Skip to content

feat: centralize PostgreSQL on glyph - #359

Merged
stackptr merged 6 commits into
mainfrom
feat/centralize-postgresql
Mar 11, 2026
Merged

stackptr merged 6 commits into
mainfrom
feat/centralize-postgresql

Conversation

@stackptr

@stackptr stackptr commented Mar 11, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Move PostgreSQL from spore to glyph (i7-13700K, NVMe, ZFS) as the central database host
  • Switch atticd from SQLite to PostgreSQL, fixing connection pool timeouts under concurrent CI pushes
  • Add databaseURL and localDatabase options to rc.web.auth module so pocket-id can connect to a remote database
  • Configure pocket-id on spore to connect to glyph's PostgreSQL via Tailscale
  • Disable PostgreSQL on spore, move database backups to glyph

Migration steps

Before deploying, migrate the pocketid database from spore to glyph:

  1. Deploy glyph first to create the PostgreSQL instance and empty databases:

    nixos-rebuild switch --flake .#glyph
  2. Dump pocketid from spore:

    ssh spore sudo -u postgres pg_dump pocketid > pocketid.sql
  3. Restore on glyph:

    scp pocketid.sql glyph:
    ssh glyph sudo -u postgres psql pocketid < pocketid.sql
  4. Migrate atticd data from SQLite to PostgreSQL on glyph:

    ssh glyph
    # Stop atticd to prevent writes
    sudo systemctl stop atticd
    # Dump SQLite
    sqlite3 /var/lib/atticd/server.db .dump > atticd-sqlite.sql
    # The SQLite dump won't import directly into PG — use pgloader or
    # just start fresh (atticd will recreate its schema). Existing
    # cached NARs in /var/lib/atticd/storage/ are retained; only the
    # metadata DB is lost, so a fresh CI push will repopulate it.
  5. Deploy spore to disable local PostgreSQL and point pocket-id at glyph:

    nixos-rebuild switch --flake .#spore
  6. Verify pocket-id can reach glyph's database:

    ssh spore psql -h glyph.rove-duck.ts.net -U pocketid -d pocketid -c '\dt'

Test plan

  • Deploy glyph, verify PostgreSQL starts and databases are created
  • Migrate pocketid data from spore
  • Deploy spore, verify pocket-id connects to glyph
  • Verify id.zx.dev login works end-to-end
  • Verify atticd starts and cache.zx.dev is functional
  • Verify CI push to Attic works without connection pool errors

🤖 Generated with Claude Code

stackptr and others added 6 commits March 10, 2026 21:12
Move PostgreSQL from spore to glyph so all databases are on the host
with the best hardware (i7-13700K, NVMe, ZFS). This also fixes the
atticd SQLite connection pool timeout under concurrent CI pushes by
switching to PostgreSQL.

- Add PostgreSQL 16 on glyph with atticd and pocketid databases
- Switch atticd from SQLite to PostgreSQL
- Add databaseURL and localDatabase options to rc.web.auth module
- Configure pocket-id on spore to connect to glyph via Tailscale
- Disable PostgreSQL on spore
- Move database backups from spore to glyph

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
atticd uses DynamicUser so the atticd user doesn't exist during
activation when agenix decrypts secrets. Default to root:root —
systemd reads the EnvironmentFile as root before dropping privileges.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The signing keypair was regenerated when the cache was recreated on
the new PostgreSQL backend.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The atticd NixOS module already detects local PostgreSQL from the
database URL (checks for /run/postgresql) and adds the systemd
after/requires dependencies automatically.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
PostgreSQL and database backups have moved to glyph. These files
were left as stubs and are no longer needed.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@stackptr
stackptr enabled auto-merge (squash) March 11, 2026 05:19
@stackptr
stackptr merged commit 7e6db42 into main Mar 11, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant