make suffix configurable and add deprecated field to pgUser struct

This commit is contained in:
Felix Kunde
2021-04-23 09:57:34 +02:00
parent eb20c5829b
commit 1e2dbe4712
18 changed files with 89 additions and 30 deletions
+1
View File
@@ -176,6 +176,7 @@ type Config struct {
EnableTeamsAPI bool `name:"enable_teams_api" default:"true"`
EnableTeamSuperuser bool `name:"enable_team_superuser" default:"false"`
TeamAdminRole string `name:"team_admin_role" default:"admin"`
RoleDeprecationSuffix string `name:"role_deprecation_suffix,omitempty" default:"_delete_me"`
EnableAdminRoleForUsers bool `name:"enable_admin_role_for_users" default:"true"`
EnablePostgresTeamCRD bool `name:"enable_postgres_team_crd" default:"false"`
EnablePostgresTeamCRDSuperusers bool `name:"enable_postgres_team_crd_superusers" default:"false"`
-1
View File
@@ -18,6 +18,5 @@ const (
ReaderRoleNameSuffix = "_reader"
WriterRoleNameSuffix = "_writer"
UserRoleNameSuffix = "_user"
RoleRenameSuffix = "_delete_me"
DefaultSearchPath = "\"$user\""
)
+9 -7
View File
@@ -9,7 +9,6 @@ import (
"github.com/zalando/postgres-operator/pkg/spec"
"github.com/zalando/postgres-operator/pkg/util"
"github.com/zalando/postgres-operator/pkg/util/constants"
)
const (
@@ -30,7 +29,8 @@ const (
// an existing roles of another role membership, nor it removes the already assigned flag
// (except for the NOLOGIN). TODO: process other NOflags, i.e. NOSUPERUSER correctly.
type DefaultUserSyncStrategy struct {
PasswordEncryption string
PasswordEncryption string
RoleDeprecationSuffix string
}
// ProduceSyncRequests figures out the types of changes that need to happen with the given users.
@@ -39,9 +39,11 @@ func (strategy DefaultUserSyncStrategy) ProduceSyncRequests(dbUsers spec.PgUserM
var reqs []spec.PgSyncUserRequest
for name, newUser := range newUsers {
if newUser.Deprecated {
continue
}
dbUser, exists := dbUsers[name]
_, existsRenamed := dbUsers[name+constants.RoleRenameSuffix]
if !exists && !existsRenamed {
if !exists {
reqs = append(reqs, spec.PgSyncUserRequest{Kind: spec.PGSyncUserAdd, User: newUser})
if len(newUser.Parameters) > 0 {
reqs = append(reqs, spec.PgSyncUserRequest{Kind: spec.PGSyncAlterSet, User: newUser})
@@ -141,11 +143,11 @@ func (strategy DefaultUserSyncStrategy) alterPgUserSet(user spec.PgUser, db *sql
func (strategy DefaultUserSyncStrategy) alterPgUserRename(user spec.PgUser, db *sql.DB) error {
var query string
if strings.HasSuffix(user.Name, constants.RoleRenameSuffix) {
newName := strings.TrimSuffix(user.Name, constants.RoleRenameSuffix)
if user.Deprecated {
newName := strings.TrimSuffix(user.Name, strategy.RoleDeprecationSuffix)
query = fmt.Sprintf(alterUserRenameSQL, user.Name, newName, "")
} else {
query = fmt.Sprintf(alterUserRenameSQL, user.Name, user.Name, constants.RoleRenameSuffix)
query = fmt.Sprintf(alterUserRenameSQL, user.Name, user.Name, strategy.RoleDeprecationSuffix)
}
if _, err := db.Exec(query); err != nil {