Skip to content

Applied ML and Data Science · Mar 2026

locksmith: Dangerous Postgres Migration Checker

Ten lock rules over a real Postgres AST, blocking the migration in CI

Source

The problem

A migration that acquires the wrong lock takes production down at deploy time.

Approach

A Go CLI that analyses migration files and flags operations acquiring dangerous locks — table rewrites, exclusive locks, blocking ALTER TABLE — before they hit production. Distributed via a Homebrew tap and designed to run in CI pipelines.

How it works

Key decisions

Fail the pipeline, do not write a report
A warning in a log is read after the outage. A non-zero exit code stops the deploy, which is the only intervention that actually prevents the incident. Findings carry the fix, not just the rule name, so the pipeline failure is actionable on its own.
Ignore comments over a global off switch
Some locking migrations are intentional and scheduled. Marking them inline keeps the exception next to the reason, rather than disabling the whole rule for everyone.

What the measurements showed

Running it

brew install emartai/tap/locksmith

Full setup, configuration and API reference are in the repository README.

Stack