/goal /ultracode-workflows [RBAC-7] DESIGN Forgejo-identity → per-app postgres role / RLS propagation #33

Closed
opened 2026-07-01 02:03:46 +00:00 by plat · 0 comments
Owner

Track/Wave: RBAC-7 · Wave G2 · Size M
Repos: mitosis-vision
Depends on: RBAC-1

Why

The postgres leg of the 'propagate everywhere' vision has NO design doc — CNPG provisions one flat credential with no link to Forgejo teams. It needs a design pass before it can be a buildable issue.

Scope

A design doc: does the client's one app even need per-team postgres roles given forwardAuth already gates the whole app at the edge? If sub-app RLS is needed, define the Forgejo-team→postgres-role/RLS mapping, who provisions it, and interaction with better-auth's user table. DESIGN ONLY — include an explicit defer-or-build recommendation for a one-app client.

Acceptance

A reviewed/merged design doc a future agent could implement without further decisions, including an explicit recommendation on whether it is needed for the client's actual app or deferred.

Notes

Design-first — natural fan-out target.


Part of the First Client Deploy → Governance roadmap. The owning agent may recurse into its own subagent team (ultracode workflow) if the task warrants. Honor the seam-serialization: land on a shared seam by rebase, and don't start a seam position until the prior one has merged.

**Track/Wave:** `RBAC-7` · Wave **G2** · Size **M** **Repos:** `mitosis-vision` **Depends on:** RBAC-1 ## Why The postgres leg of the 'propagate everywhere' vision has NO design doc — CNPG provisions one flat credential with no link to Forgejo teams. It needs a design pass before it can be a buildable issue. ## Scope A design doc: does the client's one app even need per-team postgres roles given forwardAuth already gates the whole app at the edge? If sub-app RLS is needed, define the Forgejo-team→postgres-role/RLS mapping, who provisions it, and interaction with better-auth's user table. DESIGN ONLY — include an explicit defer-or-build recommendation for a one-app client. ## Acceptance A reviewed/merged design doc a future agent could implement without further decisions, including an explicit recommendation on whether it is needed for the client's actual app or deferred. ## Notes **Design-first — natural fan-out target.** --- *Part of the **First Client Deploy → Governance** roadmap. The owning agent may recurse into its own subagent team (ultracode workflow) if the task warrants. Honor the seam-serialization: land on a shared seam by rebase, and don't start a seam position until the prior one has merged.*
plat closed this issue 2026-07-01 17:05:48 +00:00
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
open-platform/mitosis#33
No description provided.