mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-09-30 07:31:34 +02:00
Skip owner references on user secrets when secret deletion is disabled (#3165)
* Skip owner references on user secrets when secret deletion is disabled Kubernetes garbage-collects owner-referenced secrets as soon as the owning Postgresql resource is deleted, regardless of the operator's own EnableSecretsDeletion check in Delete() (which only guards the operator's explicit deleteSecrets() call, not GC). This made enable_secrets_deletion=false ineffective whenever enable_owner_references was also enabled, since GC removed the credential secrets anyway. Now the generated secrets are not removed when enable_owner_references: true, enable_secrets_deletion: false. * Document skip-owner-refs on user secrets when deletion disabled - refresh inline comment in generateSingleUserSecret - extend enable_owner_references / enable_secrets_deletion docs in operator_parameters.md to describe the interaction - clarify in operator_parameters.md that the protection takes effect on the cluster's next sync after the setting is applied - add third exception in administrator.md "Owner References and Finalizers" - add TestGenerateSingleUserSecret_OwnerReferences covering all four flag combinations plus the cross-namespace cases --------- Co-authored-by: Serdar Dalgıç <sd@serdardalgic.org>
This commit is contained in:
co-authored by
Serdar Dalgıç
parent
b43c7be1d0
commit
bbc3eab7e0
@@ -289,8 +289,12 @@ configuration they are grouped under the `kubernetes` key.
|
||||
* **enable_owner_references**
|
||||
The operator can set owner references on its child resources (except PVCs,
|
||||
Patroni config service/endpoint, cross-namespace secrets) to improve cluster
|
||||
monitoring and enable cascading deletion. The default is `false`. Warning,
|
||||
enabling this option disables configured delete protection checks (see below).
|
||||
monitoring and enable cascading deletion. User-credential secrets are also
|
||||
excluded from controller owner references whenever
|
||||
[enable_secrets_deletion](#enable_secrets_deletion) is `false`, so that
|
||||
Kubernetes garbage collection does not cascade-delete them when the
|
||||
Postgresql resource is removed. The default is `false`. Warning, enabling
|
||||
this option disables configured delete protection checks (see below).
|
||||
|
||||
* **delete_annotation_date_key**
|
||||
key name for annotation that compares manifest value with current date in the
|
||||
@@ -381,7 +385,15 @@ configuration they are grouped under the `kubernetes` key.
|
||||
|
||||
* **enable_secrets_deletion**
|
||||
By default, the operator deletes secrets when removing the Postgres cluster
|
||||
manifest. To keep secrets, set this option to `false`. The default is `true`.
|
||||
manifest. To keep secrets, set this option to `false`. Note that this only
|
||||
guards the operator's own deletion logic; Kubernetes garbage collection can
|
||||
still remove user-credential secrets when
|
||||
[enable_owner_references](#enable_owner_references) is `true` because the
|
||||
Postgresql resource acts as a controller owner. To prevent that, the
|
||||
operator skips the controller owner reference on user-credential secrets
|
||||
whenever `enable_secrets_deletion` is `false`, so the two settings work
|
||||
together. This protection takes effect on the cluster's next sync after
|
||||
the setting is applied. The default is `true`.
|
||||
|
||||
* **enable_persistent_volume_claim_deletion**
|
||||
By default, the operator deletes persistent volume claims when removing the
|
||||
|
||||
Reference in New Issue
Block a user