allow specifiying more extra owner roles

This commit is contained in:
Felix Kunde
2022-03-04 11:01:07 +01:00
parent 89801ef30a
commit 78eaae2efc
12 changed files with 86 additions and 62 deletions
@@ -130,8 +130,11 @@ spec:
users:
type: object
properties:
cron_admin_username:
type: string
additional_owner_roles:
type: array
nullable: true
items:
type: string
enable_password_rotation:
type: boolean
default: false
@@ -502,6 +505,7 @@ spec:
type: string
default:
- admin
- cron_admin
role_deletion_suffix:
type: string
default: "_deleted"
+5 -2
View File
@@ -59,8 +59,10 @@ configGeneral:
# parameters describing Postgres users
configUsers:
# username used to grant rights to set up and maintain cron jobs to database owners
cron_admin_username: cron_admin
# roles to be granted to database owners
# additional_owner_roles:
# - cron_admin
# enable password rotation for app users that are not database owners
enable_password_rotation: false
# rotation interval for updating credentials in K8s secrets of app users
@@ -346,6 +348,7 @@ configTeamsApi:
# List of roles that cannot be overwritten by an application, team or infrastructure role
protected_role_names:
- admin
- cron_admin
# Suffix to add if members are removed from TeamsAPI or PostgresTeam CRD
role_deletion_suffix: "_deleted"
# role name to grant to team members created from the Teams API