feat: current state
validate / macos-arm64 (push) Canceled after 0s
validate / windows-x86_64 (push) Canceled after 0s

This commit is contained in:
Louis Frei
2026-08-13 20:18:30 +02:00
parent 42fc9ee2dc
commit 8dda5dcf23
42 changed files with 5155 additions and 82 deletions
+26
View File
@@ -0,0 +1,26 @@
# Operations
## Prerequisites
Install Azure CLI and authenticate to the desired tenant before launching the
TUI. The application reads the tenant from `az account show`, filters
subscriptions to that tenant and to the `Enabled` state, and explicitly passes
each subscription to Azure CLI. It never runs `az account set`.
Network routing, DNS, private-endpoint connectivity and firewall access remain
environmental prerequisites. A discovered server may still reject a PostgreSQL
connection.
## Profiles
Profiles live in the platform application configuration directory as
`profiles.json`. The file contains no password. On macOS and Windows the TUI
can reference a system-keychain secret; otherwise a password is session-only.
An unsupported future profile-file format is rejected without overwriting it.
## Dependency lock
`Cargo.lock` is part of the source of truth. Use locked Cargo commands. If the
manifest changes, regenerate the lockfile through the controlled maintainer
dependency-resolution process before running CI or release jobs. CI does not
repair or regenerate a lockfile.
+22
View File
@@ -0,0 +1,22 @@
# Release process
The release pipeline publishes only Gitea release assets for macOS ARM64 and
Windows x86_64. Binaries are not signed or notarized in this release stage.
## Required repository configuration
Variables:
- `MACOS_ARM64_RUNNER_LABEL` — label for a native `aarch64-apple-darwin` host.
- `WINDOWS_X86_64_RUNNER_LABEL` — label for a native `x86_64-pc-windows-msvc` host.
- `GITEA_API_URL` — base REST endpoint ending with `/api/v1`.
- `GITEA_REPOSITORY` — `owner/repository`.
Secret:
- `GITEA_RELEASE_TOKEN` — least-privilege token for release creation/editing
and asset upload.
Tags must equal the Cargo package version or `v` plus that version. Both native
archives and both `.sha256` files must exist before publication. Existing assets
are never replaced; an already published incomplete release fails safely.
+29
View File
@@ -0,0 +1,29 @@
# Security model
Azure CLI discovers management-plane resources only. It does **not** grant
PostgreSQL data-plane access. PostgreSQL connections use a separate username
and password and must use certificate and hostname validated TLS.
## Secrets
- Connection profiles store metadata and an optional system-keychain reference;
they never store a password.
- A missing or unavailable keychain requires password entry for the current
session. There is no clear-text fallback file or environment-variable store.
- Existing PostgreSQL passwords cannot be recovered. Only a newly created or
reset password can be offered once for copying.
- The one-time copy action consumes the application-held credential regardless
of whether the platform clipboard write succeeds. Clipboard history and other
applications are outside the application's control.
## SQL and administration
The SQL workspace intentionally sends PostgreSQL SQL without an allowlist.
The connected PostgreSQL role is the authorization boundary. Guided inserts use
parameters and guided table deletion requires an exact qualified-name
confirmation without `CASCADE`.
PostgreSQL requires a SQL password literal for role-password DDL. The role
service therefore owns a narrow, zeroizing literal renderer used only for role
creation and password reset. The application cannot control server-side audit
logging or driver-internal transport buffers.