add unit test for syncSecrets + new updateSecret func

This commit is contained in:
Felix Kunde
2022-02-09 18:40:49 +01:00
parent 48cbc66d19
commit 11c286fe9a
6 changed files with 216 additions and 126 deletions
+1 -1
View File
@@ -129,7 +129,7 @@ These parameters are grouped directly under the `spec` key in the manifest.
password value will be replaced in the secrets which the operator reflects
in the database, too. List only users here that rarely connect to the
database, like a flyway user running a migration on Pod start. See more
details in the [administrator docs](https://github.com/zalando/postgres-operator/blob/master/docs/administrator.md#password-replacement-without-extra-roles).
details in the [administrator docs](https://github.com/zalando/postgres-operator/blob/master/docs/administrator.md#password-replacement-without-extra-users).
* **databases**
a map of database names to database owners for the databases that should be
+4 -4
View File
@@ -175,12 +175,12 @@ under the `users` key.
`standby`.
* **enable_password_rotation**
For all LOGIN roles that are not database owners the Operator can rotate
For all `LOGIN` roles that are not database owners the operator can rotate
credentials in the corresponding K8s secrets by replacing the username and
password. This means, new users will be added on each rotation inheriting
all priviliges from the original roles. The rotation date in the YYMMDD is
appended to the new user names. The timestamp of the next rotation is
written to the secret. The default is `false`.
all priviliges from the original roles. The rotation date (in YYMMDD format)
is appended to the names of the new user. The timestamp of the next rotation
is written to the secret. The default is `false`.
* **password_rotation_interval**
If password rotation is enabled (either from config or cluster manifest) the