mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-04 23:16:22 +02:00
Feature/infrastructure roles (#91)
* Add infrastructure roles configured globally. Those are the roles defined in the operator itself. The operator's configuration refers to the secret containing role names, passwords and membership information. While they are referred to as roles, in reality those are users. In addition, improve the regex to filter out invalid users and make sure user secret names are compatible with DNS name spec. Add an example manifest for the infrastructure roles.
This commit is contained in:
committed by
Murat Kabilov
parent
b8fba429df
commit
71b93b4cc2
@@ -24,12 +24,13 @@ type Resources struct {
|
||||
}
|
||||
|
||||
type Auth struct {
|
||||
PamRoleName string `split_words:"true" default:"zalandos"`
|
||||
PamConfiguration string `split_words:"true" default:"https://info.example.com/oauth2/tokeninfo?access_token= uid realm=/employees"`
|
||||
TeamsAPIUrl string `envconfig:"teams_api_url" default:"https://teams.example.com/api/"`
|
||||
OAuthTokenSecretName string `envconfig:"oauth_token_secret_name" default:"postgresql-operator"`
|
||||
SuperUsername string `split_words:"true" default:"postgres"`
|
||||
ReplicationUsername string `split_words:"true" default:"replication"`
|
||||
PamRoleName string `split_words:"true" default:"zalandos"`
|
||||
PamConfiguration string `split_words:"true" default:"https://info.example.com/oauth2/tokeninfo?access_token= uid realm=/employees"`
|
||||
TeamsAPIUrl string `envconfig:"teams_api_url" default:"https://teams.example.com/api/"`
|
||||
OAuthTokenSecretName string `envconfig:"oauth_token_secret_name" default:"postgresql-operator"`
|
||||
InfrastructureRolesSecretName string `split_words:"true"`
|
||||
SuperUsername string `split_words:"true" default:"postgres"`
|
||||
ReplicationUsername string `split_words:"true" default:"replication"`
|
||||
}
|
||||
|
||||
type Config struct {
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
package teams
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"strings"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"net/http"
|
||||
"strings"
|
||||
|
||||
"github.com/Sirupsen/logrus"
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user