Skip to content

doctor, diff and rehearse

Break it here. Not in production.

Terminal window
kling db tenant-check crm-1

Output

kling db tenant-check: crm-1 (database appdb, role app, column tenant_id, setting app.tenant_id)
tenants tested: 3 (-max 5)
FAIL public.accounts (RLS on, 1 policy)
fail no tenant (setting unset): SELECT sees 4 row(s) with no tenant set
fail no tenant (setting unset): INSERT of a row for another tenant passed row level security; only a constraint stopped it (23505)
fail no tenant (setting unset): UPDATE moving a row to another tenant succeeded (1 row(s), rolled back)
fail no tenant (setting unset): UPDATE of rows with no tenant set succeeded (4 row(s), rolled back)
why: policy "tenant_isolation" (permissive, ALL): fail-open in USING: <tenant setting> IS NULL is true when the setting is missing, so with no tenant set every row passes
fix: make the policy fail closed: current_setting('<var>') without missing_ok (errors when unset), or compare only tenant_id = current_setting(...) with no IS NULL / '' / COALESCE escape
PASS public.contacts (RLS on, 1 policy)
summary: 2 table(s), 1 not passing; 4 failed check(s), 0 error(s), 2 skipped

It exits with 1 if there are leaks. Writes are always rolled back.

Terminal window
kling db doctor t1 # rules DB001-DB055
kling db doctor -url 'postgres://…' # a Postgres you already have, over verified TLS
Terminal window
kling db diff t1 t2

Schema, functions, grants, and rows added, deleted or changed by primary key. Only salted fingerprints reach the host: not a single value leaves the database.

Terminal window
kling db rehearse pg -migrations migrations/

Applies each .sql on a throwaway copy, as the application role, and measures time, size and strong locks. If a file fails, it exits with 1.

Terminal window
kling db snapshot t1 antes
kling db undo t1 antes