mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-04 01:32:11 +02:00
disable team member deprecation by default
This commit is contained in:
@@ -705,12 +705,18 @@ key.
|
||||
The default is empty.
|
||||
|
||||
* **role_deletion_suffix**
|
||||
defines a suffix that will be appended to database role names of team members
|
||||
that were removed from either the team in the Teams API or a `PostgresTeam`
|
||||
custom resource (additionalMembers). When re-added, the operator will rename
|
||||
roles with the defined suffix back to the original role name.
|
||||
defines a suffix that - when `enable_team_member_deprecation` is set to
|
||||
`true` - will be appended to database role names of team members that were
|
||||
removed from either the team in the Teams API or a `PostgresTeam` custom
|
||||
resource (additionalMembers). When re-added, the operator will rename roles
|
||||
with the defined suffix back to the original role name.
|
||||
The default is `_deleted`.
|
||||
|
||||
* **enable_team_member_deprecation**
|
||||
if `true` database roles of former team members will be renamed by appending
|
||||
the configured `role_deletion_suffix` and `LOGIN` privilege will be revoked.
|
||||
The default is `false`.
|
||||
|
||||
* **enable_postgres_team_crd**
|
||||
toggle to make the operator watch for created or updated `PostgresTeam` CRDs
|
||||
and create roles for specified additional teams and members.
|
||||
|
||||
+3
-2
@@ -413,10 +413,11 @@ The Postgres Operator does not delete database roles when users are removed
|
||||
from manifests. But, using the `PostgresTeam` custom resource or Teams API it
|
||||
is very easy to add roles to many clusters. Manually reverting such a change
|
||||
is cumbersome. Therefore, if members are removed from a `PostgresTeam` or the
|
||||
Teams API the operator will rename roles appending a configured suffix to the
|
||||
Teams API the operator can rename roles appending a configured suffix to the
|
||||
name (see `role_deletion_suffix` option) and revoke the `LOGIN` privilege.
|
||||
The suffix makes it easy then for a cleanup script to remove those deprecated
|
||||
roles completely.
|
||||
roles completely. Switch `enable_team_member_deprecation` to `true` to enable
|
||||
this behavior.
|
||||
|
||||
When a role is re-added to a `PostgresTeam` manifest (or to the source behind
|
||||
the Teams API) the operator will check for roles with the configured suffix
|
||||
|
||||
Reference in New Issue
Block a user