR_STOP=1 -f init-db.sql
sh commands/apply.txt
psql "$DATABASE_URL" -v ON_ERROR_STOP=1 -f sql/catalog.sql
sh commands/preview.txt
psql "$DATABASE_URL" -v ON_ERROR_STOP=1 -f sql/drift.sql
sh commands/preview.txt
psql "$DATABASE_URL" -v ON_ERROR_STOP=1 -f sql/policy-state.sql
sh commands/apply.txt
psql "$DATABASE_URL" -v ON_ERROR_STOP=1 -f sql/policy-state.sql
sh commands/settled.txt
```

The bootstrap creates the local role. The fresh schema has 11 tables, 32 policies,
and eight tables with both RLS flags. After drift, preview must leave the `false`
predicate and disabled FORCE flag unchanged. Apply restores both; the JSON plan
then has an empty `Changes` object. `measured/commands.json` records the actual
container invocations used to capture these results. The shell command files
are the literal CLI examples; they add no planning or migration behavior.

## Earlier integration verification

The handover control used Atlas Community 1.3.1 to apply `original/schema.hcl`,
then psql to apply `original/rls.sql`. The retained schema-only dumps compare
identically after removing only pg_dump's random restriction-token lines;
`measured/catalog-comparison.json` records that comparison. `handover-plan.txt`
and `both-roles-plan.json` record Ptah's empty plans for the original state and
for a database with both application roles' grants.

`application-tests.txt` is an excerpt from the full Deno 2.8.1 suite result:
327 tests and 274 steps passed. Its coverage rows use branch, function, and line
columns, in that order. The test run includes the new wrapper and RLS-drift tests.
The later tasks commit changes only production configuration and documentation.

The exact shared workflow shell was also executed with `app_role=tasks-role`
against a disposable PostgreSQL 16 database. `workflow-noop.txt` records its
second run. `workflow-drop-guard.txt` records the expected nonzero refusal after
adding a table containing a row; an independent query confirmed that the row
remained. The release installer was checked with both incorrect and correct
archive checksums. The shared repository's `mage ci:fix && mage ci:check` passed,
including its 100% package coverage gates. These checks do not claim a live GCP
deployment or an upstream CI run.

## Recording

The article replay records stdout and stderr separately. Text files have a
final newline appended when the command omitted it. Earlier integration logs
remove terminal color escapes; the application-test file retains only the final
result and relevant coverage rows. Catalog tables and dumps trim trailing
whitespace and final blank lines for storage; their original hashes are retained
in `verified.json`. The catalog equality check ran before that normalization. No
production credentials or live database data are included.

`verified.json` records versions, source revisions, PR status at preparation,
and SHA-256 hashes of every supporting file other than itself. The article's
code blocks are checked against these files by the blog's example gate.
