mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-03 03:45:52 +02:00
Merge branch 'master' into fix/logical-backup-job-cleanup
This commit is contained in:
@@ -748,6 +748,18 @@ var OperatorConfigCRDResourceValidation = apiextv1.CustomResourceValidation{
|
||||
"enable_replica_pooler_load_balancer": {
|
||||
Type: "boolean",
|
||||
},
|
||||
"enable_master_node_port": {
|
||||
Type: "boolean",
|
||||
},
|
||||
"enable_master_pooler_node_port": {
|
||||
Type: "boolean",
|
||||
},
|
||||
"enable_replica_node_port": {
|
||||
Type: "boolean",
|
||||
},
|
||||
"enable_replica_pooler_node_port": {
|
||||
Type: "boolean",
|
||||
},
|
||||
"external_traffic_policy": {
|
||||
Type: "string",
|
||||
Enum: []apiextv1.JSON{
|
||||
|
||||
@@ -137,17 +137,24 @@ type OperatorTimeouts struct {
|
||||
|
||||
// LoadBalancerConfiguration defines the LB configuration
|
||||
type LoadBalancerConfiguration struct {
|
||||
DbHostedZone string `json:"db_hosted_zone,omitempty"`
|
||||
EnableMasterLoadBalancer bool `json:"enable_master_load_balancer,omitempty"`
|
||||
EnableMasterPoolerLoadBalancer bool `json:"enable_master_pooler_load_balancer,omitempty"`
|
||||
EnableReplicaLoadBalancer bool `json:"enable_replica_load_balancer,omitempty"`
|
||||
EnableReplicaPoolerLoadBalancer bool `json:"enable_replica_pooler_load_balancer,omitempty"`
|
||||
CustomServiceAnnotations map[string]string `json:"custom_service_annotations,omitempty"`
|
||||
MasterDNSNameFormat config.StringTemplate `json:"master_dns_name_format,omitempty"`
|
||||
MasterLegacyDNSNameFormat config.StringTemplate `json:"master_legacy_dns_name_format,omitempty"`
|
||||
ReplicaDNSNameFormat config.StringTemplate `json:"replica_dns_name_format,omitempty"`
|
||||
ReplicaLegacyDNSNameFormat config.StringTemplate `json:"replica_legacy_dns_name_format,omitempty"`
|
||||
ExternalTrafficPolicy string `json:"external_traffic_policy" default:"Cluster"`
|
||||
DbHostedZone string `json:"db_hosted_zone,omitempty"`
|
||||
EnableMasterLoadBalancer bool `json:"enable_master_load_balancer,omitempty"`
|
||||
EnableMasterPoolerLoadBalancer bool `json:"enable_master_pooler_load_balancer,omitempty"`
|
||||
EnableReplicaLoadBalancer bool `json:"enable_replica_load_balancer,omitempty"`
|
||||
EnableReplicaPoolerLoadBalancer bool `json:"enable_replica_pooler_load_balancer,omitempty"`
|
||||
|
||||
// kept in LoadBalancerConfiguration because all the other parameters apply here too
|
||||
EnableMasterNodePort bool `json:"enable_master_node_port,omitempty"`
|
||||
EnableMasterPoolerNodePort bool `json:"enable_master_pooler_node_port,omitempty"`
|
||||
EnableReplicaNodePort bool `json:"enable_replica_node_port,omitempty"`
|
||||
EnableReplicaPoolerNodePort bool `json:"enable_replica_pooler_node_port,omitempty"`
|
||||
|
||||
CustomServiceAnnotations map[string]string `json:"custom_service_annotations,omitempty"`
|
||||
MasterDNSNameFormat config.StringTemplate `json:"master_dns_name_format,omitempty"`
|
||||
MasterLegacyDNSNameFormat config.StringTemplate `json:"master_legacy_dns_name_format,omitempty"`
|
||||
