- A Neki database with a ready branch.
- An application role for that branch. Use
pg_read_all_datafor read traffic and addpg_write_all_datawhen the application writes rows. These inherited data roles do not grantCREATEorALTER, so application credentials cannot change the schema. - A separate migration role, if you run schema changes against the branch. DDL
requires the
postgresinherited role. Neki restricts execution of the cross-router DDL barrier function__neki.wait_for_ddlto itsneki_viewerrole, so addneki_viewer, which requirespg_read_all_data, to the same role. Keep the migration credentials out of the application’s runtime configuration. - The Primary connection details from the database’s Connect page.
Install the Postgres adapter
Addpg to the application’s Gemfile:
Gemfile
Store the connection details
Open the encrypted credentials for the target environment:sslrootcert to the path of the
system CA bundle. Common paths include /etc/ssl/certs/ca-certificates.crt
on Debian and Ubuntu, /etc/pki/tls/certs/ca-bundle.crt on RHEL, and
/etc/ssl/cert.pem on macOS:
config/credentials/production.yml.enc
Environment-specific credentials replace the global credentials for that
environment. Keep
secret_key_base in the production credentials, or set
SECRET_KEY_BASE where the application runs, so Rails can start in
production. For local development, use
bin/rails credentials:edit --environment development and a matching
development entry in config/database.yml.Configure Active Record
Add the production connection toconfig/database.yml:
config/database.yml
Framework migration commands send DDL through a normal Neki connection. The
router fans that DDL out to the managed shards, but it does not create a
managed schema-change workflow. Use a schema-change
workflow when you want Neki to prepare and coordinate
an Online DDL change.
pg_read_all_data and pg_write_all_data
cannot run CREATE or ALTER, so a migration that uses application
credentials fails on its first DDL statement.
Apply migration DDL with psql and the migration role so the client prints
PostgreSQL notices:
NOTICE containing the barrier call
for that transaction:
psql when the framework cannot preserve
the notice. If the notice is lost, its version pair cannot be reconstructed.
Route Active Record reads to replicas
Theprimary_replica entry connects to the same Neki endpoint and database,
but the libpq options parameter sets the target when the connection starts.
replica: true prevents Rails database tasks, including migrations, from
running through the reader.
Map Active Record’s writing and reading roles in ApplicationRecord:
app/models/application_record.rb
REPLICA. Replica reads can return stale data, so keep
reads that require the latest committed data on the writing role. See Primary
and replica routing.

