SIGN IN SIGN UP

feat(capsuledb): add optional authorization persistence (#74)

## Summary

Add an optional PostgreSQL persistence package for DomainKit's
Effect-first managed-DNS authorization lifecycle. Hosts retain the exact
SQL client, credential custody, tenant/domain bindings, routes, consent,
authorization, and audit policy.

## Composition

```ts
const authorizationCapsule = yield* capsule;
const registry = yield* makeRegistry({
  capsules: [authorizationCapsule],
  provider: Pg.profile,
});

yield* prepare(registry);
```

```text
host-owned Pool
  -> one Effect PgClient
     -> Effect Drizzle
     -> CapsuleDB registry + ManagedDnsConnections.Service
```

Preparation runs once per API/workflow runtime before readiness. Both
persistence paths receive the same `PgClient`, including inside shared
transactions.

## Ownership

| Package | Host |
| --- | --- |
| Authorization aggregate schema and CapsuleDB migrations | Pool, client
lifetime, organizations, and domains |
| Atomic connect, attach, detach, rotate, and evidence updates |
Credential encryption and KMS keys |
| Durable final-revocation preparation and recovery | Tenancy,
authorization, consent, audit, and routes |

The PostgreSQL tracer adopts the existing authorization, connection, and
attachment tables in place. It exports semantic Effect services only—no
rows, tables, Drizzle schema, query handles, Promise implementation, or
async lifecycle wrapper.

## Validation

- frozen Bun install from CapsuleDB Git SHA
`561aa127b37055f885c703583c3c5e80b44395f3`; no local-path lock entries
- `bun run release:check`
  - DomainKit: 156 tests and 7 packed-artifact tests
  - React: 71 tests, 4 packed-artifact tests, and 5 browser tests
- CapsuleDB integration: 8 PostgreSQL lifecycle/concurrency tests and 1
packed-artifact test
- `git diff --check`

The isolated Blume typecheck retains the existing Astro/React/Bun typing
baseline; the new reference page adds no reported error.

## Follow-up scope

- Async DomainKit hosts supply their own Promise persistence; CapsuleDB
remains Effect-native.
- Samva schema/repository convergence is a separate host PR; runtime
cutover waits for package publication.
- Bun SQLite and libSQL remain deferred until the PostgreSQL contract is
proven. D1 remains deferred because bounded `AtomicBatch` cannot express
this lifecycle.
- No package publish, deployment, database migration, or production
cutover is included.
S
Saatvik Arya committed
6b96c71670260ea7959ea9361ea5dae41fbfcaf8
Parent: 52f3dd1
Committed by GitHub <noreply@github.com> on 8/31/2026, 8:50:27 PM