ReplicaDNSNameFormat config.StringTemplate `json:"replica_dns_name_format,omitempty"`
|
||||
ReplicaLegacyDNSNameFormat config.StringTemplate `json:"replica_legacy_dns_name_format,omitempty"`
|
||||
ExternalTrafficPolicy string `json:"external_traffic_policy" default:"Cluster"`
|
||||
}
|
||||
|
||||
// AWSGCPConfiguration defines the configuration for AWS
|
||||
@@ -168,8 +175,8 @@ type AWSGCPConfiguration struct {
|
||||
|
||||
// OperatorDebugConfiguration defines options for the debug mode
|
||||
type OperatorDebugConfiguration struct {
|
||||
DebugLogging bool `json:"debug_logging,omitempty"`
|
||||
EnableDBAccess bool `json:"enable_database_access,omitempty"`
|
||||
DebugLogging *bool `json:"debug_logging,omitempty"`
|
||||
EnableDBAccess *bool `json:"enable_database_access,omitempty"`
|
||||
}
|
||||
|
||||
// TeamsAPIConfiguration defines the configuration of TeamsAPI
|
||||
|
||||
@@ -108,7 +108,7 @@ spec:
|
||||
description: load balancers' source ranges are the same for master
|
||||
and replica services
|
||||
items:
|
||||
pattern: ^(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\/(\d|[1-2]\d|3[0-2])$
|
||||
pattern: ^((\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\/(\d|[1-2]\d|3[0-2])|(([0-9a-fA-F]{1,4}:){7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:))\/(12[0-8]|1[01][0-9]|[1-9]?[0-9]))$
|
||||
type: string
|
||||
nullable: true
|
||||
type: array
|
||||
@@ -274,14 +274,26 @@ spec:
|
||||
vars that enable load balancers are pointers because it is important to know if any of them is omitted from the Postgres manifest
|
||||
in that case the var evaluates to nil and the value is taken from the operator config
|
||||
type: boolean
|
||||
enableMasterNodePort:
|
||||
description: |-
|
||||
vars to enable and configure nodeport services
|
||||
set ports to 0 or nil to let kubernetes decide which port to use
|
||||
overrides loadbalancer configuration
|
||||
type: boolean
|
||||
enableMasterPoolerLoadBalancer:
|
||||
type: boolean
|
||||
enableMasterPoolerNodePort:
|
||||
type: boolean
|
||||
enableReplicaConnectionPooler:
|
||||
type: boolean
|
||||
enableReplicaLoadBalancer:
|
||||
type: boolean
|
||||
enableReplicaNodePort:
|
||||
type: boolean
|
||||
enableReplicaPoolerLoadBalancer:
|
||||
type: boolean
|
||||
enableReplicaPoolerNodePort:
|
||||
type: boolean
|
||||
enableShmVolume:
|
||||
type: boolean
|
||||
env:
|
||||
@@ -3409,6 +3421,12 @@ spec:
|
||||
pattern: '^\ *((Mon|Tue|Wed|Thu|Fri|Sat|Sun):(2[0-3]|[01]?\d):([0-5]?\d)|(2[0-3]|[01]?\d):([0-5]?\d))-((2[0-3]|[01]?\d):([0-5]?\d)|(2[0-3]|[01]?\d):([0-5]?\d))\ *$'
|
||||
type: string
|
||||
type: array
|
||||
masterNodePort:
|
||||
format: int32
|
||||
type: integer
|
||||
masterPoolerNodePort:
|
||||
format: int32
|
||||
type: integer
|
||||
masterServiceAnnotations:
|
||||
additionalProperties:
|
||||
type: string
|
||||
@@ -3713,6 +3731,12 @@ spec:
|
||||
replicaLoadBalancer:
|
||||
description: deprecated
|
||||
type: boolean
|
||||
replicaNodePort:
|
||||
format: int32
|
||||
type: integer
|
||||
replicaPoolerNodePort:
|
||||
format: int32
|
||||
type: integer
|
