Files
praxis/db/pg_schema.sql
T
Praxis CI b0cb6280d7 feat(P01): TASK-01-04..07 Postgres DB foundation — migrate + schema + PgStore + tests
- db/pg_migrate.py: asyncpg migration runner with _pg_migrations tracking
  table, ordered .sql, transactional, 3x retry on connection failure (R-MT-02).
- db/pg_schema.sql + db/pg_migrations/0001_operator_tier.sql: 5 operator-tier
  tables (operators, issued_credentials, mastery_gate_events,
  cohort_aggregates, issuer_keys) using gen_random_uuid() (PG16 core, no
  extension). cohort_aggregates is a plain table, NOT partitioned (D-050).
- db/pg_store.py: PgStore class implementing the IssuerKeyStore protocol
  (init/get_active/get_public_key_row/set_superseded) plus operator CRUD,
  cohort aggregate read/write, credential methods, gate events.
  get_public_key_row queries by id (not status) → finds superseded keys
  (R-VC-MIG-01 verification fallback, D-051). No cross-DB FKs (D-031).
- tests/test_pg_store.py: 13 integration tests (skip if PRAXIS_PG_DSN unset).

---ci---
project: praxis
phase: 1
milestone: v0.4
status: execute
persona: data-engineer
task: 01-04,01-05,01-06,01-07
requirements:
  covered: [REQ-MT-01, REQ-NFR-MT-01, REQ-MT-02]
---/ci---
2026-08-04 00:47:14 +00:00

71 lines
2.8 KiB
SQL

-- Praxis v0.4 operator-tier Postgres schema (reference).
-- Applied in order by db/pg_migrate.py via db/pg_migrations/*.sql.
-- The canonical migration is 0001_operator_tier.sql; this file is the
-- human-readable reference (kept in sync). Uses gen_random_uuid() which
-- is in PG16 core (no extension needed — R-MT-05 verified).
--
-- Tables:
-- operators — operator accounts (argon2id password hash)
-- issued_credentials — VC issuance log (learner_ref is opaque, no FK)
-- mastery_gate_events — mastery gate audit log (REQ-NFR-MAST-02)
-- cohort_aggregates — k-anonymized cohort metrics (plain table, D-050)
-- issuer_keys — Ed25519 issuer key lifecycle (active/superseded)
--
-- No cross-DB FKs (D-031). learner_ref is an opaque string in Postgres.
CREATE TABLE IF NOT EXISTS operators (
id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
username TEXT UNIQUE NOT NULL,
password_hash TEXT NOT NULL,
display_name TEXT,
role TEXT NOT NULL DEFAULT 'operator',
is_active BOOLEAN NOT NULL DEFAULT TRUE,
created_at TIMESTAMPTZ NOT NULL DEFAULT now(),
last_login_at TIMESTAMPTZ
);
CREATE TABLE IF NOT EXISTS issued_credentials (
id UUID PRIMARY KEY,
operator_id UUID REFERENCES operators(id),
learner_ref TEXT NOT NULL,
vc_type TEXT,
payload_jsonb JSONB NOT NULL,
signature_b64 TEXT NOT NULL,
status TEXT NOT NULL DEFAULT 'active',
issued_at TIMESTAMPTZ NOT NULL DEFAULT now(),
revoked_at TIMESTAMPTZ
);
CREATE TABLE IF NOT EXISTS mastery_gate_events (
id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
learner_ref TEXT NOT NULL,
scenario_id TEXT,
path_id TEXT NOT NULL,
gate_outcome TEXT,
rubric_scores_jsonb JSONB,
recorded_at TIMESTAMPTZ NOT NULL DEFAULT now(),
source TEXT NOT NULL DEFAULT 'sync'
);
CREATE TABLE IF NOT EXISTS cohort_aggregates (
path TEXT NOT NULL,
metric TEXT NOT NULL,
window_start DATE NOT NULL,
window_end DATE NOT NULL,
value NUMERIC,
cell_count INTEGER NOT NULL DEFAULT 0,
cell_suppressed BOOLEAN NOT NULL DEFAULT FALSE,
updated_at TIMESTAMPTZ NOT NULL DEFAULT now(),
PRIMARY KEY (path, metric, window_start)
);
-- Plain table, NOT partitioned (D-050..D-053; add partitioning post-pilot).
CREATE INDEX IF NOT EXISTS cohort_aggregates_path_window_idx
ON cohort_aggregates (path, window_start);
CREATE TABLE IF NOT EXISTS issuer_keys (
id TEXT PRIMARY KEY,
public_key TEXT NOT NULL,
private_key_enc BYTEA,
status TEXT NOT NULL DEFAULT 'active',
created_at TIMESTAMPTZ NOT NULL DEFAULT now()
);