mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-04 21:02:29 +02:00
rename db roles that are removed from manifests
This commit is contained in:
@@ -957,10 +957,6 @@ func (c *Cluster) initSystemUsers() {
|
||||
Password: util.RandomPassword(constants.PasswordLength),
|
||||
}
|
||||
|
||||
if _, exists := c.pgUsers[username]; !exists {
|
||||
c.pgUsers[username] = connectionPoolerUser
|
||||
}
|
||||
|
||||
if _, exists := c.systemUsers[constants.ConnectionPoolerUserKeyName]; !exists {
|
||||
c.systemUsers[constants.ConnectionPoolerUserKeyName] = connectionPoolerUser
|
||||
}
|
||||
|
||||
@@ -24,7 +24,8 @@ const (
|
||||
JOIN pg_catalog.pg_authid b ON (m.roleid = b.oid)
|
||||
WHERE m.member = a.oid) as memberof
|
||||
FROM pg_catalog.pg_authid a LEFT JOIN pg_db_role_setting s ON (a.oid = s.setrole AND s.setdatabase = 0::oid)
|
||||
WHERE a.rolname = ANY($1)
|
||||
WHERE a.rolname != ALL($1)
|
||||
AND (rolcanlogin OR (NOT rolcanlogin AND rolpassword IS NOT NULL))
|
||||
ORDER BY 1;`
|
||||
|
||||
getDatabasesSQL = `SELECT datname, pg_get_userbyid(datdba) AS owner FROM pg_database;`
|
||||
|
||||
+8
-14
@@ -528,6 +528,9 @@ func (c *Cluster) syncSecrets() error {
|
||||
} else if secretUsername == c.systemUsers[constants.ReplicationUserKeyName].Name {
|
||||
secretUsername = constants.ReplicationUserKeyName
|
||||
userMap = c.systemUsers
|
||||
} else if secretUsername == c.systemUsers[constants.ConnectionPoolerUserName].Name {
|
||||
secretUsername = constants.ConnectionPoolerUserName
|
||||
userMap = c.systemUsers
|
||||
} else {
|
||||
userMap = c.pgUsers
|
||||
}
|
||||
@@ -557,8 +560,8 @@ func (c *Cluster) syncRoles() (err error) {
|
||||
c.setProcessName("syncing roles")
|
||||
|
||||
var (
|
||||
dbUsers spec.PgUserMap
|
||||
userNames []string
|
||||
dbUsers spec.PgUserMap
|
||||
systemUserNames []string
|
||||
)
|
||||
|
||||
err = c.initDbConn()
|
||||
@@ -576,20 +579,11 @@ func (c *Cluster) syncRoles() (err error) {
|
||||
}
|
||||
}()
|
||||
|
||||
for _, u := range c.pgUsers {
|
||||
userNames = append(userNames, u.Name)
|
||||
for _, u := range c.systemUsers {
|
||||
systemUserNames = append(systemUserNames, u.Name)
|
||||
}
|
||||
|
||||
if needMasterConnectionPooler(&c.Spec) || needReplicaConnectionPooler(&c.Spec) {
|
||||
connectionPoolerUser := c.systemUsers[constants.ConnectionPoolerUserKeyName]
|
||||
userNames = append(userNames, connectionPoolerUser.Name)
|
||||
|
||||
if _, exists := c.pgUsers[connectionPoolerUser.Name]; !exists {
|
||||
c.pgUsers[connectionPoolerUser.Name] = connectionPoolerUser
|
||||
}
|
||||
}
|
||||
|
||||
dbUsers, err = c.readPgUsersFromDatabase(userNames)
|
||||
dbUsers, err = c.readPgUsersFromDatabase(systemUserNames)
|
||||
if err != nil {
|
||||
return fmt.Errorf("error getting users from the database: %v", err)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user