mirror of
https://github.com/zitadel/zitadel.git
synced 2025-07-19 07:28:35 +00:00

# Which Problems Are Solved Add the ability to keep track of the current counts of projection resources. We want to prevent calling `SELECT COUNT(*)` on tables, as that forces a full scan and sudden spikes of DB resource uses. # How the Problems Are Solved - A resource_counts table is added - Triggers that increment and decrement the counted values on inserts and deletes - Triggers that delete all counts of a table when the source table is TRUNCATEd. This is not in the business logic, but prevents wrong counts in case someone want to force a re-projection. - Triggers that delete all counts if the parent resource is deleted - Script to pre-populate the resource_counts table when a new source table is added. The triggers are reusable for any type of resource, in case we choose to add more in the future. Counts are aggregated by a given parent. Currently only `instance` and `organization` are defined as possible parent. This can later be extended to other types, such as `project`, should the need arise. I deliberately chose to use `parent_id` to distinguish from the de-factor `resource_owner` which is usually an organization ID. For example: - For users the parent is an organization and the `parent_id` matches `resource_owner`. - For organizations the parent is an instance, but the `resource_owner` is the `org_id`. In this case the `parent_id` is the `instance_id`. - Applications would have a similar problem, where the parent is a project, but the `resource_owner` is the `org_id` # Additional Context Closes https://github.com/zitadel/zitadel/issues/9957
126 lines
3.5 KiB
Go
126 lines
3.5 KiB
Go
package setup
|
|
|
|
import (
|
|
"fmt"
|
|
|
|
"github.com/zitadel/zitadel/internal/database"
|
|
"github.com/zitadel/zitadel/internal/domain"
|
|
"github.com/zitadel/zitadel/internal/migration"
|
|
"github.com/zitadel/zitadel/internal/query/projection"
|
|
)
|
|
|
|
// triggerSteps defines the repeatable migrations that set up triggers
|
|
// for counting resources in the database.
|
|
func triggerSteps(db *database.DB) []migration.RepeatableMigration {
|
|
return []migration.RepeatableMigration{
|
|
// Delete parent count triggers for instances and organizations
|
|
migration.DeleteParentCountsTrigger(db,
|
|
projection.InstanceProjectionTable,
|
|
domain.CountParentTypeInstance,
|
|
projection.InstanceColumnID,
|
|
projection.InstanceColumnID,
|
|
"instance",
|
|
),
|
|
migration.DeleteParentCountsTrigger(db,
|
|
projection.OrgProjectionTable,
|
|
domain.CountParentTypeOrganization,
|
|
projection.OrgColumnInstanceID,
|
|
projection.OrgColumnID,
|
|
"organization",
|
|
),
|
|
|
|
// Count triggers for all the resources
|
|
migration.CountTrigger(db,
|
|
projection.OrgProjectionTable,
|
|
domain.CountParentTypeInstance,
|
|
projection.OrgColumnInstanceID,
|
|
projection.OrgColumnInstanceID,
|
|
"organization",
|
|
),
|
|
migration.CountTrigger(db,
|
|
projection.ProjectProjectionTable,
|
|
domain.CountParentTypeOrganization,
|
|
projection.ProjectColumnInstanceID,
|
|
projection.ProjectColumnResourceOwner,
|
|
"project",
|
|
),
|
|
migration.CountTrigger(db,
|
|
projection.UserTable,
|
|
domain.CountParentTypeOrganization,
|
|
projection.UserInstanceIDCol,
|
|
projection.UserResourceOwnerCol,
|
|
"user",
|
|
),
|
|
migration.CountTrigger(db,
|
|
projection.InstanceMemberProjectionTable,
|
|
domain.CountParentTypeInstance,
|
|
projection.MemberInstanceID,
|
|
projection.MemberResourceOwner,
|
|
"iam_admin",
|
|
),
|
|
migration.CountTrigger(db,
|
|
projection.IDPTable,
|
|
domain.CountParentTypeInstance,
|
|
projection.IDPInstanceIDCol,
|
|
projection.IDPInstanceIDCol,
|
|
"identity_provider",
|
|
),
|
|
migration.CountTrigger(db,
|
|
projection.IDPTemplateLDAPTable,
|
|
domain.CountParentTypeInstance,
|
|
projection.LDAPInstanceIDCol,
|
|
projection.LDAPInstanceIDCol,
|
|
"identity_provider_ldap",
|
|
),
|
|
migration.CountTrigger(db,
|
|
projection.ActionTable,
|
|
domain.CountParentTypeInstance,
|
|
projection.ActionInstanceIDCol,
|
|
projection.ActionInstanceIDCol,
|
|
"action_v1",
|
|
),
|
|
migration.CountTrigger(db,
|
|
projection.ExecutionTable,
|
|
domain.CountParentTypeInstance,
|
|
projection.ExecutionInstanceIDCol,
|
|
projection.ExecutionInstanceIDCol,
|
|
"execution",
|
|
),
|
|
migration.CountTrigger(db,
|
|
fmt.Sprintf("%s_%s", projection.ExecutionTable, projection.ExecutionTargetSuffix),
|
|
domain.CountParentTypeInstance,
|
|
projection.ExecutionTargetInstanceIDCol,
|
|
projection.ExecutionTargetInstanceIDCol,
|
|
"execution_target",
|
|
),
|
|
migration.CountTrigger(db,
|
|
projection.LoginPolicyTable,
|
|
domain.CountParentTypeInstance,
|
|
projection.LoginPolicyInstanceIDCol,
|
|
projection.LoginPolicyInstanceIDCol,
|
|
"login_policy",
|
|
),
|
|
migration.CountTrigger(db,
|
|
projection.PasswordComplexityTable,
|
|
domain.CountParentTypeInstance,
|
|
projection.ComplexityPolicyInstanceIDCol,
|
|
projection.ComplexityPolicyInstanceIDCol,
|
|
"password_complexity_policy",
|
|
),
|
|
migration.CountTrigger(db,
|
|
projection.PasswordAgeTable,
|
|
domain.CountParentTypeInstance,
|
|
projection.AgePolicyInstanceIDCol,
|
|
projection.AgePolicyInstanceIDCol,
|
|
"password_expiry_policy",
|
|
),
|
|
migration.CountTrigger(db,
|
|
projection.LockoutPolicyTable,
|
|
domain.CountParentTypeInstance,
|
|
projection.LockoutPolicyInstanceIDCol,
|
|
projection.LockoutPolicyInstanceIDCol,
|
|
"lockout_policy",
|
|
),
|
|
}
|
|
}
|