allow specifiying more extra owner roles

This commit is contained in:
Felix Kunde
2022-03-04 11:01:07 +01:00
parent 89801ef30a
commit 78eaae2efc
12 changed files with 86 additions and 62 deletions
+9 -7
View File
@@ -177,12 +177,14 @@ under the `users` key.
Postgres username used for replication between instances. The default is
`standby`.
* **cron_admin_username**
Specifies the role that owns rights to set up cron jobs with `pg_cron`
extension inside the `postgres` database. The must be pre-configured in the
docker image. In Spilo this role is called `cron_admin`. This role will
become a member of all database owners so that they can set up cron jobs
e.g. as part of a migration script. Default is `empty`.
* **additional_owner_roles**
Specifies database roles that will become members of all database owners.
Then owners can use `SET ROLE` to obtain privileges of these roles to e.g.
create/update functionality from extensions as part of a migration script.
Note, that roles listed here should be preconfigured in the docker image
and already exist in the database cluster on startup. One such role can be
`cron_admin` which is provided by the Spilo docker image to set up cron
jobs inside the `postgres` database. Default is `empty`.
* **enable_password_rotation**
For all `LOGIN` roles that are not database owners the operator can rotate
@@ -755,7 +757,7 @@ key.
* **protected_role_names**
List of roles that cannot be overwritten by an application, team or
infrastructure role. The default is `admin`.
infrastructure role. The default list is `admin` and `cron_admin`.
* **postgres_superuser_teams**
List of teams which members need the superuser role in each PG database