mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-09-30 23:01:14 +02:00
Merge branch 'master' into api-improvements
This commit is contained in:
+6
-3
@@ -331,9 +331,12 @@ func (c *Cluster) credentialSecretName(username string) string {
|
||||
func (c *Cluster) credentialSecretNameForCluster(username string, clusterName string) string {
|
||||
// secret must consist of lower case alphanumeric characters, '-' or '.',
|
||||
// and must start and end with an alphanumeric character
|
||||
return fmt.Sprintf(constants.UserSecretTemplate,
|
||||
strings.Replace(username, "_", "-", -1),
|
||||
clusterName)
|
||||
|
||||
return c.OpConfig.SecretNameTemplate.Format(
|
||||
"username", strings.Replace(username, "_", "-", -1),
|
||||
"clustername", clusterName,
|
||||
"tprkind", constants.TPRKind,
|
||||
"tprgroup", constants.TPRGroup)
|
||||
}
|
||||
|
||||
func (c *Cluster) podSpiloRole(pod *v1.Pod) string {
|
||||
|
||||
@@ -32,6 +32,7 @@ type Resources struct {
|
||||
|
||||
// Auth describes authentication specific configuration parameters
|
||||
type Auth struct {
|
||||
SecretNameTemplate stringTemplate `name:"secret_name_template" default:"{username}.{clustername}.credentials.{tprkind}.{tprgroup}"`
|
||||
PamRoleName string `name:"pam_role_name" default:"zalandos"`
|
||||
PamConfiguration string `name:"pam_configuration" default:"https://info.example.com/oauth2/tokeninfo?access_token= uid realm=/employees"`
|
||||
TeamsAPIUrl string `name:"teams_api_url" default:"https://teams.example.com/api/"`
|
||||
|
||||
@@ -3,7 +3,6 @@ package constants
|
||||
// Roles specific constants
|
||||
const (
|
||||
PasswordLength = 64
|
||||
UserSecretTemplate = "%s.%s.credentials." + TPRKind + "." + TPRGroup // Username, ClusterName
|
||||
SuperuserKeyName = "superuser"
|
||||
ReplicationUserKeyName = "replication"
|
||||
RoleFlagSuperuser = "SUPERUSER"
|
||||
|
||||
Reference in New Issue
Block a user