Documentation
¶
Overview ¶
Command commerce-encrypt-dbs converts commerce's PLAINTEXT per-tenant SQLite stores (users/<id>/data.db, orgs/<id>/data.db) to the ENVELOPED, SQLCipher- encrypted layout the daemon opens under COMMERCE_KMS_MASTER_KEY.
Run it as a one-shot Job BEFORE flipping COMMERCE_KMS_MASTER_KEY onto the deployment: once the key is set the daemon refuses any tenant file that has no DEK sidecar (fail-closed), so pre-existing plaintext files must be migrated first. It is idempotent (already-encrypted tenants are skipped). Each tenant's plaintext is set aside as <data.db>.plaintext.bak and — once the encrypted copy passes per-table parity — shredded, so no tenant money data is left in the clear at rest. The encrypted copy is the verified source of truth after conversion.
Usage:
COMMERCE_KMS_MASTER_KEY=<64-hex> commerce-encrypt-dbs -data /data COMMERCE_KMS_MASTER_KEY=<64-hex> commerce-encrypt-dbs -data /data -dry-run
Build (production, links libsqlcipher):
CGO_ENABLED=1 go build -tags "libsqlite3 sqlite_fts5" ./cmd/commerce-encrypt-dbs