Confiture 🍓
PostgreSQL migrations, sweetly done.
Build from DDL. Adopt on day one against a database that already has migrations applied. Preflight every deploy by replaying the pending migrations against a parallel database, rolled back. Sync production data with PII anonymization.
In 30 seconds
# 1. You already have a database at migration 004 (applied by hand or by another tool).
# Tell Confiture about that history without re-running the SQL:
$ confiture migrate baseline --through 004 -c db/environments/production.yaml
✅ 001 create_users (marked as applied)
✅ 002 create_orders (marked as applied)
✅ 003 add_user_email (marked as applied)
✅ 004 add_user_preferences (marked as applied)
✅ Marked 4 migration(s) as applied, skipped 0 already applied
# 2. Machine-readable proof that the tracking is healthy:
$ confiture migrate status -c db/environments/production.yaml --format json | jq '.applied | length'
4
# 3. Preflight: replay the pending migrations on a parallel DB, inside a rollback.
$ confiture migrate preflight --against "$PREFLIGHT_URL" -c db/environments/production.yaml
Execution check: 1 migration(s) against postgresql://preflight-host/app
✓ 20260520143015 add_user_bio (0.02s)
✓ All 1 migration(s) passed.
(Rolled back — preflight DB unchanged)
exit 0
That's the loop. Baseline once → status to confirm → preflight every deploy.
Already have migrations?
The single biggest reason migration tools fail adoption is the day-one cliff: existing tables already exist, so any tool that tries to apply migrations from scratch crashes on the first CREATE TABLE. Confiture's answer is migrate baseline:
confiture migrate baseline --through <last-applied-version>
The walkthrough — including failure modes, the integration test that backs the recipe, and what tb_confiture ends up looking like — is in docs/guides/legacy-bootstrap.md.
No db/schema/ directory? That works too.
confiture migrate up, down, down-to, status, current, baseline,
and preflight are the migration runner — they don't require a db/schema/
directory (migrate current prints the latest applied revision as a narrow
"what's deployed?" contract; migrate down --steps N rolls back relatively
while migrate down-to <revision> rolls back to a specific revision, refusing
atomically if any required .down.sql is missing). The
"Build from DDL" pitch above the fold sells one of confiture's four
strategies; the other three (incremental migrations, production sync,
schema-to-schema FDW migration) work against a project whose only source
of truth is the migration chain itself.
If you're evaluating confiture against Flyway / Alembic / dbmate / sqlx-cli
as a pure migration runner, skip confiture build and use everything else.
Walkthrough: docs/guides/02-incremental-migrations.md.
When to use Confiture?
| Capability | Confiture | Flyway | Alembic | dbmate | sqlx-cli | plain psql |
|---|---|---|---|---|---|---|
| Source of truth | DDL files or migration chain | migration chain | model classes | migration chain | migration chain | DDL files |
| Tracking table | yes | yes | yes | yes | yes | no |
Rollback (down.sql) |
yes | paid | yes | yes | yes | no |
| Preflight against a copy DB | yes (replayed, rolled back) | no | no | no | no | no |
| Build from scratch in <1s | yes | no | no | no | no | yes (manual) |
| Production sync + anonymization | yes | no | no | no | no | no |
| Zero-downtime via FDW | yes | no | no | no | no | no |
| Ecosystem maturity / stars | early | very mature | mature | mature | mature | n/a |
Note on "source of truth": confiture can run as a pure migration tool against a project that has no
db/schema/directory — the DDL workflow is opt-in. See Nodb/schema/directory? above.
Confiture wins on build-from-DDL, replayed preflight, and production sync. It loses on ecosystem age — Flyway and Alembic have a decade of community knowledge. Pick honestly.
