make suffix configurable and add deprecated field to pgUser struct

This commit is contained in:
Felix Kunde
2021-04-23 09:57:34 +02:00
parent eb20c5829b
commit 1e2dbe4712
18 changed files with 89 additions and 30 deletions
+7
View File
@@ -704,6 +704,13 @@ key.
cluster to administer Postgres and maintain infrastructure built around it.
The default is empty.
* **role_deprecation_suffix**
defines a suffix that will be appended to database role names of team members
that were removed from either PostgresTeam CRDs (additionalMembers) or from
the team in the teams API. When readded to the manifest, the operator will
rename roles with the defined suffix back to the original role name.
The default is `_delete_me`.
* **enable_postgres_team_crd**
toggle to make the operator watch for created or updated `PostgresTeam` CRDs
and create roles for specified additional teams and members.
+11
View File
@@ -407,6 +407,17 @@ spec:
- "briggs"
```
#### Removed members
The Postgres Operator does not delete database roles when users are removed
from manifests. But, when using the PostgresTeam CRD or Teams API it is very
easy to (accidently) add roles to many clusters. Manually reverting such a
change is cumbersome. Therefore, if members are removed from the team CRD or
teams API the operator will rename roles appending a configured suffix to the
name (see `role_deprecation_suffix` option) so that old members cannot login
anymore. When a role is readded to the manifest the operator will check for
roles with the configured suffix and rename the role back to the original name.
## Prepared databases with roles and default privileges
The `users` section in the manifests only allows for creating database roles