feat: current state
This commit is contained in:
@@ -0,0 +1,26 @@
|
||||
# Operations
|
||||
|
||||
## Prerequisites
|
||||
|
||||
Install Azure CLI and authenticate to the desired tenant before launching the
|
||||
TUI. The application reads the tenant from `az account show`, filters
|
||||
subscriptions to that tenant and to the `Enabled` state, and explicitly passes
|
||||
each subscription to Azure CLI. It never runs `az account set`.
|
||||
|
||||
Network routing, DNS, private-endpoint connectivity and firewall access remain
|
||||
environmental prerequisites. A discovered server may still reject a PostgreSQL
|
||||
connection.
|
||||
|
||||
## Profiles
|
||||
|
||||
Profiles live in the platform application configuration directory as
|
||||
`profiles.json`. The file contains no password. On macOS and Windows the TUI
|
||||
can reference a system-keychain secret; otherwise a password is session-only.
|
||||
An unsupported future profile-file format is rejected without overwriting it.
|
||||
|
||||
## Dependency lock
|
||||
|
||||
`Cargo.lock` is part of the source of truth. Use locked Cargo commands. If the
|
||||
manifest changes, regenerate the lockfile through the controlled maintainer
|
||||
dependency-resolution process before running CI or release jobs. CI does not
|
||||
repair or regenerate a lockfile.
|
||||
@@ -0,0 +1,22 @@
|
||||
# Release process
|
||||
|
||||
The release pipeline publishes only Gitea release assets for macOS ARM64 and
|
||||
Windows x86_64. Binaries are not signed or notarized in this release stage.
|
||||
|
||||
## Required repository configuration
|
||||
|
||||
Variables:
|
||||
|
||||
- `MACOS_ARM64_RUNNER_LABEL` — label for a native `aarch64-apple-darwin` host.
|
||||
- `WINDOWS_X86_64_RUNNER_LABEL` — label for a native `x86_64-pc-windows-msvc` host.
|
||||
- `GITEA_API_URL` — base REST endpoint ending with `/api/v1`.
|
||||
- `GITEA_REPOSITORY` — `owner/repository`.
|
||||
|
||||
Secret:
|
||||
|
||||
- `GITEA_RELEASE_TOKEN` — least-privilege token for release creation/editing
|
||||
and asset upload.
|
||||
|
||||
Tags must equal the Cargo package version or `v` plus that version. Both native
|
||||
archives and both `.sha256` files must exist before publication. Existing assets
|
||||
are never replaced; an already published incomplete release fails safely.
|
||||
@@ -0,0 +1,29 @@
|
||||
# Security model
|
||||
|
||||
Azure CLI discovers management-plane resources only. It does **not** grant
|
||||
PostgreSQL data-plane access. PostgreSQL connections use a separate username
|
||||
and password and must use certificate and hostname validated TLS.
|
||||
|
||||
## Secrets
|
||||
|
||||
- Connection profiles store metadata and an optional system-keychain reference;
|
||||
they never store a password.
|
||||
- A missing or unavailable keychain requires password entry for the current
|
||||
session. There is no clear-text fallback file or environment-variable store.
|
||||
- Existing PostgreSQL passwords cannot be recovered. Only a newly created or
|
||||
reset password can be offered once for copying.
|
||||
- The one-time copy action consumes the application-held credential regardless
|
||||
of whether the platform clipboard write succeeds. Clipboard history and other
|
||||
applications are outside the application's control.
|
||||
|
||||
## SQL and administration
|
||||
|
||||
The SQL workspace intentionally sends PostgreSQL SQL without an allowlist.
|
||||
The connected PostgreSQL role is the authorization boundary. Guided inserts use
|
||||
parameters and guided table deletion requires an exact qualified-name
|
||||
confirmation without `CASCADE`.
|
||||
|
||||
PostgreSQL requires a SQL password literal for role-password DDL. The role
|
||||
service therefore owns a narrow, zeroizing literal renderer used only for role
|
||||
creation and password reset. The application cannot control server-side audit
|
||||
logging or driver-internal transport buffers.
|
||||
Reference in New Issue
Block a user