Adoption checklist
| Situation | Recommended tool |
|---|---|
| 1 environment + 1 contributor, schema rarely changes | plain psql |
| 2+ environments, schema changes weekly | Confiture, Flyway, Alembic, or dbmate |
| Multi-agent / AI-driven development on shared schemas | Confiture with the pgGit plugin (plugins/fraiseql-confiture-pggit/) |
You have a migration chain (no db/schema/) and want preflight + tracking |
Confiture (use everything except confiture build) |
You want db/schema/ to be source of truth, not a migration chain |
Confiture |
You need zero-downtime schema swaps with postgres_fdw |
Confiture (Medium 4) |
| You're committed to SQLAlchemy ORM | Alembic |
| You're committed to a JVM stack | Flyway |
CI integration
A migrate preflight gate on every PR, a migrate up step on deploy. Exit codes are semantic, so the CI configuration stays simple:
# .github/workflows/db.yml
name: DB
on:
pull_request:
paths:
- 'db/**'
push:
branches: [main]
jobs:
preflight:
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
services:
postgres:
image: postgres:16
env: { POSTGRES_PASSWORD: x }
ports: ['5432:5432']
options: >-
--health-cmd pg_isready --health-interval 10s
--health-timeout 5s --health-retries 5
steps:
- uses: actions/checkout@v4
- uses: astral-sh/setup-uv@v3
- run: uv pip install --system fraiseql-confiture
- name: Restore production snapshot to preflight DB
run: ./scripts/restore-snapshot.sh # your own; pg_restore from S3/GCS
- name: Confiture preflight
env:
PREFLIGHT_URL: postgresql://postgres:x@localhost:5432/preflight
run: |
confiture migrate preflight \
--against "$PREFLIGHT_URL" \
-c db/environments/preflight.yaml \
--format json --output preflight.json
- uses: actions/upload-artifact@v4
with:
name: preflight-report
path: preflight.json
deploy:
if: github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
environment: production
steps:
- uses: actions/checkout@v4
- uses: astral-sh/setup-uv@v3
- run: uv pip install --system fraiseql-confiture
# No YAML needed in CI — the migrate family reads DATABASE_URL directly
# (or pass --database-url "$DSN"). See the connection-source docs below.
- run: confiture migrate up
env:
DATABASE_URL: ${{ secrets.PROD_DATABASE_URL }}
migrate up/down/status/verify/preflight accept --database-url <dsn> (or read CONFITURE_DATABASE_URL / DATABASE_URL) so runtime-resolved DSNs need no temp YAML — precedence and details in the CLI reference.
Exit codes are a documented stability contract — see the exit-code reference. The most operationally important: 2 tracking table absent, 3 DB connection failed, 5 config invalid, 6 lock contention. For migrate preflight's drift-gate codes specifically, see the dry-run guide.
Migrations that open their own SAVEPOINTs, use
psycopg'sconn.transaction(), or wrapDO $$ … EXCEPTION WHEN … $$blocks are supported under all three modes. The rules a migration body must follow for the SAVEPOINT-based rollback to stay clean are documented in the transaction & SAVEPOINT contract.
Python project snippet
Add Confiture as a dev dependency. pglast (PostgreSQL's own parser) comes with it since 0.50.0.
# pyproject.toml
[dependency-groups]
dev = [
"fraiseql-confiture>=0.50",
"pytest>=8",
]
# justfile
default:
just --list
db-build:
confiture build --env local
db-up:
confiture migrate up
db-status:
confiture migrate status
db-preflight:
confiture migrate preflight --against "$PREFLIGHT_URL"
Or as a Makefile:
db-build:
confiture build --env local
db-up:
confiture migrate up
db-status:
confiture migrate status
Library API
Confiture is a CLI first, but the migrator is fully usable from Python:
from confiture import Migrator
with Migrator.from_config("db/environments/prod.yaml") as m:
status = m.status()
if status.has_pending:
result = m.up()
print(f"Applied {len(result.applied)} migrations")
Building on confiture
What confiture knows about a schema is a public seam, confiture.platform: read a schema
from DDL or from a live database into one model, diff two schemas into typed changes,
order tables by their foreign keys, say which columns a writer supplies and what each must
respect, and write, apply and validate seed files. Every name and signature is pinned by a
contract test, and no signature exposes a parser or driver type.
from confiture.platform import dependency_order, parse_schema, writable_columns
model = parse_schema(env="local")
for table in dependency_order(model):
print(table.display, [c.name for c in writable_columns(model, table)])
confiture schema dump-model writes the same model as byte-stable JSON. Its consumers:
fraisier, which drives confiture at deploy time
through the adapter contract, and
fraiseql-semis (in development), which generates seed data on the seam. See
Building on confiture and the
platform API reference.
The Four Strategies
| Strategy | Use Case | Command |
|---|---|---|
| Build from DDL | Fresh databases, testing, CI | confiture build --env local |
| Incremental Migrations | Existing databases, production | confiture migrate up |
| Production Sync | Copy data with PII anonymization | confiture sync --from prod --anonymize users.email |
| Zero-Downtime | Complex migrations via FDW | confiture migrate schema-to-schema |
Documentation
Start here
- Getting started — first 5 minutes.
- Legacy bootstrap guide — adopting on an existing database.
- Prerequisites — PostgreSQL version, roles, secret stores.
