Skip to main content

ExternalDatabaseConfig

Struct ExternalDatabaseConfig 

Source
pub struct ExternalDatabaseConfig {
Show 17 fields pub kind: String, pub url_env: String, pub read_url_env: Option<String>, pub compute: Option<String>, pub database: Option<String>, pub user: Option<String>, pub password_env: Option<String>, pub pool_max: Option<u32>, pub read_only: bool, pub allow_preview: bool, pub connect_timeout_secs: Option<u64>, pub image: Option<String>, pub volume_size_mib: Option<u32>, pub startup_grace_secs: Option<u32>, pub tenant: TenantIsolation, pub tenant_scope: TenantScope, pub rls_session: bool,
}
Expand description

One external SQL database for the handler sql binding. Its source is one of two mutually-exclusive forms:

  • url_env — a bring-your-own database: the connection URL is a secret, named indirectly by an env var (never written in the config file).
  • compute — a database boatramp runs as a compute workload: boatramp derives the connection from the workload’s live endpoint (host:port) plus the database/user/password_env here, so there is no URL to hand-map and it follows the workload across restarts (PLAN-managed-compute-sql).

Fields§

§kind: String

Engine: postgres (aliases postgresql/pg) or mysql (alias mariadb).

§url_env: String

Name of the env var holding the connection URL (e.g. postgres://user:pw@host/db). Required unless compute is set.

§read_url_env: Option<String>

Optional env var holding a read-replica connection URL. When set, open-read-only transactions route there; writes stay on url_env.

§compute: Option<String>

The name of a compute workload (a Postgres/MySQL server boatramp runs) to source this database from, instead of url_env. boatramp resolves the workload’s live endpoint and builds the connection. Mutually exclusive with url_env.

§database: Option<String>

The database name inside the compute-backed server (non-secret).

§user: Option<String>

The connecting user for the compute-backed server (non-secret).

§password_env: Option<String>

Env var holding the password for user on the compute-backed server. Omit to let boatramp fully manage the credential (PLAN-managed-compute-sql Phase 2): it generates a strong password once, seals it with the [secrets] envelope, injects it into the DB workload’s server-init env at launch, and connects the handler with it — the operator sets no DB secret at all. Set it only to bring your own password for the compute-backed server.

§pool_max: Option<u32>

Maximum pooled connections (default 8).

§read_only: bool

Open every transaction READ ONLY (the engine rejects writes) — for a database functions should only read.

§allow_preview: bool

Permit preview deployments to reach this database. Default false: a preview is refused, so it can never touch the operator’s live external DB.

§connect_timeout_secs: Option<u64>

Connection/acquire timeout in seconds (default 10).

§image: Option<String>

The stock OCI image for a managed co-located database (compute set, no password_env). When omitted, boatramp auto-registers the workload from the engine’s default image (pgvector/pgvector:pg16 for postgres, mysql:8.0 for mysql). Ignored for a bring-your-own (url_env) database.

§volume_size_mib: Option<u32>

The persistent data-volume size in MiB for a managed co-located database (default 10240 = 10 GiB). Ignored for a bring-your-own database.

§startup_grace_secs: Option<u32>

Startup grace (seconds) for a managed co-located database: how long a freshly launched server has to finish its first initdb before the reconcile loop treats a still-unhealthy replica as a broken launch to stop + relaunch. When set it overrides the engine default the synthesizer picks (Postgres 60, MySQL 120). Omit to use that default. Ignored for a bring-your-own database.

§tenant: TenantIsolation

Isolation mechanism for a compute-backed managed database (2×2 axis 1). single (default) — a dedicated database server (its own container) per tenant; sharedone server hosting a permission-separated database + role per tenant. Ignored for a bring-your-own (url_env) database.

§tenant_scope: TenantScope

Tenant grain for a compute-backed managed database (2×2 axis 2). project (default) — a tenant is a project; site — a tenant is a site. A tenant may hold several databases (one per binding that names it); it gets one login role and sealed credential per (tenant, server), granted on all its own databases and none of another tenant’s. The reserved default project uses the plain configured name, so a single-tenant install is just one ordinary database.

§rls_session: bool

Opt-in (default false): inject the request’s boatramp.project / boatramp.site into the SQL session at each transaction start (Postgres set_config GUC, MySQL session var), so hand-written native RLS policies can key on them per-request. The GraphQL data connector’s row-level policy is claim-sourced and needs nothing here; this is for hand-rolled RLS on the plain sql.open path (Postgres — the engine with native row-level security).

§Trust model — read before relying on this for isolation

rls_session provides the request’s tenant to the SQL session for an app’s RLS to key on. It is not a general hostile-guest boundary:

  • The reserved keys (boatramp.* / @boatramp_*) are protected from guest override — a handler statement that tries to set_config('boatramp.…', …) / SET boatramp.… / SET @boatramp_… (or RESET/DISCARD them) is refused, so a guest cannot spoof its injected tenant.
  • But the real tenant-isolation boundary is the per-tenant database + role (tenant = single / shared), which a compromised handler cannot cross regardless of what it does in-session. rls_session is a convenience for app-authored RLS within a tenant’s own database, layered on top of that boundary — not a substitute for it.
  • For untrusted data, prefer claim-sourced enforcement (the GraphQL data connector’s row-level policy), which derives the tenant from the verified request, not from anything the handler’s SQL can influence.

Implementations§

Source§

impl ExternalDatabaseConfig

Source

pub fn validate(&self, name: &str) -> Result<(), String>

Validate the source is well-formed: exactly one of url_env / compute, and a compute-backed database has the connection details boatramp can’t infer (database + user). password_env is optional — omit it to let boatramp manage the credential (Phase 2). name is the binding name, for the error message.

Source

pub fn is_managed_credential(&self) -> bool

Whether this compute-backed database uses a boatramp-managed credential (Phase 2): compute is set and no password_env was supplied.

Trait Implementations§

Source§

impl Clone for ExternalDatabaseConfig

Source§

fn clone(&self) -> ExternalDatabaseConfig

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ExternalDatabaseConfig

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for ExternalDatabaseConfig

Source§

fn default() -> ExternalDatabaseConfig

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for ExternalDatabaseConfig

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more