CI does not need credentials to the target database. The deployment host does. The hand-off is a published snapshot.
deployment host (database reachable) CI (offline)
------------------------------------ -----------
dblift diff --generate-sql --fail-on warning
dblift migrate --env prod
dblift snapshot publish --env prod --> dblift plan --env prod
dblift preflight --env prod --skip-replay
On the host
diffagainst the live schema. Stop if drift needs a human.migrate --env prod. A successful run captures a snapshot into the snapshots table.snapshot publish --env prodwrites the portable JSON (and sidecar manifest) that CI will read.
In CI
plan and preflight read the environment's snapshot.source. They do not open the target database. Preflight still needs a replay mode: --skip-replay for an offline gate, or --container-existing / --container-image when you rehearse against a throwaway schema you provide.
--fail-on warning treats warnings as blocking. Archive --output-dir.
See Environments, Snapshot models, Plan, Preflight and Drift detection.