rename suffix and pgUser field

This commit is contained in:
Felix Kunde
2021-05-17 12:11:36 +02:00
parent 044e92a609
commit 8d58ceb339
18 changed files with 42 additions and 41 deletions
+2 -2
View File
@@ -704,12 +704,12 @@ key.
cluster to administer Postgres and maintain infrastructure built around it.
The default is empty.
* **role_deprecation_suffix**
* **role_deletion_suffix**
defines a suffix that will be appended to database role names of team members
that were removed from either the team in the Teams API or a `PostgresTeam`
custom resource (additionalMembers). When re-added, the operator will rename
roles with the defined suffix back to the original role name.
The default is `_delete_me`.
The default is `_deleted`.
* **enable_postgres_team_crd**
toggle to make the operator watch for created or updated `PostgresTeam` CRDs
+4 -3
View File
@@ -414,13 +414,14 @@ from manifests. But, using the `PostgresTeam` custom resource or Teams API it
is very easy to add roles to many clusters. Manually reverting such a change
is cumbersome. Therefore, if members are removed from a `PostgresTeam` or the
Teams API the operator will rename roles appending a configured suffix to the
name (see `role_deprecation_suffix` option) and revoke the `LOGIN` privilege.
name (see `role_deletion_suffix` option) and revoke the `LOGIN` privilege.
The suffix makes it easy then for a cleanup script to remove those deprecated
roles completely.
When a role is re-added to a PostgresTeam manifest (or to the source behind
When a role is re-added to a `PostgresTeam` manifest (or to the source behind
the Teams API) the operator will check for roles with the configured suffix
and if found, rename the role back to the original name and grant LOGIN again.
and if found, rename the role back to the original name and grant `LOGIN`
again.
## Prepared databases with roles and default privileges