Database Migration Manager
Expert in safe, reversible database schema migrations with zero-downtime deployment strategies.
Activation Triggers
Activate on: "database migration", "schema change", "alter table", "add column", "drop column", "zero-downtime DDL", "rollback plan", "Prisma migrate", "Drizzle kit", "Flyway", "migration strategy"
NOT for: Query optimization → database-optimizer | ORM data modeling → data-pipeline-engineer | Backup/restore → devops-automator
Quick Start
- Assess the change — additive (safe), modification (needs strategy), or destructive (needs expand-contract)
- Write the migration — forward migration with explicit rollback SQL
- Test on staging — run against a copy of production data volume
- Plan zero-downtime — use expand-contract for breaking changes
- Execute with monitoring — deploy migration, watch error rates, rollback if needed
Core Capabilities
| Domain |
Technologies |
| ORM Migrations |
Prisma Migrate, Drizzle Kit, TypeORM, Sequelize |
| SQL Migrations |
Flyway, Liquibase, golang-migrate, dbmate, Atlas |
| Zero-Downtime |
Expand-contract, shadow columns, online DDL (pt-online-schema-change) |
| Databases |
PostgreSQL 17, MySQL 8.4, SQLite, CockroachDB, PlanetScale |
| Safety |
Rollback scripts, dry-run validation, lock timeout guards |
Architecture Patterns
Expand-Contract Pattern (Zero-Downtime Column Rename)
Phase 1 — EXPAND (deploy migration, app reads both):
├─ Add new column `full_name`
├─ Backfill: UPDATE users SET full_name = name
├─ Add trigger: sync writes to both columns
└─ Deploy app reading `full_name`, falling back to `name`
Phase 2 — MIGRATE (app writes to new only):
├─ Deploy app writing only to `full_name`
└─ Verify no reads/writes to old column (query logs)
Phase 3 — CONTRACT (remove old):
├─ Drop trigger
├─ Drop old column `name`
└─ Clean migration: one final migration file
Safe Migration Template (PostgreSQL)
-- migrations/20260320_001_add_email_verified.sql
-- FORWARD
BEGIN;
SET lock_timeout = '5s'; -- Fail fast if table locked
ALTER TABLE users
ADD COLUMN IF NOT EXISTS email_verified boolean
DEFAULT false NOT NULL;
CREATE INDEX CONCURRENTLY IF NOT EXISTS
idx_users_email_verified ON users(email_verified)
WHERE email_verified = true;
COMMIT;
-- ROLLBACK (in companion file or comment block)
-- BEGIN;
-- DROP INDEX CONCURRENTLY IF EXISTS idx_users_email_verified;
-- ALTER TABLE users DROP COLUMN IF EXISTS email_verified;
-- COMMIT;
Migration Safety Ladder
Risk Level 1 (Safe): ADD COLUMN (nullable), CREATE INDEX CONCURRENTLY
Risk Level 2 (Caution): ADD COLUMN (with default), ADD NOT NULL constraint
Risk Level 3 (Danger): ALTER COLUMN TYPE, RENAME COLUMN
Risk Level 4 (Critical): DROP COLUMN, DROP TABLE
↓
Requires expand-contract pattern
Anti-Patterns
- Running migrations in application startup — if the migration fails, the app cannot start and cannot roll back. Run migrations as a separate CI/CD step with its own rollback.
- No lock_timeout —
ALTER TABLE acquires an ACCESS EXCLUSIVE lock. Without timeout, it queues behind long queries and blocks all subsequent queries. Always set lock_timeout.
- Destructive changes without expand-contract — dropping or renaming columns while the old app version still reads them causes errors. Always use the expand-contract pattern for breaking changes.
- Missing rollback scripts — every forward migration needs a tested rollback. If you cannot roll back, the migration is not safe for production.
- Backfilling in the migration transaction — large backfills in a single transaction lock the table for minutes. Backfill in batches outside the DDL transaction.
Quality Checklist
[ ] Migration has explicit rollback SQL
[ ] lock_timeout set for all DDL statements
[ ] CREATE INDEX uses CONCURRENTLY
[ ] Breaking changes use expand-contract pattern
[ ] Backfills run in batches (1000-10000 rows per batch)
[ ] Migration tested against production-volume staging data
[ ] No data loss — dropped columns backed up or archived
[ ] Migration is idempotent (IF NOT EXISTS / IF EXISTS guards)
[ ] Application code deployed before destructive phase
[ ] Monitoring dashboards checked during and after migration
[ ] Migration numbered/timestamped for ordering
[ ] Rollback tested independently on staging
1---2name: database-migration-manager3description: Safe database migration manager for zero-downtime DDL changes and rollback plans. Activate on: database migration, schema change, DDL, rollback plan, zero-downtime migration, Prisma migrate, Drizzle kit, Flyway, column rename, table alter. NOT for: query optimization (use database-optimizer), ORM modeling (use data-pipeline-engineer), backup/restore (use devops-automator).4license: Apache-2.05---6
7# Database Migration Manager
8
9Expert in safe, reversible database schema migrations with zero-downtime deployment strategies.
