From e94086e1e0a9d68c26192f791a4b1660dcf0925f Mon Sep 17 00:00:00 2001 From: Bryan Frimin Date: Tue, 30 Sep 2025 16:47:34 +0200 Subject: [PATCH] Add database migration Signed-off-by: Bryan Frimin --- pkg/coredata/migrations/20250929T121248Z.sql | 47 ++++++++++++++++++++ 1 file changed, 47 insertions(+) create mode 100644 pkg/coredata/migrations/20250929T121248Z.sql diff --git a/pkg/coredata/migrations/20250929T121248Z.sql b/pkg/coredata/migrations/20250929T121248Z.sql new file mode 100644 index 000000000..458c72a48 --- /dev/null +++ b/pkg/coredata/migrations/20250929T121248Z.sql @@ -0,0 +1,47 @@ +CREATE EXTENSION IF NOT EXISTS citext; + +CREATE TYPE custom_domain_ssl_status AS ENUM ( + 'PENDING', + 'PROVISIONING', + 'ACTIVE', + 'RENEWING', + 'EXPIRED', + 'FAILED' +); + +CREATE TABLE custom_domains ( + id TEXT PRIMARY KEY, + tenant_id TEXT NOT NULL, + organization_id TEXT NOT NULL REFERENCES organizations(id) ON DELETE CASCADE, + domain CITEXT NOT NULL UNIQUE, + encrypted_ssl_certificate BYTEA, + encrypted_ssl_private_key BYTEA, + ssl_certificate_chain TEXT, + ssl_status custom_domain_ssl_status, + ssl_expires_at TIMESTAMP WITH TIME ZONE, + http_challenge_token TEXT, + http_challenge_key_auth TEXT, + http_challenge_url TEXT, + http_order_url TEXT, + is_active BOOLEAN NOT NULL, + created_at TIMESTAMP WITH TIME ZONE NOT NULL, + updated_at TIMESTAMP WITH TIME ZONE NOT NULL +); + +CREATE UNLOGGED TABLE certificate_cache ( + domain CITEXT PRIMARY KEY, + certificate_pem TEXT NOT NULL, + private_key_pem TEXT NOT NULL, + certificate_chain TEXT, + expires_at TIMESTAMP WITH TIME ZONE NOT NULL, + cached_at TIMESTAMP WITH TIME ZONE NOT NULL, + custom_domain_id TEXT REFERENCES custom_domains(id) ON DELETE CASCADE +); + +CREATE INDEX idx_custom_domains_domain ON custom_domains(domain) WHERE is_active = true; +CREATE INDEX idx_custom_domains_org ON custom_domains(organization_id); +CREATE INDEX idx_custom_domains_ssl_expires ON custom_domains(ssl_expires_at) + WHERE ssl_status = 'ACTIVE' AND is_active = true; +CREATE INDEX idx_custom_domains_http_challenge_token ON custom_domains(http_challenge_token) + WHERE http_challenge_token IS NOT NULL; +CREATE INDEX idx_certificate_cache_expires ON certificate_cache(expires_at);