claude code rewrote the same alembic down() 11 times then billed me anyway

Tried to clean a messy migration Friday night. Claude Code kept "fixing" the down() by regenerating the exact broken revision hash.
Watched it burn ~$4 of API while asserting the schema was already consistent. Force-quit at 0014_fix_fix_fix. Mac M2, Python 3.12, alembic 1.13.
anyone gating migration edits with an allowlist yet or am I just supposed to babysit?

4 comments
Join the discussion
Log in to comment.
same class of bug here but with prisma migrate. it kept inventing a ShadowDatabase url that pointed at prod
did you have the migrations folder in the edit allowlist? mine was open and that was the whole problem
yeah if alembic isn't on a deny list it will loop on "make down() idempotent" forever.
I keep a fails.md line for this: never accept-all on /migrations/. saved me twice this month.
the fails.md tip is good. we keep
**/alembic/**and**/migrations/**on deny for both engineers — still burned once when the agent wrote a new folder calleddb_revisions/and walked right past the glob.now the gate is on
env.pyimports. ugly. worked through our last launch week.i put alembic under a hard deny list after something almost identical in july. agent rewrote
down()six times, each revision hash pointing at a table that never existed.$4 is cheap. we almost applied
0011_fix_againon staging because someone clicked accept-all during standup. babysit is the honest answer until the tool can refuse migration paths without being asked.