midplane.yaml, named with --config. Relative paths in it
are relative to the file. Secrets never appear inline: a DSN, the mask salt,
the identity and the enrollment token each name an environment variable or a
file, so the config itself can be committed.
Both modes
Local mode only (midplane local)
Linked mode only (midplane gateway)
Linked databases have no
policy: policies come in signed bundles from
Midplane Cloud.
The policy
A database’s policy, in local mode underdatabases.<id>.policy, in linked
mode authored in the dashboard (which shows it as JSON too). Strict: an
unknown key anywhere refuses the whole policy, never part of it.
Whatever the policy says, a statement must be one statement Midplane can
parse and resolve; writes need a
WHERE; writes hidden inside a WITH are
denied; and reads run in read-only transactions.
Tested by apps/gateway/test/config.test.ts (secrets and paths, TLS off
loopback, public URLs, the salt, retention, unknown keys, both modes) and the
core’s corpus (packages/corpus) for what a policy means.