mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-01 00:01:00 +02:00
Periodically sync roles with the running clusters. (#102)
The sync adds or alters database roles based on the roles defined in the cluster's TPR, Team API and operator's infrastructure roles. At the moment, roles are not deleted, as it would be dangerous for the robot roles in case TPR is misconfigured. In addition, ALTER ROLE does not remove role options, i.e. SUPERUSER or CREATEROLE, neither it removes role membership: only new options are added and new role membership is granted. So far, options like NOSUPERUSER and NOCREATEROLE won't be handed correctly, when mixed with the non-negative counterparts, also NOLOGIN should be processed correctly. The code assumes that only MD5 passwords are stored in the DB and will likely break with the new SCRAM auth in PostgreSQL 10. On the implementation side, create the new interface to abstract roles merge and creation, move most of the role-based functionality from cluster/pg into the new 'users' module, strip create user code of special cases related to human-based users (moving them to init instead) and fixed the password md5 generator to avoid processing already encrypted passwords. In addition, moved the system roles off the slice containing all other roles in order to avoid extra efforts to avoid creating them. Also, fix a leak in DB connections when the new connection is not considered healthy and discarded without being closed. Initialize the database during the sync phase before syncing users.
This commit is contained in:
committed by
Murat Kabilov
parent
411487e66d
commit
6983f444ed
@@ -122,7 +122,7 @@ Users:
|
||||
case "password":
|
||||
t.Password = s
|
||||
case "inrole":
|
||||
t.MemberOf = s
|
||||
t.MemberOf = append(t.MemberOf, s)
|
||||
default:
|
||||
c.logger.Warnf("Unknown key %s", p)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user