mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-03 00:54:06 +02:00
configure pooler auth type based on parameters (#3193)
* configure pooler auth type based on parameters * need to sync CONNECTION_POOLER_AUTH_TYPE * add case when auth type is not yet set * Update docs/migrate.md Co-authored-by: Ida Novindasari <idanovinda@gmail.com> * add type cast to only allow scram or md5 --------- Co-authored-by: Ida Novindasari <idanovinda@gmail.com>
This commit is contained in:
co-authored by
Ida Novindasari
parent
c8e0225f8f
commit
5dce164427
@@ -137,10 +137,7 @@ func New(cfg Config, kubeClient k8sutil.KubernetesClient, pgSpec acidv1.Postgres
|
||||
podEventsStore := cache.NewStore(keyFn)
|
||||
podEventsQueue := cache.NewFIFO(keyFn)
|
||||
|
||||
passwordEncryption, ok := pgSpec.Spec.PostgresqlParam.Parameters["password_encryption"]
|
||||
if !ok {
|
||||
passwordEncryption = "scram-sha-256"
|
||||
}
|
||||
passwordEncryption := passwordEncryptionFromSpec(&pgSpec.Spec)
|
||||
|
||||
cluster := &Cluster{
|
||||
Config: cfg,
|
||||
@@ -158,7 +155,7 @@ func New(cfg Config, kubeClient k8sutil.KubernetesClient, pgSpec acidv1.Postgres
|
||||
Streams: make(map[string]*zalandov1.FabricEventStream),
|
||||
},
|
||||
userSyncStrategy: users.DefaultUserSyncStrategy{
|
||||
PasswordEncryption: passwordEncryption,
|
||||
PasswordEncryption: string(passwordEncryption),
|
||||
RoleDeletionSuffix: cfg.OpConfig.RoleDeletionSuffix,
|
||||
AdditionalOwnerRoles: cfg.OpConfig.AdditionalOwnerRoles,
|
||||
},
|
||||
|
||||
@@ -253,6 +253,8 @@ func (c *Cluster) getConnectionPoolerEnvVars() []v1.EnvVar {
|
||||
minSize := defaultSize / 2
|
||||
reserveSize := minSize
|
||||
|
||||
passwordEncryption := passwordEncryptionFromSpec(spec)
|
||||
|
||||
return []v1.EnvVar{
|
||||
{
|
||||
Name: "CONNECTION_POOLER_PORT",
|
||||
@@ -262,6 +264,10 @@ func (c *Cluster) getConnectionPoolerEnvVars() []v1.EnvVar {
|
||||
Name: "CONNECTION_POOLER_MODE",
|
||||
Value: effectiveMode,
|
||||
},
|
||||
{
|
||||
Name: "CONNECTION_POOLER_AUTH_TYPE",
|
||||
Value: string(passwordEncryption),
|
||||
},
|
||||
{
|
||||
Name: "CONNECTION_POOLER_DEFAULT_SIZE",
|
||||
Value: fmt.Sprint(defaultSize),
|
||||
@@ -912,6 +918,8 @@ func (c *Cluster) needSyncConnectionPoolerDefaults(Config *Config, spec *acidv1.
|
||||
return false, reasons
|
||||
}
|
||||
|
||||
authTypeFound := false
|
||||
passwordEncryption := passwordEncryptionFromSpec(&c.Spec)
|
||||
for _, env := range poolerContainer.Env {
|
||||
if spec.User == "" && env.Name == "PGUSER" {
|
||||
ref := env.ValueFrom.SecretKeyRef.LocalObjectReference
|
||||
@@ -935,6 +943,22 @@ func (c *Cluster) needSyncConnectionPoolerDefaults(Config *Config, spec *acidv1.
|
||||
env.Value, config.Schema)
|
||||
reasons = append(reasons, msg)
|
||||
}
|
||||
|
||||
if env.Name == "CONNECTION_POOLER_AUTH_TYPE" {
|
||||
authTypeFound = true
|
||||
if string(passwordEncryption) != env.Value {
|
||||
sync = true
|
||||
msg := fmt.Sprintf("pooler auth type is different (having %s, required %s)",
|
||||
env.Value, passwordEncryption)
|
||||
reasons = append(reasons, msg)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// env var is missing on deployments created before it was introduced
|
||||
if !authTypeFound {
|
||||
sync = true
|
||||
reasons = append(reasons, "pooler auth type env variable is missing")
|
||||
}
|
||||
|
||||
return sync, reasons
|
||||
|
||||
@@ -539,13 +539,14 @@ func TestCronjobEnvironmentSecretVariables(t *testing.T) {
|
||||
|
||||
func testEnvs(cluster *Cluster, podSpec *v1.PodTemplateSpec, role PostgresRole) error {
|
||||
required := map[string]bool{
|
||||
"PGHOST": false,
|
||||
"PGPORT": false,
|
||||
"PGUSER": false,
|
||||
"PGSCHEMA": false,
|
||||
"PGPASSWORD": false,
|
||||
"CONNECTION_POOLER_MODE": false,
|
||||
"CONNECTION_POOLER_PORT": false,
|
||||
"PGHOST": false,
|
||||
"PGPORT": false,
|
||||
"PGUSER": false,
|
||||
"PGSCHEMA": false,
|
||||
"PGPASSWORD": false,
|
||||
"CONNECTION_POOLER_MODE": false,
|
||||
"CONNECTION_POOLER_PORT": false,
|
||||
"CONNECTION_POOLER_AUTH_TYPE": false,
|
||||
}
|
||||
|
||||
container := getPostgresContainer(&podSpec.Spec)
|
||||
|
||||
@@ -82,5 +82,23 @@ type InstallFunction func(schema string, user string) error
|
||||
|
||||
type SyncReason []string
|
||||
|
||||
// PasswordEncryption is the password hashing method used by Postgres and the pooler
|
||||
type PasswordEncryption string
|
||||
|
||||
const (
|
||||
PasswordEncryptionMD5 PasswordEncryption = "md5"
|
||||
PasswordEncryptionScramSHA256 PasswordEncryption = "scram-sha-256"
|
||||
)
|
||||
|
||||
// passwordEncryptionFromSpec returns the password_encryption parameter, falling back to scram-sha-256 for unset or unsupported values
|
||||
func passwordEncryptionFromSpec(spec *acidv1.PostgresSpec) PasswordEncryption {
|
||||
switch pe := PasswordEncryption(spec.PostgresqlParam.Parameters["password_encryption"]); pe {
|
||||
case PasswordEncryptionMD5, PasswordEncryptionScramSHA256:
|
||||
return pe
|
||||
default:
|
||||
return PasswordEncryptionScramSHA256
|
||||
}
|
||||
}
|
||||
|
||||
// no sync happened, empty value
|
||||
var NoSync SyncReason = []string{}
|
||||
|
||||
Reference in New Issue
Block a user