update individual role secrets from infrastructure roles (#206)

* Track origin of roles.

* Propagate changes on infrastructure roles to corresponding secrets.

When the password in the infrastructure role is updated, re-generate the
secret for that role.

Previously, the password for an infrastructure role was always fetched from
the secret, making any updates to such role a no-op after the corresponding
secret had been generated.
This commit is contained in:
Oleksii Kliukin
2018-02-23 17:24:04 +01:00
committed by GitHub
parent 7b05758893
commit 2bb7e98268
7 changed files with 44 additions and 9 deletions
+15 -2
View File
@@ -322,6 +322,10 @@ func (c *Cluster) syncSecrets() error {
if err2 != nil {
return fmt.Errorf("could not get current secret: %v", err2)
}
if secretUsername != string(curSecret.Data["username"]) {
c.logger.Warningf("secret %q does not contain the role %q", secretSpec.Name, secretUsername)
continue
}
c.logger.Debugf("secret %q already exists, fetching its password", util.NameFromMeta(curSecret.ObjectMeta))
if secretUsername == c.systemUsers[constants.SuperuserKeyName].Name {
secretUsername = constants.SuperuserKeyName
@@ -333,8 +337,17 @@ func (c *Cluster) syncSecrets() error {
userMap = c.pgUsers
}
pwdUser := userMap[secretUsername]
pwdUser.Password = string(curSecret.Data["password"])
userMap[secretUsername] = pwdUser
// if this secret belongs to the infrastructure role and the password has changed - replace it in the secret
if pwdUser.Password != string(curSecret.Data["password"]) && pwdUser.Origin == spec.RoleOriginInfrastructure {
c.logger.Debugf("updating the secret %q from the infrastructure roles", secretSpec.Name)
if _, err := c.KubeClient.Secrets(secretSpec.Namespace).Update(secretSpec); err != nil {
return fmt.Errorf("could not update infrastructure role secret for role %q: %v", secretUsername, err)
}
} else {
// for non-infrastructure role - update the role with the password from the secret
pwdUser.Password = string(curSecret.Data["password"])
userMap[secretUsername] = pwdUser
}
continue
} else {