commerce-encrypt-dbs

command
v1.48.7 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 16, 2026 License: MIT Imports: 5 Imported by: 0

Documentation

Overview

Command commerce-encrypt-dbs converts commerce's PLAINTEXT per-tenant SQLite stores (users/<id>/data.db, orgs/<id>/data.db) to the ENVELOPED, SQLCipher- encrypted layout the daemon opens under COMMERCE_KMS_MASTER_KEY.

Run it as a one-shot Job BEFORE flipping COMMERCE_KMS_MASTER_KEY onto the deployment: once the key is set the daemon refuses any tenant file that has no DEK sidecar (fail-closed), so pre-existing plaintext files must be migrated first. It is idempotent (already-encrypted tenants are skipped) and never deletes the plaintext — each converted file is kept as <data.db>.plaintext.bak for operator verification.

Usage:

COMMERCE_KMS_MASTER_KEY=<64-hex> commerce-encrypt-dbs -data /data
COMMERCE_KMS_MASTER_KEY=<64-hex> commerce-encrypt-dbs -data /data -dry-run

Build (production, links libsqlcipher):

CGO_ENABLED=1 go build -tags "libsqlite3 sqlite_fts5" ./cmd/commerce-encrypt-dbs

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL