mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-09-30 18:28:06 +02:00
update individual role secrets from infrastructure roles (#206)
* Track origin of roles. * Propagate changes on infrastructure roles to corresponding secrets. When the password in the infrastructure role is updated, re-generate the secret for that role. Previously, the password for an infrastructure role was always fetched from the secret, making any updates to such role a no-op after the corresponding secret had been generated.
This commit is contained in:
@@ -116,7 +116,7 @@ Users:
|
||||
// in worst case we would have one line per user
|
||||
for i := 1; i <= len(data); i++ {
|
||||
properties := []string{"user", "password", "inrole"}
|
||||
t := spec.PgUser{}
|
||||
t := spec.PgUser{Origin: spec.RoleOriginInfrastructure}
|
||||
for _, p := range properties {
|
||||
key := fmt.Sprintf("%s%d", p, i)
|
||||
if val, present := data[key]; !present {
|
||||
|
||||
@@ -131,6 +131,7 @@ func TestGetInfrastructureRoles(t *testing.T) {
|
||||
map[string]spec.PgUser{
|
||||
"testrole": {
|
||||
Name: "testrole",
|
||||
Origin: spec.RoleOriginInfrastructure,
|
||||
Password: "testpassword",
|
||||
MemberOf: []string{"testinrole"},
|
||||
},
|
||||
|
||||
Reference in New Issue
Block a user