fix(db): replace broken migration system with clean baseline (#105) master
* fix(db): add entities.roles to drizzle config for RLS support * feat(db): replace 32 broken migrations with single baseline Delete all legacy migration files (0000-0031) that were out of sync with the database state. Generate a clean baseline from the current Drizzle schema that creates all 30 tables, 16 RLS policies, and the barazo_app role in a single migration. This is a clean break -- existing databases must be wiped or have the baseline manually marked as applied. * fix(db): use tsx loader for drizzle-kit generate drizzle-kit uses CJS require internally, which can't resolve .js extension imports to .ts files. Running via --import tsx fixes the module resolution for schema files that use ESM import conventions. * refactor(db): switch db:migrate from drizzle-kit CLI to programmatic migrate() Ensures CI, local dev, and production runtime all use the same migration code path (drizzle-orm/postgres-js/migrator). * ci: add schema drift detection to CI pipeline Runs drizzle-kit generate and fails if there are uncommitted migration files, catching forgotten db:generate runs.