[E00-S03-T01] PostgreSQL 18.6 container #390
No Reviewers
Labels
Clear labels
agent/analyst-drafted
agent/analyst-drafted
needs/human-decision
needs/human-decision
needs/security-review
needs/security-review
tier/t0
tier/t1
tier/t2
tier/t3
kind
bug
kind
bug
kind
epic
kind
epic
kind
initiative
EPPP programme initiative
kind
story
kind
story
kind
task
EPPP engineering card/task decomposed from a story
kind
toil
kind
toil
loop
1
loop
1
loop
2
loop
2
loop
3
loop
3
risk
agent-full
risk
agent-full
risk
human-gated
risk
human-gated
risk
human-only
risk
human-only
size
l
size
l
size
m
size
m
size
s
size
s
status
blocked
status
blocked
status
done
Workflow: Done
status
in-progress
status
in-progress
status
proposed
status
proposed
status
ready
status
ready
status
review
status
review
stream
checkout
stream
checkout
stream
onboarding
stream
onboarding
stream
platform
stream
platform
trivial — implementer only, auto-merge
standard — implementer + reviewer + tester
complex — security if triggered, human merge
critical — full chain + security, human merge
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Fabrika/PersonalBlog#390
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What changed
Implements [E00-S03-T01] PostgreSQL 18.6 container (#176): the workspace database container is pinned to PostgreSQL 18.6 and the criterion is locked in by tests and enforced in CI.
compose.yaml—db.imagepinned topostgres:18.6-bookworm(exact 18.6 minor on the same Debian bookworm flavor as before — no Alpine drift, Technology-Stack §5.2/§5.4/§6.2, golden tuple §7). The floating major tag (postgres:18-bookworm) would not guarantee the container exposes the expected version; the exact-minor pin makes the database container reproducible. Rollback: revertimagetopostgres:18-bookworm.tests/compose-config.test.mjs— the pinned image is asserted statically (assertDbServicerequirespostgres:18.6-bookworm), the parser probe and the db-mutation fixture are updated, and a mutation probe proves non-vacuousness: reverting to the floatingpostgres:18-bookwormtag fails the criterion.tests/compose-config.test.mjs— new Docker-gated real-stack probe "the database container exposes the expected PostgreSQL version (18.6)": starts the stack and runsSHOW server_versionagainst the runningdbcontainer, asserting the exposed version is 18.6 — the issue's test plan ("start the container and confirm PostgreSQL 18.6") executed end to end. Skips cleanly where no Docker daemon exists (same pattern as the T01..T08 real-stack probes)..gitea/workflows/ci.yml— newcompose-configjob runsnode --test tests/compose-config.test.mjson every PR, so the pinned-version criterion gates merges (the Docker-gated probes run where a daemon exists and skip cleanly otherwise).Explicitly out of scope per the brief, not touched: pg/Kysely isolation (E00-S03-T02), migration ledger (E00-S03-T03), advisory lock (E00-S03-T04).
Criterion → test table
PostgreSQL 18.6 container is used as the databasetests/compose-config.test.mjs— "the database service is defined so `docker compose up -d` starts the database" (static:assertDbServicerequiresdb.image === 'postgres:18.6-bookworm'); "reverting the db image to a floating major tag fails the PostgreSQL 18.6 criterion (mutation probe)" proves non-vacuous —postgres:18-bookworm/postgres:18would not satisfy the exact-minor pinthe container exposes the expected PostgreSQL versiontests/compose-config.test.mjs— "the database container exposes the expected PostgreSQL version (18.6)" (Docker-gated real-stack probe):docker compose up -dthe committed stack,docker compose exec db psql … -c 'SHOW server_version;', assert the running server reports18.6— verifies the exposed version end to end, not just the declared tagthe guarantee is enforced in CI.gitea/workflows/ci.yml—compose-configjob runsnode --test tests/compose-config.test.mjson every PR (static assertions gate merges; docker-gated probes skip cleanly without a daemon)Test plan executed
node --test tests/compose-config.test.mjs→ 18 pass / 0 fail / 4 skip (the 4 skips are the Docker-gated real-stack probes — no Docker daemon in this sandbox, matching the CI runner).node --test tests/build-targets.test.mjs tests/secrets-not-embedded.test.mjs→ pass (fixtures updated to the pinned tag; no behavior change).node --test "tests/**/*.test.mjs") → 102 pass / 12 fail / 9 skip; the 12 failures are byte-identical to cleanmain(frozen-install / root-commands / strict-tsconfig / node-engine / typescript-pin suites needpnpm install+ Node 24 — absent here: nonode_modules, Node 22.23.2) — zero new failures, +2 tests net (+1 pass, +1 Docker-gated skip) vs main's 101/12/8.Risks / notes
-bookworm); only the minor version is pinned, so the runtime behavior of the existing stack (health gate, volume persistence, app startup) is unaffected.SHOW server_versionmatches/^18\.6\b/, which matches both the bare18.6and the PGDG build string (18.6 (Debian 18.6-1.pgdg120+1)) — no over-constraining on the distro suffix.compose-configsuite (not just the pinned-version tests), so the previously CI-ungated T02..T08 compose assertions now gate merges too.Refs #176