Sidecar setup (CLAUDE.md Deployment): the one engine the NixOS module and the container image both call. This library holds the parts with no I/O, so every rule is testable without a server:
- [
config]: the one config file naming the target, its options, the schemas to import and the user mappings. - [
secret]: each secret from a file or an env var, exactly one. - [
sync]: the plan that brings the foreign tables in line with the target's catalog, change by change, never by drop and re-import.
10#![forbid(unsafe_code)]