update individual role secrets from infrastructure roles (#206)

* Track origin of roles.

* Propagate changes on infrastructure roles to corresponding secrets.

When the password in the infrastructure role is updated, re-generate the
secret for that role.

Previously, the password for an infrastructure role was always fetched from
the secret, making any updates to such role a no-op after the corresponding
secret had been generated.
This commit is contained in:
Oleksii Kliukin
2018-02-23 17:24:04 +01:00
committed by GitHub
parent 7b05758893
commit 2bb7e98268
7 changed files with 44 additions and 9 deletions
+1 -1
View File
@@ -116,7 +116,7 @@ Users:
// in worst case we would have one line per user
for i := 1; i <= len(data); i++ {
properties := []string{"user", "password", "inrole"}
t := spec.PgUser{}
t := spec.PgUser{Origin: spec.RoleOriginInfrastructure}
for _, p := range properties {
key := fmt.Sprintf("%s%d", p, i)
if val, present := data[key]; !present {
+1
View File
@@ -131,6 +131,7 @@ func TestGetInfrastructureRoles(t *testing.T) {
map[string]spec.PgUser{
"testrole": {
Name: "testrole",
Origin: spec.RoleOriginInfrastructure,
Password: "testpassword",
MemberOf: []string{"testinrole"},
},