||||
replicaServiceAnnotations:
|
||||
additionalProperties:
|
||||
type: string
|
||||
|
||||
@@ -63,6 +63,18 @@ type PostgresSpec struct {
|
||||
EnableReplicaLoadBalancer *bool `json:"enableReplicaLoadBalancer,omitempty"`
|
||||
EnableReplicaPoolerLoadBalancer *bool `json:"enableReplicaPoolerLoadBalancer,omitempty"`
|
||||
|
||||
// vars to enable and configure nodeport services
|
||||
// set ports to 0 or nil to let kubernetes decide which port to use
|
||||
// overrides loadbalancer configuration
|
||||
EnableMasterNodePort *bool `json:"enableMasterNodePort,omitempty"`
|
||||
MasterNodePort *int32 `json:"masterNodePort,omitempty"`
|
||||
EnableMasterPoolerNodePort *bool `json:"enableMasterPoolerNodePort,omitempty"`
|
||||
MasterPoolerNodePort *int32 `json:"masterPoolerNodePort,omitempty"`
|
||||
EnableReplicaNodePort *bool `json:"enableReplicaNodePort,omitempty"`
|
||||
ReplicaNodePort *int32 `json:"replicaNodePort,omitempty"`
|
||||
EnableReplicaPoolerNodePort *bool `json:"enableReplicaPoolerNodePort,omitempty"`
|
||||
ReplicaPoolerNodePort *int32 `json:"replicaPoolerNodePort,omitempty"`
|
||||
|
||||
// deprecated load balancer settings maintained for backward compatibility
|
||||
// see "Load balancers" operator docs
|
||||
UseLoadBalancer *bool `json:"useLoadBalancer,omitempty"`
|
||||
@@ -71,7 +83,7 @@ type PostgresSpec struct {
|
||||
|
||||
// load balancers' source ranges are the same for master and replica services
|
||||
// +nullable
|
||||
// +kubebuilder:validation:items:Pattern=`^(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\/(\d|[1-2]\d|3[0-2])$`
|
||||
// +kubebuilder:validation:items:Pattern=`^((\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\/(\d|[1-2]\d|3[0-2])|(([0-9a-fA-F]{1,4}:){7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:))\/(12[0-8]|1[01][0-9]|[1-9]?[0-9]))$`
|
||||
// +optional
|
||||
AllowedSourceRanges []string `json:"allowedSourceRanges"`
|
||||
|
||||
|
||||
@@ -5,6 +5,7 @@ import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"reflect"
|
||||
"regexp"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
@@ -810,3 +811,47 @@ func TestPostgresqlClone(t *testing.T) {
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestAllowedSourceRangesPattern(t *testing.T) {
|
||||
// pattern used in CRD validation for allowedSourceRanges
|
||||
pattern := `^((\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\.(\d|[1-9]\d|1\d\d|2[0-4]\d|25[0-5])\/(\d|[1-2]\d|3[0-2])|(([0-9a-fA-F]{1,4}:){7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:))\/(12[0-8]|1[01][0-9]|[1-9]?[0-9]))$`
|
||||
re := regexp.MustCompile(pattern)
|
||||
|
||||
valid := []string{
|
||||
// IPv4
|
||||
"192.168.1.0/24",
|
||||
"0.0.0.0/0",
|
||||
"127.0.0.1/32",
|
||||
"10.0.0.0/8",
|
||||
"185.85.220.0/22",
|
||||
// IPv6
|
||||
"fd01::/48",
|
||||
"::1/128",
|
||||
"::/0",
|
||||
"2001:db8::/32",
|
||||
"fe80::1/64",
|
||||
"2001:0db8:85a3:0000:0000:8a2e:0370:7334/128",
|
||||
}
|
||||
|
||||
invalid := []string{
|
||||
"999.999.999.999/24",
|
||||
"192.168.1.0/33",
|
||||
"192.168.1.0",
|
||||
"not-an-ip",
|
||||
