mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-03 09:10:13 +02:00
add user retention
This commit is contained in:
@@ -101,6 +101,7 @@ type Auth struct {
|
||||
ReplicationUsername string `name:"replication_username" default:"standby"`
|
||||
EnablePasswordRotation bool `name:"enable_password_rotation" default:"false"`
|
||||
PasswordRotationInterval uint32 `name:"password_rotation_interval" default:"90"`
|
||||
PasswordRotationUserRetention uint32 `name:"password_rotation_user_retention" default:"180"`
|
||||
}
|
||||
|
||||
// Scalyr holds the configuration for the Scalyr Agent sidecar for log shipping:
|
||||
|
||||
@@ -18,6 +18,7 @@ const (
|
||||
alterUserRenameSQL = `ALTER ROLE "%s" RENAME TO "%s%s"`
|
||||
alterRoleResetAllSQL = `ALTER ROLE "%s" RESET ALL`
|
||||
alterRoleSetSQL = `ALTER ROLE "%s" SET %s TO %s`
|
||||
dropUserSQL = `SET LOCAL synchronous_commit = 'local'; DROP ROLE "%s";`
|
||||
grantToUserSQL = `GRANT %s TO "%s"`
|
||||
doBlockStmt = `SET LOCAL synchronous_commit = 'local'; DO $$ BEGIN %s; END;$$;`
|
||||
passwordTemplate = "ENCRYPTED PASSWORD '%s'"
|
||||
@@ -288,3 +289,13 @@ func quoteParameterValue(name, val string) string {
|
||||
}
|
||||
return fmt.Sprintf(`'%s'`, strings.Trim(val, " "))
|
||||
}
|
||||
|
||||
// DropPgUser to remove user created by the operator e.g. for password rotation
|
||||
func DropPgUser(user string, db *sql.DB) error {
|
||||
query := fmt.Sprintf(dropUserSQL, user)
|
||||
if _, err := db.Exec(query); err != nil { // TODO: Try several times
|
||||
return err
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user