refactor pooler tls support and set pooler pod security context (#2255)

* bump pooler image
* set pooler pod security context
* use hard coded RunAsUser 100 and RunAsGroup 101 for pooler pod
* unify generation of TLS secret mounts
* extend documentation on tls support
* add unit test for testing TLS support for pooler
* add e2e test for tls support
This commit is contained in:
Felix Kunde
2023-04-17 11:38:56 +02:00
committed by GitHub
parent 87b7ac0806
commit 0e7beb5fe5
16 changed files with 369 additions and 120 deletions
+3 -1
View File
@@ -543,7 +543,9 @@ for both master and replica pooler services (if `enableReplicaConnectionPooler`
## Custom TLS certificates
Those parameters are grouped under the `tls` top-level key.
Those parameters are grouped under the `tls` top-level key. Note, you have to
define `spiloFSGroup` in the Postgres cluster manifest or `spilo_fsgroup` in
the global configuration before adding the `tls` section'.
* **secretName**
By setting the `secretName` value, the cluster will switch to load the given