Avoid overwriting critical users. (#172)

* Avoid overwriting critical users.

Disallow defining new users either in the cluster manifest, teams
API or infrastructure roles with the names mentioned in the new
protected_role_names parameter (list of comma-separated names)

Additionally, forbid defining a user with the name matching either
super_username or replication_username, so that we don't overwrite
system roles required for correct working of the operator itself.

Also, clear PostgreSQL roles on each sync first in order to avoid using
the old definitions that are no longer present in the current manifest,
infrastructure roles secret or the teams API.
This commit is contained in:
Oleksii Kliukin
2017-12-05 14:27:12 +01:00
committed by GitHub
parent 022ce29314
commit 1fb8cf7ea0
5 changed files with 58 additions and 1 deletions
+1
View File
@@ -74,6 +74,7 @@ type Config struct {
ClusterHistoryEntries int `name:"cluster_history_entries" default:"1000"`
TeamAPIRoleConfiguration map[string]string `name:"team_api_role_configuration" default:"log_statement:all"`
PodTerminateGracePeriod time.Duration `name:"pod_terminate_grace_period" default:"5m"`
ProtectedRoles []string `name:"protected_role_names" default:"admin"`
}
// MustMarshal marshals the config or panics