configure pooler auth type based on parameters (#3193)

* configure pooler auth type based on parameters
* need to sync CONNECTION_POOLER_AUTH_TYPE
* add case when auth type is not yet set
* Update docs/migrate.md

Co-authored-by: Ida Novindasari <idanovinda@gmail.com>

* add type cast to only allow scram or md5

---------

Co-authored-by: Ida Novindasari <idanovinda@gmail.com>
This commit is contained in:
Felix Kunde
2026-09-30 17:07:06 +02:00
committed by GitHub
co-authored by Ida Novindasari
parent c8e0225f8f
commit 5dce164427
6 changed files with 57 additions and 15 deletions
+2 -5
View File
@@ -137,10 +137,7 @@ func New(cfg Config, kubeClient k8sutil.KubernetesClient, pgSpec acidv1.Postgres
podEventsStore := cache.NewStore(keyFn)
podEventsQueue := cache.NewFIFO(keyFn)
passwordEncryption, ok := pgSpec.Spec.PostgresqlParam.Parameters["password_encryption"]
if !ok {
passwordEncryption = "scram-sha-256"
}
passwordEncryption := passwordEncryptionFromSpec(&pgSpec.Spec)
cluster := &Cluster{
Config: cfg,
@@ -158,7 +155,7 @@ func New(cfg Config, kubeClient k8sutil.KubernetesClient, pgSpec acidv1.Postgres
Streams: make(map[string]*zalandov1.FabricEventStream),
},
userSyncStrategy: users.DefaultUserSyncStrategy{
PasswordEncryption: passwordEncryption,
PasswordEncryption: string(passwordEncryption),
RoleDeletionSuffix: cfg.OpConfig.RoleDeletionSuffix,
AdditionalOwnerRoles: cfg.OpConfig.AdditionalOwnerRoles,
},
+24
View File
@@ -253,6 +253,8 @@ func (c *Cluster) getConnectionPoolerEnvVars() []v1.EnvVar {
minSize := defaultSize / 2
reserveSize := minSize
passwordEncryption := passwordEncryptionFromSpec(spec)
return []v1.EnvVar{
{
Name: "CONNECTION_POOLER_PORT",
@@ -262,6 +264,10 @@ func (c *Cluster) getConnectionPoolerEnvVars() []v1.EnvVar {
Name: "CONNECTION_POOLER_MODE",
Value: effectiveMode,
},
{
Name: "CONNECTION_POOLER_AUTH_TYPE",
Value: string(passwordEncryption),
},
{
Name: "CONNECTION_POOLER_DEFAULT_SIZE",
Value: fmt.Sprint(defaultSize),
@@ -912,6 +918,8 @@ func (c *Cluster) needSyncConnectionPoolerDefaults(Config *Config, spec *acidv1.
return false, reasons
}
authTypeFound := false
passwordEncryption := passwordEncryptionFromSpec(&c.Spec)
for _, env := range poolerContainer.Env {
if spec.User == "" && env.Name == "PGUSER" {
ref := env.ValueFrom.SecretKeyRef.LocalObjectReference
@@ -935,6 +943,22 @@ func (c *Cluster) needSyncConnectionPoolerDefaults(Config *Config, spec *acidv1.
env.Value, config.Schema)
reasons = append(reasons, msg)
}
if env.Name == "CONNECTION_POOLER_AUTH_TYPE" {
authTypeFound = true
if string(passwordEncryption) != env.Value {
sync = true
msg := fmt.Sprintf("pooler auth type is different (having %s, required %s)",
env.Value, passwordEncryption)
reasons = append(reasons, msg)
}
}
}
// env var is missing on deployments created before it was introduced
if !authTypeFound {
sync = true
reasons = append(reasons, "pooler auth type env variable is missing")
}
return sync, reasons
+8 -7
View File
@@ -539,13 +539,14 @@ func TestCronjobEnvironmentSecretVariables(t *testing.T) {
func testEnvs(cluster *Cluster, podSpec *v1.PodTemplateSpec, role PostgresRole) error {
required := map[string]bool{
"PGHOST": false,
"PGPORT": false,
"PGUSER": false,
"PGSCHEMA": false,
"PGPASSWORD": false,
"CONNECTION_POOLER_MODE": false,
"CONNECTION_POOLER_PORT": false,
"PGHOST": false,
"PGPORT": false,
"PGUSER": false,
"PGSCHEMA": false,
"PGPASSWORD": false,
"CONNECTION_POOLER_MODE": false,
"CONNECTION_POOLER_PORT": false,
"CONNECTION_POOLER_AUTH_TYPE": false,
}
container := getPostgresContainer(&podSpec.Spec)
+18
View File
@@ -82,5 +82,23 @@ type InstallFunction func(schema string, user string) error
type SyncReason []string
// PasswordEncryption is the password hashing method used by Postgres and the pooler
type PasswordEncryption string
const (
PasswordEncryptionMD5 PasswordEncryption = "md5"
PasswordEncryptionScramSHA256 PasswordEncryption = "scram-sha-256"
)
// passwordEncryptionFromSpec returns the password_encryption parameter, falling back to scram-sha-256 for unset or unsupported values
func passwordEncryptionFromSpec(spec *acidv1.PostgresSpec) PasswordEncryption {
switch pe := PasswordEncryption(spec.PostgresqlParam.Parameters["password_encryption"]); pe {
case PasswordEncryptionMD5, PasswordEncryptionScramSHA256:
return pe
default:
return PasswordEncryptionScramSHA256
}
}
// no sync happened, empty value
var NoSync SyncReason = []string{}