mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-04 23:21:43 +02:00
grant db owners to cron_admin
This commit is contained in:
@@ -228,6 +228,8 @@ func (c *Cluster) initUsers() error {
|
||||
return fmt.Errorf("could not init human users: %v", err)
|
||||
}
|
||||
|
||||
c.initCronAdmin()
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -1297,6 +1299,40 @@ func (c *Cluster) initRobotUsers() error {
|
||||
return nil
|
||||
}
|
||||
|
||||
func (c *Cluster) initCronAdmin() {
|
||||
cronAdminName := c.OpConfig.CronAdminUsername
|
||||
if cronAdminName == "" {
|
||||
return
|
||||
}
|
||||
memberOf := make([]string, 0)
|
||||
for username, pgUser := range c.pgUsers {
|
||||
if pgUser.IsDbOwner {
|
||||
memberOf = append(memberOf, username)
|
||||
}
|
||||
}
|
||||
|
||||
if len(memberOf) > 1 {
|
||||
namespace := c.Namespace
|
||||
adminRole := ""
|
||||
if c.OpConfig.EnableAdminRoleForUsers && cronAdminName != c.OpConfig.TeamAdminRole {
|
||||
adminRole = c.OpConfig.TeamAdminRole
|
||||
}
|
||||
cronAdmin := spec.PgUser{
|
||||
Origin: spec.RoleOriginSpilo,
|
||||
MemberOf: memberOf,
|
||||
Name: cronAdminName,
|
||||
Namespace: namespace,
|
||||
Flags: []string{constants.RoleFlagNoLogin},
|
||||
AdminRole: adminRole,
|
||||
}
|
||||
if currentRole, present := c.pgUsers[cronAdminName]; present {
|
||||
c.pgUsers[cronAdminName] = c.resolveNameConflict(¤tRole, &cronAdmin)
|
||||
} else {
|
||||
c.pgUsers[cronAdminName] = cronAdmin
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func (c *Cluster) initTeamMembers(teamID string, isPostgresSuperuserTeam bool) error {
|
||||
teamMembers, err := c.getTeamMembers(teamID)
|
||||
|
||||
|
||||
@@ -1622,7 +1622,7 @@ func (c *Cluster) generateUserSecrets() map[string]*v1.Secret {
|
||||
func (c *Cluster) generateSingleUserSecret(namespace string, pgUser spec.PgUser) *v1.Secret {
|
||||
//Skip users with no password i.e. human users (they'll be authenticated using pam)
|
||||
if pgUser.Password == "" {
|
||||
if pgUser.Origin != spec.RoleOriginTeamsAPI {
|
||||
if pgUser.Origin != spec.RoleOriginTeamsAPI && pgUser.Origin != spec.RoleOriginSpilo {
|
||||
c.logger.Warningf("could not generate secret for a non-teamsAPI role %q: role has no password",
|
||||
pgUser.Name)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user