define default access privileges for default users too (#1512)

* define default access privileges for default users too
* extend docs on defaultUsers
This commit is contained in:
Felix Kunde
2021-06-22 16:45:28 +02:00
committed by GitHub
parent 53fb540c35
commit 54e506c00b
3 changed files with 42 additions and 5 deletions
+6 -1
View File
@@ -522,7 +522,8 @@ The roles described in the previous paragraph can be granted to LOGIN roles from
the `users` section in the manifest. Optionally, the Postgres Operator can also
create default LOGIN roles for the database an each schema individually. These
roles will get the `_user` suffix and they inherit all rights from their NOLOGIN
counterparts.
counterparts. Therefore, you cannot have `defaultRoles` set to `false` and enable
`defaultUsers` at the same time.
| Role name | Member of | Admin |
| ------------------- | -------------- | ------------- |
@@ -545,6 +546,10 @@ spec:
defaultUsers: true
```
Default access privileges are also defined for LOGIN roles on database and
schema creation. This means they are currently not set when `defaultUsers`
(or `defaultRoles` for schemas) are enabled at a later point in time.
### Schema `search_path` for default roles
The schema [`search_path`](https://www.postgresql.org/docs/13/ddl-schemas.html#DDL-SCHEMAS-PATH)