# KMS database configuration

KMS defaults to SQLite so a fresh local or embedded deployment only needs a writable data directory.

## SQLite default

```sh
export KMS_DATABASE_BACKEND=sqlite # optional; this is the default
export KMS_DATA_DIR=/var/lib/kms
mix ecto.migrate
```

By default production stores the database at:

```text
$KMS_DATA_DIR/kms.sqlite3
```

You can set an exact file path instead:

```sh
export KMS_DATABASE_PATH=/var/lib/kms/kms.sqlite3
```

KMS creates the parent directory when the SQLite repo starts. Protect the database file and WAL/SHM sidecars with the same host controls as other KMS secrets.

## PostgreSQL option

PostgreSQL remains supported. Select it with:

```sh
export KMS_DATABASE_BACKEND=postgres
export KMS_DATABASE_URL=ecto://postgres:postgres@localhost/kms_prod
mix ecto.create
mix ecto.migrate
```

Or use host credential variables:

```sh
export KMS_DATABASE_BACKEND=postgres
export KMS_DATABASE_HOST=localhost
export KMS_DATABASE_NAME=kms_prod
export KMS_DATABASE_USER=postgres
export KMS_DATABASE_PASSWORD=postgres
```

## Test matrix

Default `mix test` uses whatever `KMS_DATABASE_BACKEND` selects; with no env it uses SQLite.

Adapter-specific commands:

```sh
mix test.sqlite
mix test.postgresql
mix test.adapters
```

`mix test.adapters` runs the same KMS and KMS API domain tests once with SQLite and once with PostgreSQL. CI can either call that command or define a matrix over `KMS_DATABASE_BACKEND=sqlite|postgres`.
