mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-09-30 19:31:23 +02:00
[WIP] Add 'admin' option to create role (#425)
* Add 'admin' option to create role * Fix run_locally_script
This commit is contained in:
@@ -709,11 +709,16 @@ func (c *Cluster) initRobotUsers() error {
|
||||
if err != nil {
|
||||
return fmt.Errorf("invalid flags for user %q: %v", username, err)
|
||||
}
|
||||
adminRole := ""
|
||||
if c.OpConfig.EnableAdminRoleForUsers {
|
||||
adminRole = c.OpConfig.TeamAdminRole
|
||||
}
|
||||
newRole := spec.PgUser{
|
||||
Origin: spec.RoleOriginManifest,
|
||||
Name: username,
|
||||
Password: util.RandomPassword(constants.PasswordLength),
|
||||
Flags: flags,
|
||||
Origin: spec.RoleOriginManifest,
|
||||
Name: username,
|
||||
Password: util.RandomPassword(constants.PasswordLength),
|
||||
Flags: flags,
|
||||
AdminRole: adminRole,
|
||||
}
|
||||
if currentRole, present := c.pgUsers[username]; present {
|
||||
c.pgUsers[username] = c.resolveNameConflict(¤tRole, &newRole)
|
||||
|
||||
@@ -49,6 +49,7 @@ type PgUser struct {
|
||||
Flags []string `yaml:"user_flags"`
|
||||
MemberOf []string `yaml:"inrole"`
|
||||
Parameters map[string]string `yaml:"db_parameters"`
|
||||
AdminRole string `yaml:"admin_role"`
|
||||
}
|
||||
|
||||
// PgUserMap maps user names to the definitions.
|
||||
|
||||
@@ -90,6 +90,7 @@ type Config struct {
|
||||
EnableTeamsAPI bool `name:"enable_teams_api" default:"true"`
|
||||
EnableTeamSuperuser bool `name:"enable_team_superuser" default:"false"`
|
||||
TeamAdminRole string `name:"team_admin_role" default:"admin"`
|
||||
EnableAdminRoleForUsers bool `name:"enable_admin_role_for_users" default:"true"`
|
||||
EnableMasterLoadBalancer bool `name:"enable_master_load_balancer" default:"true"`
|
||||
EnableReplicaLoadBalancer bool `name:"enable_replica_load_balancer" default:"false"`
|
||||
// deprecated and kept for backward compatibility
|
||||
|
||||
@@ -5,9 +5,10 @@ import (
|
||||
"fmt"
|
||||
"strings"
|
||||
|
||||
"reflect"
|
||||
|
||||
"github.com/zalando-incubator/postgres-operator/pkg/spec"
|
||||
"github.com/zalando-incubator/postgres-operator/pkg/util"
|
||||
"reflect"
|
||||
)
|
||||
|
||||
const (
|
||||
@@ -19,6 +20,7 @@ const (
|
||||
doBlockStmt = `SET LOCAL synchronous_commit = 'local'; DO $$ BEGIN %s; END;$$;`
|
||||
passwordTemplate = "ENCRYPTED PASSWORD '%s'"
|
||||
inRoleTemplate = `IN ROLE %s`
|
||||
adminTemplate = `ADMIN %s`
|
||||
)
|
||||
|
||||
// DefaultUserSyncStrategy implements a user sync strategy that merges already existing database users
|
||||
@@ -113,6 +115,9 @@ func (strategy DefaultUserSyncStrategy) createPgUser(user spec.PgUser, db *sql.D
|
||||
if len(user.MemberOf) > 0 {
|
||||
userFlags = append(userFlags, fmt.Sprintf(inRoleTemplate, quoteMemberList(user)))
|
||||
}
|
||||
if user.AdminRole != "" {
|
||||
userFlags = append(userFlags, fmt.Sprintf(adminTemplate, user.AdminRole))
|
||||
}
|
||||
|
||||
if user.Password == "" {
|
||||
userPassword = "PASSWORD NULL"
|
||||
|
||||
Reference in New Issue
Block a user