/** * Pg pool factory — feature-switched between connection-string auth and * Microsoft Entra (AAD) token auth for the bicep-deploy flow on AKS with * workload identity. Used by the CMS + facts pg.Pool paths. * * The duroxide orchestration store has its own Entra path * (`PostgresProvider.connectWithSchemaAndEntra`, available in * duroxide-node >= 0.1.25) which uses duroxide's native credential chain * in Rust rather than the JS `DefaultAzureCredential` used here; see * `duroxide-provider-factory.ts`. URL parsing is shared between both * paths via `parsePostgresUrl` / `resolveAadPostgresUser` below. * * @internal */ import type { PoolConfig } from "pg"; import { type TokenCredential } from "@azure/identity"; /** * Replace the cached credential with a custom one. Tests pass a stub * here; production code should never call this. * * @internal */ export declare function _setPgAadCredentialForTests(cred: TokenCredential | null): void; export interface PgPoolFactoryOptions { /** * Connection string. In MI mode this can be a passwordless URL like * `postgresql://@:5432/?sslmode=require`; the * password segment (if any) is ignored. */ connectionString: string; /** * Opt into AAD token auth. When `true` the returned config has a * `password` callback that mints AAD tokens via * `DefaultAzureCredential` instead of using the URL password. * * Defaults to `false` (legacy connection-string behaviour). */ useManagedIdentity?: boolean; /** * Override the Postgres role name (`user` field) when in MI mode. * Defaults to the URL's `username` component. Required when the URL * encodes the bicep-bootstrap admin login but the worker should * authenticate as the federated UAMI's display name. */ aadUser?: string; /** Forwarded to pg.Pool. Default 3 to match existing CMS / facts pools. */ max?: number; } /** * Parsed components of a `postgres://` / `postgresql://` connection * string in the shape both the pg.Pool factory and the duroxide * provider factory need. Centralizes the sslmode-stripping and * default-port/database behaviour so the two paths stay aligned. * * @internal */ export interface ParsedPgUrl { host: string; /** Defaults to 5432 when the URL omits a port. */ port: number; /** Defaults to `postgres` when the URL has no pathname. */ database: string; /** Decoded URL `user@` segment, or empty string when absent. */ urlUsername: string; /** True when sslmode is require/prefer/verify-ca/verify-full. */ needsSsl: boolean; /** Connection string with `sslmode` stripped from the query. */ sanitizedConnectionString: string; } /** * Parse a Postgres connection string into the parts both the pg.Pool * factory (for CMS/facts) and the duroxide provider factory need. * * @internal */ export declare function parsePostgresUrl(connectionString: string): ParsedPgUrl; /** * Resolve the Postgres role to use in managed-identity mode. Prefers * the caller-provided `aadUser` (typically the federated UAMI display * name), falling back to the URL's `user@` segment. * * Throws when neither is set so misconfigurations fail loudly at * startup rather than producing cryptic auth errors at first query. * * @internal */ export declare function resolveAadPostgresUser(parsed: ParsedPgUrl, aadUser?: string): string; /** * Build a `pg.PoolConfig` honouring the MI feature switch. * * Implementation note: pg accepts `password` as either `string` or a * function returning `string | Promise` and invokes it on every * new physical connection. `DefaultAzureCredential` returns a cached * token until ~5 min before expiry, so the factory does not need its * own token cache. * * @internal */ export declare function buildPgPoolConfig(opts: PgPoolFactoryOptions): PoolConfig; /** * Read the `PILOTSWARM_USE_MANAGED_IDENTITY` env flag. Convenience * helper so callers don't reimplement the truthy-flag parsing. * * @internal */ export declare function readManagedIdentityFlag(env: NodeJS.ProcessEnv | Record): boolean; //# sourceMappingURL=pg-pool-factory.d.ts.map