Editions and Tiers
Two installs, three editions. The open-source package ships every migration command. The commercial build ships those same commands plus the paid ones; a licence decides which paid commands run. Pro and Enterprise are not two packages — they are licence tiers on that one commercial build.
What each edition adds
| Edition | Licence | Commands |
|---|---|---|
| OSS Core | Apache 2.0 | migrate · info · validate · undo · clean · baseline · repair · import-flyway · db · config |
| Pro | Everything in OSS Core | diff · export-schema · validate-sql · data new · data plan · data apply · data status |
| Enterprise | Everything in Pro | snapshot · plan · preflight · data undo · secret providers |
OSS Core runs and reverses migrations across 20 engines, from the CLI or Python. Pro catches SQL, schema and data risk before a release ships. Enterprise shows approvers what will happen, keeps the evidence, and pulls credentials from your secret manager.
Commands that span tiers
Two commands are not owned by a single edition. Check the subcommand — or, for validate-sql, which rules you asked for.
| Command | Split |
|---|---|
data | new, plan, apply, and status are Pro. undo — reversing an audited correction, including a direct child row — is Enterprise. |
validate-sql | The command is Pro. A custom --rules-file and --rules security run on Pro. Named profiles and the other built-in packs (naming, performance, best_practices) need Enterprise. |
license | Used by both paid editions to activate and inspect a licence. |
Secret providers
Not every edition difference is a command. The secret-resolution mechanism is OSS — any config value can be a URI that DBLift resolves at load time — but the managed-service providers register only on Enterprise, keyed by URI scheme.
| Scheme | Resolves against |
|---|---|
vault:// | HashiCorp Vault |
aws-secrets:// | AWS Secrets Manager |
aws-ssm:// | AWS Systems Manager Parameter Store |
azure-keyvault:// | Azure Key Vault |
gcp-secrets:// | Google Cloud Secret Manager |
Because environment blocks are a plain config merge, each environment can point at a different vault path — see Environments.
What paid commands do on the open-source build
They are visible, not hidden. The open-source build advertises every paid command in --help with its real one-line summary, so you can see what exists before deciding to buy. Running one prints what it does and where to get it, then exits with code 4.
$ dblift diff'diff' is a dblift Pro command and is not included in the open-source edition.Compare applied migrations against live database schema (drift detection).Learn more and upgrade: https://dblift.com/upgrade
When the paid runtime is installed, those stubs are never created — the real command takes the name instead. The same applies to the Python API, where paid client methods exist as stubs that point at the equivalent upgrade.
Exit code 4 means "licence required", not "command failed"
Treat it separately in CI — it is the signal that a pipeline is running the wrong build, not that a migration went wrong.
See Licensing and Activation to activate a key and use it in CI.