Sign inSign up

tensorbeeio/waypoint

By tensorbeeio

•Updated about 1 month ago

Lightweight PostgreSQL migration tool — drop-in Flyway replacement

Image
0

1.5K

tensorbeeio/waypoint repository overview

⁠Waypoint Docker Image

Lightweight SQL migration tool, distributed as a minimal Docker image (~30MB). Supports PostgreSQL 12+ and MySQL 8.0+ (engine auto-detected from the connection URL scheme). Drop-in replacement for Flyway containers.

⁠Quick Start

PostgreSQL:

docker run --rm \
  -v ./db/migrations:/waypoint/sql \
  -e DB_HOST=host.docker.internal \
  -e DB_PORT=5432 \
  -e DB_NAME=mydb \
  -e DB_USERNAME=postgres \
  -e DB_PASSWORD=secret \
  tensorbeeio/waypoint

MySQL 8.0+ (pass the full URL so the mysql:// scheme triggers the MySQL backend):

docker run --rm \
  -v ./db/migrations:/waypoint/sql \
  -e WAYPOINT_DATABASE_URL="mysql://user:[email protected]:3306/mydb" \
  tensorbeeio/waypoint

⁠Pull from Docker Hub

docker pull tensorbeeio/waypoint:latest
docker pull tensorbeeio/waypoint:0.1.0    # pinned version

⁠Migrating from Flyway

Replace your Flyway setup:

# Before
FROM flyway/flyway
COPY migrations /flyway/sql

# After
FROM tensorbeeio/waypoint
COPY migrations /waypoint/sql

The same environment variables work:

Env VarDefaultDescription
DB_HOSTlocalhostDatabase host
DB_PORT5432Database port
DB_NAMEpostgresDatabase name
DB_USERNAMEpostgresDatabase user
DB_PASSWORD(empty)Database password
CONNECT_RETRIES50Connection retry attempts
SSL_MODEpreferTLS mode: disable, prefer, require, verify-ca, verify-full
SSL_ROOT_CERT(empty)Path to a CA PEM file inside the container; replaces the built-in trust store
LOCATIONS/waypoint/sqlMigration file directory

⁠Entrypoint Behavior

The docker-entrypoint.sh script:

  1. Builds a JDBC-style connection URL from environment variables
  2. Runs waypoint migrate with --out-of-order enabled
  3. Retries connection up to 50 times (configurable)
  4. Prints elapsed time on completion

⁠Docker Compose

services:
  db:
    image: postgres:16
    environment:
      POSTGRES_USER: app
      POSTGRES_PASSWORD: secret
      POSTGRES_DB: myapp
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U app -d myapp"]
      interval: 5s
      timeout: 5s
      retries: 5

  migrate:
    image: tensorbeeio/waypoint:latest
    depends_on:
      db:
        condition: service_healthy
    volumes:
      - ./db/migrations:/waypoint/sql
    environment:
      DB_HOST: db
      DB_NAME: myapp
      DB_USERNAME: app
      DB_PASSWORD: secret

⁠Advanced Usage

Override the entrypoint to use the CLI directly:

# Show help
docker run --rm --entrypoint waypoint tensorbeeio/waypoint --help

# Migration status
docker run --rm --entrypoint waypoint \
  -v ./db/migrations:/waypoint/sql \
  tensorbeeio/waypoint \
  --url "postgres://user:pass@host:5432/mydb" \
  --locations /waypoint/sql \
  info

# Dry-run
docker run --rm --entrypoint waypoint \
  -v ./db/migrations:/waypoint/sql \
  tensorbeeio/waypoint \
  --url "postgres://user:pass@host:5432/mydb" \
  --locations /waypoint/sql \
  --dry-run migrate

# JSON output
docker run --rm --entrypoint waypoint \
  -v ./db/migrations:/waypoint/sql \
  tensorbeeio/waypoint \
  --url "postgres://user:pass@host:5432/mydb" \
  --locations /waypoint/sql \
  --json info

# Validate / Repair
docker run --rm --entrypoint waypoint \
  -v ./db/migrations:/waypoint/sql \
  tensorbeeio/waypoint \
  --url "postgres://user:pass@host:5432/mydb" \
  --locations /waypoint/sql \
  validate

⁠TLS Connections

The image includes the Mozilla CA bundle. SSL_MODE takes libpq's values and libpq's meanings:

ModeTLSChain verifiedHostname verified
disableno——
prefer (default)opportunistic, may end up plaintextnono
requiremandatorynono
verify-camandatoryyesno
verify-fullmandatoryyesyes

Note that require encrypts but does not authenticate the server. Use verify-full when you need the server's identity checked.

docker run --rm \
  -v ./db/migrations:/waypoint/sql \
  -e DB_HOST=my-rds-instance.amazonaws.com \
  -e DB_NAME=mydb \
  -e DB_USERNAME=admin \
  -e DB_PASSWORD=secret \
  -e SSL_MODE=verify-full \
  tensorbeeio/waypoint
⁠Private certificate authority

For a server whose certificate is issued by an internal CA, mount the CA file and point SSL_ROOT_CERT at it. As with libpq's sslrootcert, it replaces the built-in trust store rather than adding to it:

docker run --rm \
  -v ./db/migrations:/waypoint/sql \
  -v /etc/ssl/certs/internal-ca.pem:/ca.pem:ro \
  -e DB_HOST=db.internal \
  -e DB_NAME=mydb \
  -e DB_USERNAME=admin \
  -e DB_PASSWORD=secret \
  -e SSL_MODE=verify-full \
  -e SSL_ROOT_CERT=/ca.pem \
  tensorbeeio/waypoint

If the file is missing or contains no certificates the run fails rather than silently falling back to the public CA bundle.

⁠Exit Codes

CodeMeaning
0Success
1General error
2Configuration error
3Validation failed
4Database error
5Migration or hook failed
6Lock error
7Clean disabled

Tag summary

Content type

Image

Digest

sha256:18d3706cd…

Size

6.2 MB

Last updated

about 1 month ago

docker pull tensorbeeio/waypoint