Skip to main content

PostgreSQL

FieldAS_IS value
KindRelational system-of-record
C4 classificationContainer: independently provisioned deployable data store
Deployment evidenceSeparate Aurora/RDS Terraform resource; local PostgreSQL image for development
Source contractpackages/api/prisma/schema.prisma and packages/api/prisma/migrations
TechnologyPostgreSQL accessed through Prisma Client
Production indicationEncrypted, non-public AWS Aurora PostgreSQL 14 cluster intent and DATABASE_URL
Local indicationContainerized PostgreSQL/maze-database and local helper scripts
NetworkDefault PostgreSQL port 5432 in local/deployment settings

Stored domains​

The schema contains records for users, access and password-reset tokens, project membership, cloud accounts, projects, canvas/resource state, templates, imports, Terraform variables, project activities, cost history, service status, notifications, feedback, bug/crash reports, images cache, Prism integration, machine images, and administrative data.

Ownership​

Maze Core is the primary database owner through PrismaService. Maze Git's current third-party module does not show direct Prisma access. Migrations are run from root build/production scripts and are copied into the Core image.

Data sensitivity​

  • Identity and authorization state, password-reset/access tokens, user profiles, cloud account credentials, integration metadata, and project infrastructure definitions share one database boundary.
  • Several domains use JSON fields, which makes schema-level constraints and migration analysis less explicit.
  • Repository evidence does not establish encryption-at-rest policy, credential field encryption, backup/restore objectives, retention, row-level isolation, or audit-log immutability.

Operational drift​

Terraform indicates an Aurora PostgreSQL cluster with two instances, seven-day backup retention, and production configured to skip the final snapshot; local Compose embeds credentials and exposes a database container. Additional older TypeORM-style settings coexist with Prisma's DATABASE_URL. Terraform also places the generated credential-bearing DATABASE_URL in a Kubernetes ConfigMap. Treat environment-specific configuration as unverified until the live deployment is inspected.

Migration implications​

Before moving data, classify sensitive fields, define canonical ownership per target service, inventory JSON payload versions, test migration ordering against the full Prisma history, and establish backup, restore, retention, encryption, and tenant-isolation requirements.