ALTER TABLE, CREATE INDEX and CREATE OR REPLACE FUNCTION all require table/function
ownership in PostgreSQL. Replace IF NOT EXISTS DDL with explicit existence checks so
db_init works for unprivileged application users where the schema was created by a
different role (e.g. postgres).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Secrets (S3 keys, PG password, DeerMapper API key) were committed in
config.yaml and .env and remain in git history. This removes them from
the tracked tree and moves all secrets to env injection.
Security:
- config.yaml: drop all credentials, keep only non-secret app tunables
- untrack .env, add .env.example template; .gitignore excludes .env
- main.py: tolerant config lookups + fail-fast validation for missing secrets
- docker-compose: env_file injection, no full-repo bind mount, debug port off
- Dockerfile: bake config into image, run as non-root user
Efficiency:
- OCR: run the second (expensive) tesseract pass only when the first
is unparsable; identical fallback behavior
Docs:
- README with operation + security notes
- MIGRATION.md runbook: secret rotation, server cutover, decommission,
git history purge
Note: the leaked secrets are compromised and MUST be rotated; removing
them from the tree is not sufficient. See MIGRATION.md.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>