Admin / admin / extension
Independently verify the active tab, connection, server, and database before extension intent.
Public-safe SQL proof packet
This checked-in synthetic example makes expected context, prerequisite status, protected handling categories, validation-step presence, stop conditions, gaps, and provenance inspectable before a DBA or operator makes an independent decision.
Public claim level: demo. Derived from sql-operator-runbook-packet/v2 at a public commit with reduced static-analysis coverage. It contains no statement text, protected values, connection details, scheduled command body, or observed database result.
Proof identity
joefeser/tracemapa522705b3b9f331d65ef4e05e723fc4d2d647f08samples/sql-operator-runbook/setup.sql · synthetic and repo-relativepublic-sql-runbook-proof-v1 · public-safe projection, not raw scan outputreduced · static analysis only · build not run · runtime observation unavailableOrdered context checkpoints
The example uses categorical server, database, schema, and execution-mode roles. It cannot observe which pgAdmin tab or connection is active.
Independently verify the active tab, connection, server, and database before extension intent.
Stop on wrong-tab or wrong-database uncertainty before foreign-server, permission, user-mapping, or schema-import intent.
Independently verify the source context before publication intent.
Require owner review at the pg_cron scheduled-context boundary.
Keep validation-step presence separate from any observed result.
Require owner review before a cleanup or rollback-shaped candidate.
PostgreSQL surfaces
postgres_fdw · illustratedExtension, foreign-server, user-mapping, schema-import, and permission-candidate categories are visible.dblink · missing-evidenceThis fixture does not illustrate extension or call boundaries; absence from the fixture is not a runtime conclusion.pg_cron · illustratedExtension and scheduled-operation categories are visible; the scheduled command body is omitted and execution is not observed.Permission prerequisite language
present-in-scriptsCompatible checked-in evidence appears for the illustrated operation; effective permission still requires DBA validation.missing-evidenceCompatible evidence was not established within coverage; runtime absence is not established.conflicting-evidenceStatic grant, revoke, ordering, or context evidence disagrees.unknownIdentity, ordering, parsing, or coverage does not support a stronger status.needs-owner-reviewAdministrative capability, protected handling, or scheduled context requires a named human owner.Protected categories
user-mapping and credential-option categories; values omitted.connection-material and credential-option categories; values omitted.remote-query-input category; statement content omitted.scheduled-command-body category; command content omitted.Intent versus validation
foreign-serverintended-by-script · milestone validation step not established · validation-evidence-not-providedscheduled-jobintended-by-script · milestone validation step not established · validation-evidence-not-providedvalidationvalidation-step-present · no database result is published or observedcleanup-candidateintended-by-script · completion and reversibility remain unknownEvidence attachment
database.sql.context.declaration.v1 · Tier2Structural · repo-relative spans · sql-execution-context/0.1.0database.sql.secret-bearing-step.v1 · Tier2Structural · repo-relative spans · sql-secret-safety/0.1.0database.postgres.permission.coverage.v1 · Tier2Structural · complete or reduced coverage · postgres-permission-evidence/0.1.0database.postgres.archive-link.v1 · Tier2Structural; gaps use Tier4Unknown · postgres-archive-link/0.1.0Stops, gaps, and owners
dblink, logical-subscription, archive-link direction, and reduced-coverage gaps visible.Public claim boundary
Keep the proof attached