Guides
- Build from DDL
- Incremental Migrations —
up,down, rollback. - Parallel, cacheable CI provisioning —
build --dumpartifacts,test-dbtemplate/clone, per-worker xdist fixtures, slim seed profiles. - Production Data Sync
- Zero-Downtime Migrations
- Dry-Run + Preflight
- Replica-safe migrations —
replica_001/PFLIGHT_REPLICA_*forward-compatibility lint under streaming replication. - Bootstrap —
confiture bootstrapfor one-shot env ownership setup. - Superuser Migrations —
requires_superuser = True+migrate apply-asrecovery workflow. - Function Uniqueness —
func_001catches duplicateCREATE FUNCTIONacross DDL files. - Security-Definer Lint —
sec_002flagsSECURITY DEFINERfunctions/procedures that don't pinsearch_path(CVE-2018-1058); static DDL scan and livepg_procpath;--emit-remediationgenerates ALTER scripts. - Named Schemas
- Hooks
- pgGit branching and multi-agent coordination — a plugin since 1.16, not part of confiture's core.
Reference
- Tracking table (
tb_confiture) - Transaction & SAVEPOINT contract — what migration bodies may and may not do under the wrapping transaction.
- Exit-code convention — the stable, wrapper-facing exit codes.
- CLI
- Configuration YAML
- Complete feature list
For agents and tooling
- JSON schemas are published for the
--format jsonoutput ofbuild,drift,introspect,lint,schema dump-model,sync,validate-config,verify-checksumsand, in the migrate family,migrate up,migrate down-to,migrate status,migrate current,migrate diff,migrate fix,migrate introspect,migrate preflight,migrate steps,migrate validateandmigrate verify. They ship in the package (python/confiture/schemas/) and are mirrored underdocs/reference/json-schemas/; a test asserts the mirror equals the packaged source (seedocs/reference/json-schemas.md). The other commands' JSON payloads are stable but not schema-backed yet. - On an error path in
--format jsonmode, the migrate family emits a structured error envelope on stdout —{"ok": false, "error": {code, message, severity, actionable, details, migration, file, line}}— and exits with the exit code for that error. The full code list and the envelope schema are in the error-code codebook. confiture migrate validate --list-patterns --format jsonexposes the full idempotency-detection catalog (read-only, no DB / config / migrations directory needed).- Quiet-success ambiguities surface advisory hints in
payload["hints"](or on stderr in text mode) — exit codes are unaffected.
Contributing
git clone https://github.com/fraiseql/confiture.git
cd confiture
uv sync --all-extras
uv run pytest
See CONTRIBUTING.md and CLAUDE.md.
Author & License
Vibe-engineered by Lionel Hamayon 🍓
MIT License — Copyright (c) 2025 Lionel Hamayon
Making jam from strawberries, one migration at a time. 🍓→🍯
Release files for fraiseql-confiture 1.18.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| fraiseql_confiture-1.18.0.tar.gz | 3.4 MB | Details |
Built distributions (wheels)
Total release size: 17.1 MB
Release files / fraiseql_confiture-1.18.0.tar.gz
| Download URL | fraiseql_confiture-1.18.0.tar.gz |
|---|---|
| Size | 3.4 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
76f8727a05c18025813d9494178e99821440be968a637c405c4aaa95786963d4
|
|
BLAKE2b-256 checksum How to use checksums |
b3a284260541980fef6feb7a2b177489362e245970fd08a0032f47db492c6297
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / fraiseql_confiture-1.18.0-cp314-cp314-win_amd64.whl
| Download URL | fraiseql_confiture-1.18.0-cp314-cp314-win_amd64.whl |
|---|---|
| Size | 1.3 MB |
| Tags | CPython 3.14 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
c6eea616eb5362938715054ea2651b7e290e1087e78304bb1a6311b7d7069434
|
|
BLAKE2b-256 checksum How to use checksums |
aa94e38dbd9020184cd751aaa35eeca8f11c60c9f8f44662e1a6087c8683142a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / fraiseql_confiture-1.18.0-cp313-cp313-win_amd64.whl
| Download URL | fraiseql_confiture-1.18.0-cp313-cp313-win_amd64.whl |
|---|---|
| Size | 1.3 MB |
| Tags | CPython 3.13 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
482c38e5958d5c4daa621129464017ff659928a5a7a0734683bfbf9859904495
|
