ALTER TABLE social_account ADD COLUMN platform text, ADD COLUMN platform_account_key text, ADD COLUMN authorization_kind text, ADD COLUMN authorization_status text, ADD COLUMN revoked_at timestamptz; UPDATE social_account SET platform = 'mock', platform_account_key = id, authorization_kind = 'owned', authorization_status = 'authorized', status = 'paused', paused_at = COALESCE(paused_at, now()); UPDATE operation_task SET state = 'policy_hold', updated_at = now() WHERE state = 'queued'; ALTER TABLE social_account ALTER COLUMN platform SET NOT NULL, ALTER COLUMN platform_account_key SET NOT NULL, ALTER COLUMN authorization_kind SET NOT NULL, ALTER COLUMN authorization_status SET NOT NULL, ALTER COLUMN status SET DEFAULT 'paused', ALTER COLUMN profile_id DROP NOT NULL, ADD CONSTRAINT social_account_platform_check CHECK (platform ~ '^[a-z0-9][a-z0-9-]{0,31}$'), ADD CONSTRAINT social_account_platform_key_check CHECK (platform_account_key ~ '^[A-Za-z0-9][A-Za-z0-9._:@/-]{0,127}$'), ADD CONSTRAINT social_account_authorization_kind_check CHECK (authorization_kind IN ('owned', 'authorized')), ADD CONSTRAINT social_account_authorization_status_check CHECK (authorization_status IN ('authorized', 'revoked')), ADD CONSTRAINT social_account_platform_key_unique UNIQUE (platform, platform_account_key); ALTER TABLE browser_env ADD COLUMN version bigint NOT NULL DEFAULT 1 CHECK (version > 0); ALTER TABLE browser_image DROP CONSTRAINT IF EXISTS browser_image_image_ref_check, ADD CONSTRAINT browser_image_image_ref_check CHECK (length(image_ref) <= 301 AND (image_ref ~ '^[A-Za-z0-9][A-Za-z0-9._:/@-]*$' OR image_ref ~ '^/[A-Za-z0-9._+~/-]+$')); CREATE TABLE network_exit ( id text PRIMARY KEY CHECK (id ~ '^[A-Za-z0-9][A-Za-z0-9._/-]{0,127}$'), protocol text NOT NULL CHECK (protocol IN ('http', 'https', 'socks4', 'socks5')), host text NOT NULL CHECK (host <> '' AND host !~ '[[:space:]@]' AND length(host) <= 253), port integer NOT NULL CHECK (port BETWEEN 1 AND 65535), credential_reference_id text REFERENCES credential_reference(id), expected_public_ip inet, expected_region text NOT NULL DEFAULT '' CHECK (length(expected_region) <= 64), observed_public_ip inet, observed_region text NOT NULL DEFAULT '' CHECK (length(observed_region) <= 64), health_status text NOT NULL DEFAULT 'unchecked' CHECK (health_status IN ('unchecked', 'healthy', 'unhealthy', 'disabled')), version bigint NOT NULL DEFAULT 1 CHECK (version > 0), last_checked_at timestamptz, created_at timestamptz NOT NULL DEFAULT now(), updated_at timestamptz NOT NULL DEFAULT now() ); CREATE TABLE environment_binding ( id text PRIMARY KEY CHECK (id ~ '^[A-Za-z0-9][A-Za-z0-9._/-]{0,127}$'), account_id text NOT NULL UNIQUE REFERENCES social_account(id), browser_env_alias text NOT NULL UNIQUE REFERENCES browser_env(alias), network_exit_id text REFERENCES network_exit(id), version bigint NOT NULL DEFAULT 1 CHECK (version > 0), created_at timestamptz NOT NULL DEFAULT now(), updated_at timestamptz NOT NULL DEFAULT now() ); INSERT INTO environment_binding (id, account_id, browser_env_alias) SELECT account.id, account.id, environment.alias FROM social_account account JOIN browser_env environment ON environment.alias = account.id; ALTER TABLE runtime_instance ADD COLUMN binding_id text REFERENCES environment_binding(id); UPDATE runtime_instance runtime SET binding_id = binding.id FROM environment_binding binding WHERE binding.account_id = runtime.account_id; CREATE UNIQUE INDEX one_active_runtime_per_binding ON runtime_instance (binding_id) WHERE binding_id IS NOT NULL AND released_at IS NULL; ALTER TABLE audit_event ADD COLUMN browser_env_alias text REFERENCES browser_env(alias), ADD COLUMN network_exit_id text REFERENCES network_exit(id), ADD COLUMN runtime_instance_id text REFERENCES runtime_instance(id), ADD COLUMN binding_version bigint CHECK (binding_version > 0), ADD COLUMN actor text, ADD COLUMN reason_code text;