mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-01 02:02:02 +02:00
Use encrypted passwords while creating robot users
This commit is contained in:
+4
-3
@@ -8,10 +8,11 @@ import (
|
||||
_ "github.com/lib/pq"
|
||||
|
||||
"github.bus.zalan.do/acid/postgres-operator/pkg/spec"
|
||||
"github.bus.zalan.do/acid/postgres-operator/pkg/util"
|
||||
"github.bus.zalan.do/acid/postgres-operator/pkg/util/constants"
|
||||
)
|
||||
|
||||
var createUserSQL = `SET LOCAL synchronous_commit = 'local'; CREATE ROLE "%s" %s PASSWORD %s;`
|
||||
var createUserSQL = `SET LOCAL synchronous_commit = 'local'; CREATE ROLE "%s" %s %s;`
|
||||
|
||||
func (c *Cluster) pgConnectionString() string {
|
||||
hostname := fmt.Sprintf("%s.%s.svc.cluster.local", c.Metadata.Name, c.Metadata.Namespace)
|
||||
@@ -68,9 +69,9 @@ func (c *Cluster) createPgUser(user spec.PgUser) (isHuman bool, err error) {
|
||||
}
|
||||
|
||||
userFlags := strings.Join(flags, " ")
|
||||
userPassword := fmt.Sprintf("'%s'", user.Password)
|
||||
userPassword := fmt.Sprintf("ENCRYPTED PASSWORD '%s'", util.PGUserPassword(user))
|
||||
if user.Password == "" {
|
||||
userPassword = "NULL"
|
||||
userPassword = "PASSWORD NULL"
|
||||
}
|
||||
query := fmt.Sprintf(createUserSQL, user.Name, userFlags, userPassword)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user