Skip to content

Recover local database and authorization state

runbookobservedEvidence reviewed 2026-10-06

Local seed/worktree databases and local SpiceDB. First distinguish the primary seed from the selected worktree. Production and staging are not repair targets.

Read the selected task’s generated connection configuration locally without copying secrets. Confirm localhost destinations and the task’s Compose ownership. Check migration readiness, restore logs and schema/constraint state. A sync script exit code alone is not proof of a valid restore.

If authorization fails after seeding, copied staging revision tokens may not belong to local SpiceDB. The reviewed API lifecycle reconciles relationships and overwrites local tokens as needed. If mapping code changed without schema/migration changes, consult the current application’s sync:authzed instructions for an explicit task-scoped sync.

Use the repository lifecycle for ordinary reconciliation. Never point a reset/sync command at a cloud authorization endpoint. Preserve the target data before an explicitly requested reseed. Do not copy earlier one-off SQL cleanup commands into a new restore: inspect actual foreign-key failures and exclusions first.

The initial staging sync excluded parent image rows and left dependent data. Its local cleanup counts are historical, not a recipe. Fix exclusions and error propagation before scheduling refreshes. See the staging workflow.

Compare intended table/constraint/migration states, check no invalid indexes, verify local authorization and perform the relevant read-only app operation. Streaming CDC handles subsequent changes; historical analytics remain a separate backfill. If recovery requires deleting data, stop with a concrete target and preservation plan.