"fd01::/129",
|
||||
"::gggg/64",
|
||||
"",
|
||||
}
|
||||
|
||||
for _, cidr := range valid {
|
||||
if !re.MatchString(cidr) {
|
||||
t.Errorf("expected %q to match allowedSourceRanges pattern", cidr)
|
||||
}
|
||||
}
|
||||
|
||||
for _, cidr := range invalid {
|
||||
if re.MatchString(cidr) {
|
||||
t.Errorf("expected %q NOT to match allowedSourceRanges pattern", cidr)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -476,7 +476,7 @@ func (in *OperatorConfigurationData) DeepCopyInto(out *OperatorConfigurationData
|
||||
out.Timeouts = in.Timeouts
|
||||
in.LoadBalancer.DeepCopyInto(&out.LoadBalancer)
|
||||
out.AWSGCP = in.AWSGCP
|
||||
out.OperatorDebug = in.OperatorDebug
|
||||
in.OperatorDebug.DeepCopyInto(&out.OperatorDebug)
|
||||
in.TeamsAPI.DeepCopyInto(&out.TeamsAPI)
|
||||
out.LoggingRESTAPI = in.LoggingRESTAPI
|
||||
out.Scalyr = in.Scalyr
|
||||
@@ -532,6 +532,16 @@ func (in *OperatorConfigurationList) DeepCopyObject() runtime.Object {
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *OperatorDebugConfiguration) DeepCopyInto(out *OperatorDebugConfiguration) {
|
||||
*out = *in
|
||||
if in.DebugLogging != nil {
|
||||
in, out := &in.DebugLogging, &out.DebugLogging
|
||||
*out = new(bool)
|
||||
**out = **in
|
||||
}
|
||||
if in.EnableDBAccess != nil {
|
||||
in, out := &in.EnableDBAccess, &out.EnableDBAccess
|
||||
*out = new(bool)
|
||||
**out = **in
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
@@ -725,6 +735,46 @@ func (in *PostgresSpec) DeepCopyInto(out *PostgresSpec) {
|
||||
*out = new(bool)
|
||||
**out = **in
|
||||
}
|
||||
if in.EnableMasterNodePort != nil {
|
||||
in, out := &in.EnableMasterNodePort, &out.EnableMasterNodePort
|
||||
*out = new(bool)
|
||||
**out = **in
|
||||
}
|
||||
if in.MasterNodePort != nil {
|
||||
in, out := &in.MasterNodePort, &out.MasterNodePort
|
||||
*out = new(int32)
|
||||
**out = **in
|
||||
}
|
||||
if in.EnableMasterPoolerNodePort != nil {
|
||||
in, out := &in.EnableMasterPoolerNodePort, &out.EnableMasterPoolerNodePort
|
||||
*out = new(bool)
|
||||
**out = **in
|
||||
}
|
||||
if in.MasterPoolerNodePort != nil {
|
||||
in, out := &in.MasterPoolerNodePort, &out.MasterPoolerNodePort
|
||||
*out = new(int32)
|
||||
**out = **in
|
||||
}
|
||||
if in.EnableReplicaNodePort != nil {
|
||||
in, out := &in.EnableReplicaNodePort, &out.EnableReplicaNodePort
|
||||
*out = new(bool)
|
||||
**out = **in
|
||||
}
|
||||
if in.ReplicaNodePort != nil {
|
||||
in, out := &in.ReplicaNodePort, &out.ReplicaNodePort
|
||||
*out = new(int32)
|
||||
**out = **in
|
||||
}
|
||||
if in.EnableReplicaPoolerNodePort != nil {
|
||||
in, out := &in.EnableReplicaPoolerNodePort, &out.EnableReplicaPoolerNodePort
|
||||
*out = new(bool)
|
||||
**out = **in
|
||||
}
|
||||
if in.ReplicaPoolerNodePort != nil {
|
||||
in, out := &in.ReplicaPoolerNodePort, &out.ReplicaPoolerNodePort
|
||||
*out = new(int32)
|
||||
**out = **in
|
||||
}
|
||||
if in.UseLoadBalancer != nil {
|
||||
in, out := &in.UseLoadBalancer, &out.UseLoadBalancer
|
||||
*out = new(bool)
|
||||
|
||||
Reference in New Issue
Block a user