(c *gin.Context)
| 202 | // service-credentials mint uses it to fan a snapshot reload out to peer |
| 203 | // replicas after rotating a credential. |
| 204 | peerFanout PeerFanout |
| 205 | // ingressSuffix is the managed tenant DNS suffix (leading dot) joined onto |
| 206 | // the org ID to build connect.host in the service-credential response. It |
| 207 | // must match the TLS server_name the CP pins for managed tenants so the |
| 208 | // host handed back is the ingress the credential auths against. Empty ⇒ |
| 209 | // managedIngressSuffix() falls back to DefaultManagedIngressSuffix. |
| 210 | ingressSuffix string |
| 211 | } |
| 212 | |
| 213 | // warehouseStatusResponse is the public-facing view of warehouse state. |
| 214 | // Exposes lifecycle status and, when ready, connection details (without password). |
| 215 | type warehouseStatusResponse struct { |
| 216 | OrgID string `json:"org_id"` |
| 217 | State configstore.ManagedWarehouseProvisioningState `json:"state"` |
| 218 | StatusMessage string `json:"status_message"` |
| 219 | S3State configstore.ManagedWarehouseProvisioningState `json:"s3_state"` |
| 220 | MetadataStoreState configstore.ManagedWarehouseProvisioningState `json:"metadata_store_state"` |
| 221 | IdentityState configstore.ManagedWarehouseProvisioningState `json:"identity_state"` |
| 222 | SecretsState configstore.ManagedWarehouseProvisioningState `json:"secrets_state"` |
| 223 | ReadyAt *time.Time `json:"ready_at,omitempty"` |
| 224 | FailedAt *time.Time `json:"failed_at,omitempty"` |
| 225 | Connection *connectionDetails `json:"connection,omitempty"` |
| 226 | // Bucket is the authoritative per-org S3 bucket name the CP provisioned. |
| 227 | // Empty for external data stores or ducklings provisioned before CP-owned |
| 228 | // naming whose row hasn't been backfilled yet. |
| 229 | Bucket string `json:"bucket,omitempty"` |
| 230 | } |
| 231 | |
| 232 | // connectionDetails is returned in status (without password) and in provision/reset-password (with password). |
| 233 | type connectionDetails struct { |
| 234 | Host string `json:"host"` |
| 235 | Port int `json:"port"` |
| 236 | Database string `json:"database"` |
| 237 | Username string `json:"username"` |
| 238 | Password string `json:"password,omitempty"` |
| 239 | } |
| 240 | |
| 241 | type provisionRequest struct { |
| 242 | DatabaseName string `json:"database_name"` |
| 243 | // DefaultTeamID is a TRANSITIONAL alias for TeamID (the historical field |
| 244 | // name from when duckgres tracked a billing/default team). Treated |
| 245 | // exactly as team_id; remove once the PostHog backend sends team_id. |
| 246 | DefaultTeamID int64 `json:"default_team_id,omitempty"` |
| 247 | // TeamID is the org's first PostHog team — a JSON NUMBER, matching |
| 248 | // PostHog's integer Team.id (a quoted string is a 400 at decode time). |
| 249 | // REQUIRED when the provision creates a NEW org (400 otherwise — a |
| 250 | // warehouse cannot exist without a team; the row becomes the org's first |
| 251 | // duckgres_org_teams entry, no billing semantics attached). Optional on |
| 252 | // re-provision of an existing org: absent/0 leaves the stored teams |
| 253 | // untouched. SchemaName optionally overrides the conventional "team_<id>" |
| 254 | // warehouse schema for that first row; it requires a team id. |
| 255 | TeamID int64 `json:"team_id,omitempty"` |
| 256 | SchemaName string `json:"schema_name,omitempty"` |
| 257 | MetadataStore *provisionMetadataReq `json:"metadata_store,omitempty"` |
| 258 | DataStore *provisionDataStoreReq `json:"data_store,omitempty"` |
| 259 | DuckLake *provisionDuckLakeReq `json:"ducklake,omitempty"` |
| 260 | |
| 261 | // Trino is the opt-in flag for the shared Trino cell. Optional — when |
nothing calls this directly
no test coverage detected