Core deliverables: - Go module github.com/dtoro/oikos (Go 1.26.3) - cmd/oikos: single binary with role subcommands (migrate, seed, export) - 6 SQL migrations: ontology meta-schema, entity instances (UUID+slug, blast_radius recursive function), operations (signals/checks/approvals), cognition (classifications/executions/feedback/patterns/skills), policy, observability (TimescaleDB hypertables + CAGGs + retention) - Domain layer: entity, signal, execution, classification, pattern, skill, approval, check types + 11 sentinel errors + lifecycle state machines - DB layer: pgx pool, SQL splitter (handles 94436 and -- comments), migration runner, seed ingest (ontology+inventory+policy) with content-hash dedup - Config: env-based with defaults, secrets redaction - Observability: slog JSON logger with debug mode - Infrastructure: Makefile, docker-compose.yml, multi-stage Dockerfile (distroless, CGO_ENABLED=0) Verified end-to-end against timescale/timescaledb:2.17.2-pg16: - 6 migrations applied (65 SQL statements) - Seeds ingested: 6 lifecycles, 59 entity types, 46 relationship types, 111 entities, 144 relationships, 4 risk classes, 27 approval rules, 9 autonomy settings - Idempotent: second seed run is a no-op (content hash matches) Bugs fixed during implementation: - TimescaleDB CAGGs can't run in a transaction -> splitSQL() executes statements individually - Semicolons in -- comments treated as separators -> comment handling - YAML keys source/target didn't match code's source_type/target_type - yaml.Marshal produced YAML for JSONB columns -> json.Marshal
29 lines
1.1 KiB
SQL
29 lines
1.1 KiB
SQL
-- Migration 005: Policy (risk classes, approval rules, autonomy settings)
|
|
|
|
CREATE TABLE risk_classes (
|
|
name TEXT PRIMARY KEY,
|
|
description TEXT,
|
|
approval_required TEXT NOT NULL DEFAULT 'none',
|
|
autonomy_allowed BOOLEAN NOT NULL DEFAULT false
|
|
);
|
|
|
|
CREATE TABLE approval_rules (
|
|
id UUID PRIMARY KEY,
|
|
entity_type TEXT REFERENCES entity_types(name),
|
|
action TEXT NOT NULL,
|
|
risk_class TEXT NOT NULL REFERENCES risk_classes(name),
|
|
autonomy_level TEXT NOT NULL DEFAULT 'escalate' CHECK
|
|
(autonomy_level IN ('auto','escalate','never')),
|
|
scope_entity UUID REFERENCES entities(id),
|
|
version INTEGER NOT NULL DEFAULT 1,
|
|
updated_at TIMESTAMPTZ NOT NULL DEFAULT now(),
|
|
UNIQUE (entity_type, action, scope_entity)
|
|
);
|
|
|
|
CREATE TABLE autonomy_settings (
|
|
key TEXT PRIMARY KEY,
|
|
value TEXT NOT NULL,
|
|
version INTEGER NOT NULL DEFAULT 1,
|
|
updated_at TIMESTAMPTZ NOT NULL DEFAULT now()
|
|
);
|