feat: centralize PostgreSQL on glyph - #359
Merged
Merged
Conversation
Move PostgreSQL from spore to glyph so all databases are on the host with the best hardware (i7-13700K, NVMe, ZFS). This also fixes the atticd SQLite connection pool timeout under concurrent CI pushes by switching to PostgreSQL. - Add PostgreSQL 16 on glyph with atticd and pocketid databases - Switch atticd from SQLite to PostgreSQL - Add databaseURL and localDatabase options to rc.web.auth module - Configure pocket-id on spore to connect to glyph via Tailscale - Disable PostgreSQL on spore - Move database backups from spore to glyph Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
atticd uses DynamicUser so the atticd user doesn't exist during activation when agenix decrypts secrets. Default to root:root — systemd reads the EnvironmentFile as root before dropping privileges. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The signing keypair was regenerated when the cache was recreated on the new PostgreSQL backend. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The atticd NixOS module already detects local PostgreSQL from the database URL (checks for /run/postgresql) and adds the systemd after/requires dependencies automatically. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
PostgreSQL and database backups have moved to glyph. These files were left as stubs and are no longer needed. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
stackptr
enabled auto-merge (squash)
March 11, 2026 05:19
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
databaseURLandlocalDatabaseoptions torc.web.authmodule so pocket-id can connect to a remote databaseMigration steps
Before deploying, migrate the pocketid database from spore to glyph:
Deploy glyph first to create the PostgreSQL instance and empty databases:
nixos-rebuild switch --flake .#glyphDump pocketid from spore:
ssh spore sudo -u postgres pg_dump pocketid > pocketid.sqlRestore on glyph:
scp pocketid.sql glyph: ssh glyph sudo -u postgres psql pocketid < pocketid.sqlMigrate atticd data from SQLite to PostgreSQL on glyph:
Deploy spore to disable local PostgreSQL and point pocket-id at glyph:
nixos-rebuild switch --flake .#sporeVerify pocket-id can reach glyph's database:
ssh spore psql -h glyph.rove-duck.ts.net -U pocketid -d pocketid -c '\dt'Test plan
🤖 Generated with Claude Code