/goal /ultracode-workflows [RBAC-7] DESIGN Forgejo-identity → per-app postgres role / RLS propagation #33
Labels
No labels
bug
discussion
duplicate
enhancement
goal
help wanted
horizon:backlog
horizon:governance
horizon:mvp
invalid
operator-decision
question
roadmap
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Depends on
Reference
open-platform/mitosis#33
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Track/Wave:
RBAC-7· Wave G2 · Size MRepos:
mitosis-visionDepends on: RBAC-1
Why
The postgres leg of the 'propagate everywhere' vision has NO design doc — CNPG provisions one flat credential with no link to Forgejo teams. It needs a design pass before it can be a buildable issue.
Scope
A design doc: does the client's one app even need per-team postgres roles given forwardAuth already gates the whole app at the edge? If sub-app RLS is needed, define the Forgejo-team→postgres-role/RLS mapping, who provisions it, and interaction with better-auth's user table. DESIGN ONLY — include an explicit defer-or-build recommendation for a one-app client.
Acceptance
A reviewed/merged design doc a future agent could implement without further decisions, including an explicit recommendation on whether it is needed for the client's actual app or deferred.
Notes
Design-first — natural fan-out target.
Part of the First Client Deploy → Governance roadmap. The owning agent may recurse into its own subagent team (ultracode workflow) if the task warrants. Honor the seam-serialization: land on a shared seam by rebase, and don't start a seam position until the prior one has merged.