How I destroyed the company's DB
zaidesanton.substack.com
zaidesanton.substack.com
A great example of software causing grief by trying to be too clever.
Every now and then some story appears on HN complaining that tools can give you an error message and how to fix it instead of just fixing it for you. But when it just fixes it for you, you get problems like this.
Obviously many things went wrong here and the article covers them. But it seems to just gloss over the fact that their SQL client could have prevented it as well...
Although I would have expected a "WARNING - update with no WHERE" nag dialog; I seem to recall it does that from time to time.
I have had some whoppers of screw ups... lost 250k of actual money (paid out).
Its never about the mistake. Its about what you do in response to it. OWN IT, step up, be on point for the fix; it might not be easy but your making a statement about what kind of person you are.
The Mark Twain quote "Humor is tragedy plus time" is truth. The sooner after things are back to normal, and new processes are in place embrace the jokes... Its a signal to everyone that things are OK!
The real problem is silent or partial corruption. Deleting everything gets detected almost immediately; often minutes after the query is run. Silent data corruption can spread for months and be unrecoverable without thoughtful design. But silent data corruption can come from reviewed code too.
DBeaver by default has a warning you have to accept pop up if you try to run an UPDATE without a where clause. Good reason not to disable that warning.
Thankfully it was easily recoverable and the author came out on the other side with some valuable lessons and a bit more wisdom. An easy mistake to make if the process isn’t there to prevent it, at which point it becomes a systemic problem and not a personnel problem.
Compliant process: Write Ticket, approve/review ticket, (give DB access to developer/ops) or CI/CD run SQL with migration, (revoke access), close ticket.
Why? Because I've deleted portions of a live db when I thought I was on testing.
Sure, in some sense as the AWS account owner and tech lead, I’m generally part of the trust chain and could grant them to myself. But there’s only misery available by having them bestowed normally.
I want it to be effort to touch prod, preferably in a way that involves a second person — because it keeps me from being careless. Which I (as a human) often am.
Can’t break what you can’t touch!
I haven't made that mistake again (it's been 15+ years).
Then simply replace SELECT with DELETE and you're done.