|
BLAKE2b-256 checksum How to use checksums |
f286b7e6daa777691ecf28da5061e7c7ed5c040116f7cc0df89ce1c6226700b8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / fraiseql_confiture-1.18.0-cp313-cp313-manylinux_2_28_x86_64.whl
| Download URL | fraiseql_confiture-1.18.0-cp313-cp313-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 1.4 MB |
| Tags | CPython 3.13 Linux glibc 2.28+ x86-64 |
|
SHA-256 checksum How to use checksums |
378e36131521a9b00ba50fe05fb1038a11ae971e0b3b1f48f79a45cca99fdeaf
|
|
BLAKE2b-256 checksum How to use checksums |
f736b514b235680acd7eeb2004cec89c32200f41e2a696dfc736ecda9c670633
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / fraiseql_confiture-1.18.0-cp313-cp313-macosx_11_0_arm64.whl
| Download URL | fraiseql_confiture-1.18.0-cp313-cp313-macosx_11_0_arm64.whl |
|---|---|
| Size | 1.4 MB |
| Tags | CPython 3.13 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
626bb7bc1b40f1ef39b1dcb0254c82f145a7f28e64da29ef41d33a193bff497a
|
|
BLAKE2b-256 checksum How to use checksums |
a9674cefb55a05e2c1f244a974568b9b2bea33f08d7d31034cff0f27da064196
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / fraiseql_confiture-1.18.0-cp312-cp312-win_amd64.whl
| Download URL | fraiseql_confiture-1.18.0-cp312-cp312-win_amd64.whl |
|---|---|
| Size | 1.3 MB |
| Tags | CPython 3.12 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
1b732b05458a47afb01077cce4a4e20519c1452f2e5bd33117b3f1ee0a0161fa
|
|
BLAKE2b-256 checksum How to use checksums |
44b934205c9ef02909bea7b3bd72e7e4be2d5f66ca2891ab6d364ef789eecfe0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / fraiseql_confiture-1.18.0-cp312-cp312-manylinux_2_28_x86_64.whl
| Download URL | fraiseql_confiture-1.18.0-cp312-cp312-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 1.4 MB |
| Tags | CPython 3.12 Linux glibc 2.28+ x86-64 |
|
SHA-256 checksum How to use checksums |
cee40350bdba943b3c1063b973baeb4b724bbfcb965b52ea8084cf51259a617b
|
|
BLAKE2b-256 checksum How to use checksums |
6721837941aaed055b60c3a78ded689cd2dbb73a94ce4d47839f71b486e9df90
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / fraiseql_confiture-1.18.0-cp312-cp312-macosx_11_0_arm64.whl
| Download URL | fraiseql_confiture-1.18.0-cp312-cp312-macosx_11_0_arm64.whl |
|---|---|
| Size | 1.4 MB |
| Tags | CPython 3.12 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
aebc5c748aac1a47306eab56268684f0acbc82df7dda0c1c1b7b28bb3128ad08
|
|
BLAKE2b-256 checksum How to use checksums |
cb8227483d13d8860be23aaaa40922b59de83d37399e003156adc39bba844b64
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / fraiseql_confiture-1.18.0-cp311-cp311-win_amd64.whl
| Download URL | fraiseql_confiture-1.18.0-cp311-cp311-win_amd64.whl |
|---|---|
| Size | 1.3 MB |
| Tags | CPython 3.11 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
bb3fcc525b610ae9118b3501c5f5352a644ccc2d9744dc46ccffc00756dd2c63
|
|
BLAKE2b-256 checksum How to use checksums |
f0187b598a3ae4e3cd86ce54d22727f11f84c3bfde16afe9fa65a2436153bf96
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / fraiseql_confiture-1.18.0-cp311-cp311-manylinux_2_28_x86_64.whl
| Download URL | fraiseql_confiture-1.18.0-cp311-cp311-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 1.4 MB |
| Tags | CPython 3.11 Linux glibc 2.28+ x86-64 |
|
SHA-256 checksum How to use checksums |
ca510fd308af8c3dbcf6c1195fed50437b29b43c361bf27afd0c7a1ea2b098d2
|
|
BLAKE2b-256 checksum How to use checksums |
ed3a1c93dabb757129a700fc9cdae7cc8afb56e587a354858f7bacbdd024d4af
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / fraiseql_confiture-1.18.0-cp311-cp311-macosx_11_0_arm64.whl
| Download URL | fraiseql_confiture-1.18.0-cp311-cp311-macosx_11_0_arm64.whl |
|---|---|
| Size | 1.4 MB |
| Tags | CPython 3.11 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
a1b8883f9267aa4671d2458f9ab97ef6111d7a3e16d280ab7de17525c31ce9ad
|
|
BLAKE2b-256 checksum How to use checksums |
07928a2cc0f6099fa8b8f85f70df315888152fa2ceaff237b0361167a4810ff3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.17 {"installer":{"name":"uv","version":"0.12.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|