From 5544cd06d4635e5e0218531ec8e8a9152b817740 Mon Sep 17 00:00:00 2001 From: Felix Kunde Date: Fri, 2 Oct 2026 10:22:03 +0200 Subject: [PATCH] minor update to docs --- docs/migrate.md | 2 +- docs/user.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/migrate.md b/docs/migrate.md index 5504ffd9b..2cc83dd5f 100644 --- a/docs/migrate.md +++ b/docs/migrate.md @@ -6,7 +6,7 @@ Version 2.0 changes some default settings and removes deprecated fields. Please The v2 operator will default password encryption to `scram-sha-256`. Unless you configure `password_encryption: md5` in the manifest under `spec.postgresql.parameters` the operator will encrypt existing passwords in the managed K8s secrets with `scram-sha-256` and alter the respective database users. Make sure that your clients and drivers who rely on these credentials support `scram-sha-256` as pods will get rotated in rolling fashion after updating to Postgres Operator v2. -For backwards compatibility, the current default Spilo image (`spilo-18:4.1-p2`) still configures the pg_hba.conf file to allow `md5` passwords but Postgres will validate new `scram-sha-256` passwords correctly. This means you can switch to `scram-sha-256` for manifest users, while still allowing unmanaged users to connect via `md5`. The compatibility does not work for connections via pgBouncer that rely on `md5`. In this case you have to configure `password_encryption: md5` in the manifest. +For backwards compatibility, the current default Spilo image (`spilo-18:4.1-p2`) still configures the pg_hba.conf file to allow `md5` passwords but Postgres will validate new `scram-sha-256` passwords correctly. This means you can switch to `scram-sha-256` for manifest users, while still allowing unmanaged users to connect via `md5`. The compatibility does not work for connections via pgBouncer that rely on `md5`. In this case you have to configure `password_encryption: md5` in the manifest. Note, that changing the encryption in the manifest requires an operator restart to update the database passwords. In general, make sure to alter passwords of users that are not managed by the operator and are still `md5` encrypted before the release of next tagged Spilo image which will drop `md5` completely. diff --git a/docs/user.md b/docs/user.md index c1c2b8dc1..cbca284f7 100644 --- a/docs/user.md +++ b/docs/user.md @@ -96,7 +96,7 @@ psql -U postgres -h localhost -p 6432 ## Password encryption -Passwords are encrypted using the `scram-sha-256` hashing method by default. Other methods can be configured by changing the `password_encryption` parameter in the cluster manifest: +Passwords are encrypted using the `scram-sha-256` hashing method by default. Other methods can be configured by changing the `password_encryption` parameter in the cluster manifest (requires an operator restart): ```yaml apiVersion: "acid.zalan.do/v1"