mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-02 12:00:58 +02:00
allow users to opt out from globally enabled secret rotation (#2528)
* allow users to opt out from globally enabled secret rotation * cover new option also in e2e test * change ignore test to existing user
This commit is contained in:
@@ -355,6 +355,23 @@ This would be the recommended option to enable rotation in secrets of database
|
||||
owners, but only if they are not used as application users for regular read
|
||||
and write operations.
|
||||
|
||||
### Ignore rotation for certain users
|
||||
|
||||
If you wish to globally enable password rotation but need certain users to
|
||||
opt out from it there are two ways. First, you can remove the user from the
|
||||
manifest's `users` section. The corresponding secret to this user will no
|
||||
longer be synced by the operator then.
|
||||
|
||||
Secondly, if you want the operator to continue syncing the secret (e.g. to
|
||||
recreate if it got accidentally removed) but cannot allow it being rotated,
|
||||
add the user to the following list in your manifest:
|
||||
|
||||
```
|
||||
spec:
|
||||
usersIgnoringSecretRotation:
|
||||
- bar_user
|
||||
```
|
||||
|
||||
### Turning off password rotation
|
||||
|
||||
When password rotation is turned off again the operator will check if the
|
||||
|
||||
@@ -142,6 +142,14 @@ These parameters are grouped directly under the `spec` key in the manifest.
|
||||
database, like a flyway user running a migration on Pod start. See more
|
||||
details in the [administrator docs](https://github.com/zalando/postgres-operator/blob/master/docs/administrator.md#password-replacement-without-extra-users).
|
||||
|
||||
* **usersIgnoringSecretRotation**
|
||||
if you have secret rotation enabled globally you can define a list of
|
||||
of users that should opt out from it, for example if you store credentials
|
||||
outside of K8s, too, and corresponding deployments cannot dynamically
|
||||
reference secrets. Note, you can also opt out from the rotation by removing
|
||||
users from the manifest's `users` section. The operator will not drop them
|
||||
from the database. Optional.
|
||||
|
||||
* **databases**
|
||||
a map of database names to database owners for the databases that should be
|
||||
created by the operator. The owner users should already exist on the cluster
|
||||
|
||||
Reference in New Issue
Block a user