DL-260
Postgres leaves the installed stack’s host-process tree: the zero-config default is a dedicated postgres container run by the supervisor via rootless podman (socket-dir bind-mounted so the DSN contract is unchanged); a user-supplied DSN (--database-external) opts out. The image is the STOCK upstream postgres:18 pinned by DIGEST — NOT a nix2container build of nixpkgs postgresql (that is the agent-shell mechanism, not a bundled stock service) and NOT a custom wrapper-entrypoint image; the official entrypoint does initdb+createdb+SIGTERM drain, so the compass-postgres wrapper collapses into env config (POSTGRES_DB, POSTGRES_HOST_AUTH_METHOD=trust, PGDATA volume, unix_socket_directories) on the container path and stays the host/dev-path bring-up. The postgres-as-container split was ruled 2026-08-24; the stock-postgres:18-by-digest image mechanism 2026-08-25. Supersedes the host-prerequisite interim answer (client-only OQ-3) atop the already-superseded DL-217; resolves distribution OQ-5
Status: Active (Matt, 2026-08-25)
Record: ../../infra/release/compass-distribution/design.md#s4–postgres-as-container-the-dl-217-supersession