Flagsmith / Flagsmith/flagsmith-sql-flag-engine

CI: move parity job from trial account to Flagsmith prod Snowflake with a scoped role

Offen
#2 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Python
Sterne
1
Forks
0
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

The engine-parity CI job currently runs against my personal Snowflake trial account under `ACCOUNTADMIN`. The current trial account is tied to a personal email and expires; production account with billing is the durable home.

## What needs to happen

1. **Provision a CI database + schema in the Flagsmith prod Snowflake account.** Suggested layout: a dedicated `FS_CI` database, scratch schema `PUBLIC`. The parity tests already create per-run transient `IDENTITIES_PARITY_` / `TRAITS_PARITY_` tables there and drop them on teardown, so concurrent runs don't collide.
2. **Create a least-privilege role for CI**, e.g. `FS_SQL_ENGINE_CI_RW`. Required grants:

```sql
USE ROLE SECURITYADMIN;
CREATE ROLE FS_SQL_ENGINE_CI_RW;

USE ROLE SYSADMIN;
GRANT USAGE ON DATABASE FS_CI TO ROLE FS_SQL_ENGINE_CI_RW;
GRANT USAGE ON SCHEMA FS_CI.PUBLIC TO ROLE FS_SQL_ENGINE_CI_RW;
GRANT CREATE TABLE ON SCHEMA FS_CI.PUBLIC TO ROLE FS_SQL_ENGINE_CI_RW;
GRANT USAGE ON WAREHOUSE FS_CI_WH TO ROLE FS_SQL_ENGINE_CI_RW;

GRANT ROLE FS_SQL_ENGINE_CI_RW TO USER ;
ALTER USER SET DEFAULT_ROLE = FS_SQL_ENGINE_CI_RW;
```

No grants beyond that — the parity tests do `CREATE TRANSIENT TABLE`, `INSERT`, `SELECT`, `DROP TABLE` and that's it.
3. **Provision a service user** for CI (e.g. `flagsmith_sql_engine_ci`) with key-pair auth. Generate the keypair, register the public key on the user, capture the private key for GH secrets. Disable password auth on the user.
4. **Add a resource monitor** on `FS_CI_WH` capping monthly credit spend (suggest \$5-10 / month — current usage is ~\$0.05 per CI run, ~\$2-5 / month at heavy PR volume).
5. **Update GH secrets** in this repo:
- `SNOWFLAKE_ACCOUNT` → prod account locator
- `SNOWFLAKE_USER` → `flagsmith_sql_engine_ci`
- `SNOWFLAKE_ROLE` → `FS_SQL_ENGINE_CI_RW`
- `SNOWFLAKE_WAREHOUSE` → `FS_CI_WH`
- `SNOWFLAKE_DATABASE` → `FS_CI`
- `SNOWFLAKE_SCHEMA` → `PUBLIC`
- `SNOWFLAKE_PRIVATE_KEY` → contents of the new key file

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.