mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-04 02:51:46 +02:00
@@ -1578,7 +1578,7 @@ make docker
|
||||
|
||||
# build in image in minikube docker env
|
||||
eval $(minikube docker-env)
|
||||
docker buildx build --load -t ghcr.io/zalando/postgres-operator-ui:v2.0.2 .
|
||||
docker buildx build --load -t ghcr.io/zalando/postgres-operator-ui:v2.0.3 .
|
||||
|
||||
# apply UI manifests next to a running Postgres Operator
|
||||
kubectl apply -f manifests/
|
||||
|
||||
+1
-1
@@ -6,7 +6,7 @@ Version 2.0 changes some default settings and removes deprecated fields. Please
|
||||
|
||||
The v2 operator will default password encryption to `scram-sha-256`. Unless you configure `password_encryption: md5` in the manifest under `spec.postgresql.parameters` the operator will encrypt existing passwords in the managed K8s secrets with `scram-sha-256` and alter the respective database users. Make sure that your clients and drivers who rely on these credentials support `scram-sha-256` as pods will get rotated in rolling fashion after updating to Postgres Operator v2.
|
||||
|
||||
For backwards compatibility, the current default Spilo image (`spilo-18:4.1-p2`) still configures the pg_hba.conf file to allow `md5` passwords but Postgres will validate new `scram-sha-256` passwords correctly. This means you can switch to `scram-sha-256` for manifest users, while still allowing unmanaged users to connect via `md5`. The compatibility does not work for connections via pgBouncer that rely on `md5`. In this case you have to configure `password_encryption: md5` in the manifest.
|
||||
For backwards compatibility, the current default Spilo image (`spilo-18:4.1-p2`) still configures the pg_hba.conf file to allow `md5` passwords but Postgres will validate new `scram-sha-256` passwords correctly. This means you can switch to `scram-sha-256` for manifest users, while still allowing unmanaged users to connect via `md5`. The compatibility does not work for connections via pgBouncer that rely on `md5`. In this case you have to configure `password_encryption: md5` in the manifest. Note, that changing the encryption in the manifest requires an operator restart to update the database passwords.
|
||||
|
||||
In general, make sure to alter passwords of users that are not managed by the operator and are still `md5` encrypted before the release of next tagged Spilo image which will drop `md5` completely.
|
||||
|
||||
|
||||
@@ -853,7 +853,7 @@ grouped under the `logical_backup` key.
|
||||
runs `pg_dumpall` on a replica if possible and uploads compressed results to
|
||||
an S3 bucket under the key `/<configured-s3-bucket-prefix>/<pg_cluster_name>/<cluster_k8s_uuid>/logical_backups`.
|
||||
The default image is the same image built with the Zalando-internal CI
|
||||
pipeline. Default: "ghcr.io/zalando/postgres-operator/logical-backup:v2.0.2"
|
||||
pipeline. Default: "ghcr.io/zalando/postgres-operator/logical-backup:v2.0.3"
|
||||
|
||||
* **logical_backup_google_application_credentials**
|
||||
Specifies the path of the google cloud service account json file. Default is empty.
|
||||
@@ -1094,7 +1094,7 @@ operator being able to provide some reasonable defaults.
|
||||
|
||||
* **connection_pooler_image**
|
||||
Docker image to use for connection pooler deployment.
|
||||
Default: "ghcr.io/zalando/postgres-operator/pgbouncer:v2.0.2"
|
||||
Default: "ghcr.io/zalando/postgres-operator/pgbouncer:v2.0.3"
|
||||
|
||||
* **connection_pooler_max_db_connections**
|
||||
How many connections the pooler can max hold. This value is divided among the
|
||||
|
||||
+1
-1
@@ -96,7 +96,7 @@ psql -U postgres -h localhost -p 6432
|
||||
|
||||
## Password encryption
|
||||
|
||||
Passwords are encrypted using the `scram-sha-256` hashing method by default. Other methods can be configured by changing the `password_encryption` parameter in the cluster manifest:
|
||||
Passwords are encrypted using the `scram-sha-256` hashing method by default. Other methods can be configured by changing the `password_encryption` parameter in the cluster manifest (requires an operator restart):
|
||||
|
||||
```yaml
|
||||
apiVersion: "acid.zalan.do/v1"
|
||||
|
||||
Reference in New Issue
Block a user