10
11## Activation Triggers
12
13**Activate on:** "database migration", "schema change", "alter table", "add column", "drop column", "zero-downtime DDL", "rollback plan", "Prisma migrate", "Drizzle kit", "Flyway", "migration strategy"
14
15**NOT for:** Query optimization → `database-optimizer` | ORM data modeling → `data-pipeline-engineer` | Backup/restore → `devops-automator`
16
17## Quick Start
18
191. **Assess the change** — additive (safe), modification (needs strategy), or destructive (needs expand-contract)
202. **Write the migration** — forward migration with explicit rollback SQL
213. **Test on staging** — run against a copy of production data volume
224. **Plan zero-downtime** — use expand-contract for breaking changes
235. **Execute with monitoring** — deploy migration, watch error rates, rollback if needed
24
25## Core Capabilities
26
27| Domain | Technologies |
28|--------|-------------|
29| **ORM Migrations** | Prisma Migrate, Drizzle Kit, TypeORM, Sequelize |
30| **SQL Migrations** | Flyway, Liquibase, golang-migrate, dbmate, Atlas |
31| **Zero-Downtime** | Expand-contract, shadow columns, online DDL (pt-online-schema-change) |
32| **Databases** | PostgreSQL 17, MySQL 8.4, SQLite, CockroachDB, PlanetScale |
33| **Safety** | Rollback scripts, dry-run validation, lock timeout guards |
34
35## Architecture Patterns
36
37### Expand-Contract Pattern (Zero-Downtime Column Rename)
38
39```
40Phase 1 — EXPAND (deploy migration, app reads both):
41 ├─ Add new column `full_name`
42 ├─ Backfill: UPDATE users SET full_name = name
43 ├─ Add trigger: sync writes to both columns
44 └─ Deploy app reading `full_name`, falling back to `name`
45
46Phase 2 — MIGRATE (app writes to new only):
47 ├─ Deploy app writing only to `full_name`
48 └─ Verify no reads/writes to old column (query logs)
49
50Phase 3 — CONTRACT (remove old):
51 ├─ Drop trigger
52 ├─ Drop old column `name`
53 └─ Clean migration: one final migration file
54```
55
56### Safe Migration Template (PostgreSQL)
57
58```sql
59-- migrations/20260320_001_add_email_verified.sql
60-- FORWARD
61BEGIN;
62SET lock_timeout = '5s'; -- Fail fast if table locked
63
64ALTER TABLE users
65 ADD COLUMN IF NOT EXISTS email_verified boolean
66 DEFAULT false NOT NULL;
67
68CREATE INDEX CONCURRENTLY IF NOT EXISTS
69 idx_users_email_verified ON users(email_verified)
70 WHERE email_verified = true;
71
72COMMIT;
73
74-- ROLLBACK (in companion file or comment block)
75-- BEGIN;
76-- DROP INDEX CONCURRENTLY IF EXISTS idx_users_email_verified;
77-- ALTER TABLE users DROP COLUMN IF EXISTS email_verified;
78-- COMMIT;
79```
80
81### Migration Safety Ladder
82
83```
84Risk Level 1 (Safe): ADD COLUMN (nullable), CREATE INDEX CONCURRENTLY
85Risk Level 2 (Caution): ADD COLUMN (with default), ADD NOT NULL constraint
86Risk Level 3 (Danger): ALTER COLUMN TYPE, RENAME COLUMN
87Risk Level 4 (Critical): DROP COLUMN, DROP TABLE
88 ↓
89 Requires expand-contract pattern
90```
91
92## Anti-Patterns
93
941. **Running migrations in application startup** — if the migration fails, the app cannot start and cannot roll back. Run migrations as a separate CI/CD step with its own rollback.
952. **No lock_timeout** — `ALTER TABLE` acquires an ACCESS EXCLUSIVE lock. Without timeout, it queues behind long queries and blocks all subsequent queries. Always set `lock_timeout`.
963. **Destructive changes without expand-contract** — dropping or renaming columns while the old app version still reads them causes errors. Always use the expand-contract pattern for breaking changes.
974. **Missing rollback scripts** — every forward migration needs a tested rollback. If you cannot roll back, the migration is not safe for production.
985. **Backfilling in the migration transaction** — large backfills in a single transaction lock the table for minutes. Backfill in batches outside the DDL transaction.
99
100## Quality Checklist
101
102```
103[ ] Migration has explicit rollback SQL
104[ ] lock_timeout set for all DDL statements
105[ ] CREATE INDEX uses CONCURRENTLY
106[ ] Breaking changes use expand-contract pattern
107[ ] Backfills run in batches (1000-10000 rows per batch)
108[ ] Migration tested against production-volume staging data
109[ ] No data loss — dropped columns backed up or archived
110[ ] Migration is idempotent (IF NOT EXISTS / IF EXISTS guards)
111[ ] Application code deployed before destructive phase
112[ ] Monitoring dashboards checked during and after migration
113[ ] Migration numbered/timestamped for ordering
114[ ] Rollback tested independently on staging
115```