{"record":{"id":"16659a916da8a723","repo":"clockworklabs/SpacetimeDB","slug":"database-environment-variables-can-only-be-changed-by","errorCode":null,"errorMessage":"Database environment variables can only be changed by publishing","messagePattern":"Database environment variables can only be changed by publishing","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/core/src/sql/execute.rs","lineNumber":150,"sourceCode":"            // Update transaction metrics\n            tx.metrics.merge(metrics);\n\n            Ok((\n                SqlResult {\n                    tx_offset,\n                    rows,\n                    metrics: tx.metrics,\n                },\n                trapped,\n            ))\n        }\n        Statement::DML(stmt) => {\n            // An extra layer of auth is required for DML\n            if !auth.has_write_access() {\n                return Err(anyhow!(\"Caller {} is not authorized to run SQL DML statements\", auth.caller()).into());\n            }\n            if stmt.table_id() == spacetimedb_datastore::system_tables::ST_ENV_ID {\n                return Err(anyhow!(\"Database environment variables can only be changed by publishing\").into());\n            }\n\n            // Evaluate the mutation\n            let (mut tx, _) = db.with_auto_rollback(tx, |tx| execute_dml_stmt(&auth, stmt, tx, &mut metrics))?;\n\n            // Update transaction metrics\n            tx.metrics.merge(metrics);\n\n            // Update views\n            let (result, _num_views_evaluated, trapped) = match instance {\n                Some(instance) => ModuleHost::call_views_with_tx(tx, instance, auth.caller()),\n                None => (ViewCallResult::default(tx), 0, false),\n            };\n\n            // Rollback transaction and report metrics if view execution failed\n            if let ViewOutcome::Failed(err) = result.outcome {\n                let (_, metrics, reducer) = db.rollback_mut_tx(result.tx);\n                db.report_mut_tx_metrics(reducer, metrics, None);","sourceCodeStart":132,"sourceCodeEnd":168,"githubUrl":"https://github.com/clockworklabs/SpacetimeDB/blob/eddf9f5014579a50d4b67630e28b6e15cad9c4af/crates/core/src/sql/execute.rs#L132-L168","documentation":"SQL DML against the st_env system table is blocked: environment variables for a database are managed exclusively through the publish flow, which validates keys, records the environment schema, and updates program metadata atomically. Direct SQL writes would bypass those invariants, so run_inner rejects them with this error.","triggerScenarios":"Executing an SQL INSERT/UPDATE/DELETE statement whose stmt.table_id() == ST_ENV_ID via the SQL execution API, even when the caller has write access.","commonSituations":"A developer trying to set or tweak a database config variable with `UPDATE st_env SET value=...` in the SQL console; automation scripts mutating env rows directly.","solutions":["Change environment variables by republishing with the desired environment spec (`spacetime publish` with the updated environment).","Read-only SELECTs on st_env remain allowed — use SELECT to inspect current values.","For secrets/config not tied to publishing, store them in your own table instead of st_env."],"exampleFix":"-- before: direct DML on env table\nUPDATE st_env SET value = 'v2' WHERE key = 'API_KEY';\n\n-- after: change via publish (CLI)\n-- spacetime publish mydb --env API_KEY=v2","handlingStrategy":"validation","validationCode":"-- reject st_env DML before sending\nif sql.trim().toUpperCase().startsWith(('INSERT','UPDATE','DELETE')) && /\\bst_env\\b/.test(sql) throw new Error('mutate st_env only via publish');","typeGuard":null,"tryCatchPattern":"try { execSql(sql); } catch (e) { if (e.message.includes('can only be changed by publishing')) switchToPublishFlow(); else throw e; }","preventionTips":["Treat st_env as read-only in SQL","Manage env via the publish command/API","Use your own tables for app-managed config"],"tags":["sql","dml","environment","permission"],"backgroundTag":"unsupported-operation","analyzedSha":"eddf9f5014579a50d4b67630e28b6e15cad9c4af","analyzedAt":"2026-09-20T12:15:59.611Z","contentChangedAt":"2026-09-20T12:15:59.611Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}