doctor, diff and rehearse
Break it here. Not in production.
Does each tenant see only its own data?
Section titled “Does each tenant see only its own data?”kling db tenant-check crm-1Output
kling db tenant-check: crm-1 (database appdb, role app, column tenant_id, setting app.tenant_id) tenants tested: 3 (-max 5) FAIL public.accounts (RLS on, 1 policy) fail no tenant (setting unset): SELECT sees 4 row(s) with no tenant set fail no tenant (setting unset): INSERT of a row for another tenant passed row level security; only a constraint stopped it (23505) fail no tenant (setting unset): UPDATE moving a row to another tenant succeeded (1 row(s), rolled back) fail no tenant (setting unset): UPDATE of rows with no tenant set succeeded (4 row(s), rolled back) why: policy "tenant_isolation" (permissive, ALL): fail-open in USING: <tenant setting> IS NULL is true when the setting is missing, so with no tenant set every row passes fix: make the policy fail closed: current_setting('<var>') without missing_ok (errors when unset), or compare only tenant_id = current_setting(...) with no IS NULL / '' / COALESCE escape PASS public.contacts (RLS on, 1 policy)summary: 2 table(s), 1 not passing; 4 failed check(s), 0 error(s), 2 skippedIt exits with 1 if there are leaks. Writes are always rolled back.
doctor
Section titled “doctor”kling db doctor t1 # rules DB001-DB055kling db doctor -url 'postgres://…' # a Postgres you already have, over verified TLSkling db diff t1 t2Schema, functions, grants, and rows added, deleted or changed by primary key. Only salted fingerprints reach the host: not a single value leaves the database.
rehearse
Section titled “rehearse”kling db rehearse pg -migrations migrations/Applies each .sql on a throwaway copy, as the application role, and measures time, size and strong locks. If a file fails, it exits with 1.
snapshot and undo
Section titled “snapshot and undo”kling db snapshot t1 anteskling db undo t1 antesIn the repo: docs/db.md · ext/db/internal/doctor