@everystack/pg-tools
v0.4.1
Published
Prebuilt PostgreSQL client tools (pg_dump/pg_restore) as an AWS Lambda layer for everystack db:backup
Readme
@everystack/pg-tools
Prebuilt PostgreSQL client tools (pg_dump + pg_restore) as an AWS Lambda layer, so
everystack db:backup / db:restore and the snapshot-first apply ceremony work with zero setup
on a fresh stage.
The ops Lambda needs real pg_dump/pg_restore binaries — they can't be replicated in JS. This
package vendors them as one byte-reproducible, provenance-verified arm64 artifact. The everystack
Postgres/ops construct publishes it as a content-addressed LayerVersion into your own AWS account
at deploy and attaches it. No env var, no manual layer build, no dependency on our account.
Install
Optional peer of @everystack/server — install it in V2+ apps that have a database:
pnpm add @everystack/pg-toolsThen it's automatic: pgDumpLayer() in your sst.config.ts (via @everystack/server/infra) reads
this package and attaches the layer. See docs/backups.md.
One artifact, not a matrix
- arm64 only — the everystack constructs are arm64. x86_64 is an escape hatch (build your own with
tools/pgdump-layerand pass the construct'spgDumpLayeroption), not a shipped variant. - Ceiling major —
pg_dump/pg_restoreare backward compatible and everystack gates onclientMajor >= serverMajor, so one client at the ceiling major backs up every server at or below it. This package ships the ceiling (manifest.major); it advances as PostgreSQL releases.
What it exports
import { manifest, layerZipPath } from '@everystack/pg-tools';
manifest; // { major, arch, postgresql, binaries, sha256, lock }
layerZipPath(); // absolute path to the vendored layer zipHow the artifact is built
Not by this package — by tools/pgdump-layer/ at the repo root, which
verifies vendor RPM provenance against pinned GPG keys, locks per-RPM sha256, and builds a
byte-reproducible zip. The zip and manifest.json here are the committed output; CI rebuilds and
asserts the sha256 matches. To refresh:
OUT_DIR=packages/pg-tools tools/pgdump-layer/build.shLicense
AGPL-3.0-only, © Scalable Technology, Inc. Open, and stays open. Commercial licensing for closed-source use is available from Scalable Technology.
The bundled PostgreSQL binaries are redistributed under the PostgreSQL License, and the system libraries they link under their respective open-source licenses (from Rocky Linux 9 / PGDG).
