Adopt a live database
llms.txtlists every page for an agent
For a team whose database already exists: read it into declarations and a baseline migration, then change it only through migrations.
Works
yodel init --from <env>reads the live database intosrc/and plans it back to no change before it writes anything- A baseline migration recorded as applied, with none of its statements run
- Access adopted with the tables when the environment manages it: policies and grants, and on ClickHouse users and roles
yodel init --baselinefor another environment that holds the same schema
Differs
By database
- A project owns ClickHouse databases (
yodel create <dir> --clickhouse --database <name>). - A rebuild keeps the old table until
yodel cleanupdrops it, and lint flags mutations and rebuilds (ch-mutation,ch-rebuild).
- A project owns Postgres schemas (
yodel create <dir> --postgres --schema <name>). - Roles stay the environment's: the schema declares the policies and grants that name them.
By forge
- The writer's secrets are secrets of a GitHub environment limited to
main. - The plan comment and the drift issue use the job's own token.
- The writer's variables are protected and scoped to the environment; the readers' are not protected.
- The plan comment and the drift issue need
GITLAB_TOKEN, and each drift watch runs from a pipeline schedule you create.
- Secrets belong to the repository, with no environments, so limit who can push branches.
- Jobs need a runner with the
dockerlabel, and a job gets no OIDC token for cloud roles.
First step
YODEL_CREDENTIALS=writer npx yodel init --from <env> --forceProof
Each claim runs what this room relies on against a real server, once plain (it passes) and once with the behaviour broken (the claim catches it). Claims status lists every claim.
| Claim | What it says | Plain, broken |
|---|---|---|
adopt | yodel init --from adopts a live database without touching it, and yodel plan then shows no change; on Postgres its policies, row-level security and grants too, on ClickHouse its dictionaries, functions, roles, users, row policies and grants; yodel init --baseline records the baseline, behind the gate, in a second environment that holds the same schema, and refuses one that differs | ClickHouse: pass, caughtPostgres: pass, caught |
