--- # arrproxy schema, mirrored from the arrproxy repo migrations/0001_init.sql # (v0.1.0). arrproxy-api does NOT self-migrate, so the wave-1 migrate Job applies # this once per sync as the app user. Keep in sync with the repo on schema bumps. apiVersion: v1 kind: ConfigMap metadata: name: arrproxy-migrations namespace: arrstack annotations: argocd.argoproj.io/sync-wave: "0" data: 0001_init.sql: | -- arrproxy token store. Only token hashes are persisted; plaintext is shown -- once at mint time and never recoverable. CREATE TABLE IF NOT EXISTS tokens ( id TEXT PRIMARY KEY, subject TEXT NOT NULL, label TEXT NOT NULL DEFAULT '', token_hash TEXT NOT NULL UNIQUE, apps TEXT[] NOT NULL DEFAULT '{}', created_at TIMESTAMPTZ NOT NULL DEFAULT now(), expires_at TIMESTAMPTZ, disabled BOOLEAN NOT NULL DEFAULT false, last_used_at TIMESTAMPTZ ); CREATE INDEX IF NOT EXISTS tokens_subject_idx ON tokens (subject); CREATE INDEX IF NOT EXISTS tokens_token_hash_idx ON tokens (token_hash);