mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-09-30 12:34:32 +02:00
Secrets deletion config (#2582)
* Secrets deletion config * Update e2e/tests/test_e2e.py Co-authored-by: Felix Kunde <felix-kunde@gmx.de> --------- Co-authored-by: Felix Kunde <felix-kunde@gmx.de>
This commit is contained in:
@@ -1323,6 +1323,9 @@ var OperatorConfigCRDResourceValidation = apiextv1.CustomResourceValidation{
|
||||
"enable_init_containers": {
|
||||
Type: "boolean",
|
||||
},
|
||||
"enable_secrets_deletion": {
|
||||
Type: "boolean",
|
||||
},
|
||||
"enable_persistent_volume_claim_deletion": {
|
||||
Type: "boolean",
|
||||
},
|
||||
|
||||
@@ -102,6 +102,7 @@ type KubernetesMetaConfiguration struct {
|
||||
PodAntiAffinityTopologyKey string `json:"pod_antiaffinity_topology_key,omitempty"`
|
||||
PodManagementPolicy string `json:"pod_management_policy,omitempty"`
|
||||
PersistentVolumeClaimRetentionPolicy map[string]string `json:"persistent_volume_claim_retention_policy,omitempty"`
|
||||
EnableSecretsDeletion *bool `json:"enable_secrets_deletion,omitempty"`
|
||||
EnablePersistentVolumeClaimDeletion *bool `json:"enable_persistent_volume_claim_deletion,omitempty"`
|
||||
EnableReadinessProbe bool `json:"enable_readiness_probe,omitempty"`
|
||||
EnableCrossNamespaceSecret bool `json:"enable_cross_namespace_secret,omitempty"`
|
||||
|
||||
@@ -272,6 +272,11 @@ func (in *KubernetesMetaConfiguration) DeepCopyInto(out *KubernetesMetaConfigura
|
||||
(*out)[key] = val
|
||||
}
|
||||
}
|
||||
if in.EnableSecretsDeletion != nil {
|
||||
in, out := &in.EnableSecretsDeletion, &out.EnableSecretsDeletion
|
||||
*out = new(bool)
|
||||
**out = **in
|
||||
}
|
||||
if in.EnablePersistentVolumeClaimDeletion != nil {
|
||||
in, out := &in.EnablePersistentVolumeClaimDeletion, &out.EnablePersistentVolumeClaimDeletion
|
||||
*out = new(bool)
|
||||
|
||||
@@ -1154,10 +1154,14 @@ func (c *Cluster) Delete() error {
|
||||
c.eventRecorder.Eventf(c.GetReference(), v1.EventTypeWarning, "Delete", "could not delete statefulset: %v", err)
|
||||
}
|
||||
|
||||
if err := c.deleteSecrets(); err != nil {
|
||||
anyErrors = true
|
||||
c.logger.Warningf("could not delete secrets: %v", err)
|
||||
c.eventRecorder.Eventf(c.GetReference(), v1.EventTypeWarning, "Delete", "could not delete secrets: %v", err)
|
||||
if c.OpConfig.EnableSecretsDeletion != nil && *c.OpConfig.EnableSecretsDeletion {
|
||||
if err := c.deleteSecrets(); err != nil {
|
||||
anyErrors = true
|
||||
c.logger.Warningf("could not delete secrets: %v", err)
|
||||
c.eventRecorder.Eventf(c.GetReference(), v1.EventTypeWarning, "Delete", "could not delete secrets: %v", err)
|
||||
}
|
||||
} else {
|
||||
c.logger.Info("not deleting secrets because disabled in configuration")
|
||||
}
|
||||
|
||||
if err := c.deletePodDisruptionBudget(); err != nil {
|
||||
|
||||
@@ -122,6 +122,7 @@ func (c *Controller) importConfigurationFromCRD(fromCRD *acidv1.OperatorConfigur
|
||||
result.PodPriorityClassName = fromCRD.Kubernetes.PodPriorityClassName
|
||||
result.PodManagementPolicy = util.Coalesce(fromCRD.Kubernetes.PodManagementPolicy, "ordered_ready")
|
||||
result.PersistentVolumeClaimRetentionPolicy = fromCRD.Kubernetes.PersistentVolumeClaimRetentionPolicy
|
||||
result.EnableSecretsDeletion = util.CoalesceBool(fromCRD.Kubernetes.EnableSecretsDeletion, util.True())
|
||||
result.EnablePersistentVolumeClaimDeletion = util.CoalesceBool(fromCRD.Kubernetes.EnablePersistentVolumeClaimDeletion, util.True())
|
||||
result.EnableReadinessProbe = fromCRD.Kubernetes.EnableReadinessProbe
|
||||
result.MasterPodMoveTimeout = util.CoalesceDuration(time.Duration(fromCRD.Kubernetes.MasterPodMoveTimeout), "10m")
|
||||
|
||||
@@ -250,6 +250,7 @@ type Config struct {
|
||||
PatroniAPICheckInterval time.Duration `name:"patroni_api_check_interval" default:"1s"`
|
||||
PatroniAPICheckTimeout time.Duration `name:"patroni_api_check_timeout" default:"5s"`
|
||||
EnablePatroniFailsafeMode *bool `name:"enable_patroni_failsafe_mode" default:"false"`
|
||||
EnableSecretsDeletion *bool `name:"enable_secrets_deletion" default:"true"`
|
||||
EnablePersistentVolumeClaimDeletion *bool `name:"enable_persistent_volume_claim_deletion" default:"true"`
|
||||
PersistentVolumeClaimRetentionPolicy map[string]string `name:"persistent_volume_claim_retention_policy" default:"when_deleted:retain,when_scaled:retain"`
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user