mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-01 12:51:36 +02:00
define default access privileges for default users too (#1512)
* define default access privileges for default users too * extend docs on defaultUsers
This commit is contained in:
+6
-1
@@ -522,7 +522,8 @@ The roles described in the previous paragraph can be granted to LOGIN roles from
|
||||
the `users` section in the manifest. Optionally, the Postgres Operator can also
|
||||
create default LOGIN roles for the database an each schema individually. These
|
||||
roles will get the `_user` suffix and they inherit all rights from their NOLOGIN
|
||||
counterparts.
|
||||
counterparts. Therefore, you cannot have `defaultRoles` set to `false` and enable
|
||||
`defaultUsers` at the same time.
|
||||
|
||||
| Role name | Member of | Admin |
|
||||
| ------------------- | -------------- | ------------- |
|
||||
@@ -545,6 +546,10 @@ spec:
|
||||
defaultUsers: true
|
||||
```
|
||||
|
||||
Default access privileges are also defined for LOGIN roles on database and
|
||||
schema creation. This means they are currently not set when `defaultUsers`
|
||||
(or `defaultRoles` for schemas) are enabled at a later point in time.
|
||||
|
||||
### Schema `search_path` for default roles
|
||||
|
||||
The schema [`search_path`](https://www.postgresql.org/docs/13/ddl-schemas.html#DDL-SCHEMAS-PATH)
|
||||
|
||||
Reference in New Issue
Block a user