mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-01 12:10:30 +02:00
configure pooler auth type based on parameters (#3193)
* configure pooler auth type based on parameters * need to sync CONNECTION_POOLER_AUTH_TYPE * add case when auth type is not yet set * Update docs/migrate.md Co-authored-by: Ida Novindasari <idanovinda@gmail.com> * add type cast to only allow scram or md5 --------- Co-authored-by: Ida Novindasari <idanovinda@gmail.com>
This commit is contained in:
co-authored by
Ida Novindasari
parent
c8e0225f8f
commit
5dce164427
+4
-2
@@ -4,9 +4,11 @@ Version 2.0 changes some default settings and removes deprecated fields. Please
|
||||
|
||||
## scram-sha-256 by default
|
||||
|
||||
The new operator will default password encryption to `scram-sha-256`. Unless you configure `password_encryption: md5` in the manifest under `spec.postgresql.parameters` the operator will encrypt existing passwords in the secrets with `scram-sha-256` and alter the database passwords. Make sure that your used clients and drivers support `scram-sha-256` as pods will get rotated in rolling fashion after updating to Postgres Operator v2.
|
||||
The v2 operator will default password encryption to `scram-sha-256`. Unless you configure `password_encryption: md5` in the manifest under `spec.postgresql.parameters` the operator will encrypt existing passwords in the managed K8s secrets with `scram-sha-256` and alter the respective database users. Make sure that your clients and drivers who rely on these credentials support `scram-sha-256` as pods will get rotated in rolling fashion after updating to Postgres Operator v2.
|
||||
|
||||
The default Spilo image (`spilo-18:4.1-p2`) still configures the pg_hba.conf file to allow `md5` passwords but Postgres will validate `scram-sha-256` passwords correctly. Passwords of users that are not managed by the operator and are still `md5` encrypted need be altered before the next tagged Spilo image which will drop `md5` completely.
|
||||
For backwards compatibility, the current default Spilo image (`spilo-18:4.1-p2`) still configures the pg_hba.conf file to allow `md5` passwords but Postgres will validate new `scram-sha-256` passwords correctly. This means you can switch to `scram-sha-256` for manifest users, while still allowing unmanaged users to connect via `md5`. The compatibility does not work for connections via pgBouncer that rely on `md5`. In this case you have to configure `password_encryption: md5` in the manifest.
|
||||
|
||||
In general, make sure to alter passwords of users that are not managed by the operator and are still `md5` encrypted before the release of next tagged Spilo image which will drop `md5` completely.
|
||||
|
||||
## K8s Endpoints are deprecated
|
||||
|
||||
|
||||
Reference in New Issue
Block a user