mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-10-06 03:15:41 +02:00
Merge branch 'master' into default-db-roles
This commit is contained in:
@@ -329,7 +329,7 @@ func (c *Cluster) deleteStatefulSet() error {
|
||||
return fmt.Errorf("could not delete pods: %v", err)
|
||||
}
|
||||
|
||||
if err := c.deletePersistenVolumeClaims(); err != nil {
|
||||
if err := c.deletePersistentVolumeClaims(); err != nil {
|
||||
return fmt.Errorf("could not delete PersistentVolumeClaims: %v", err)
|
||||
}
|
||||
|
||||
|
||||
@@ -30,7 +30,7 @@ func (c *Cluster) listPersistentVolumeClaims() ([]v1.PersistentVolumeClaim, erro
|
||||
return pvcs.Items, nil
|
||||
}
|
||||
|
||||
func (c *Cluster) deletePersistenVolumeClaims() error {
|
||||
func (c *Cluster) deletePersistentVolumeClaims() error {
|
||||
c.logger.Debugln("deleting PVCs")
|
||||
pvcs, err := c.listPersistentVolumeClaims()
|
||||
if err != nil {
|
||||
|
||||
@@ -58,7 +58,6 @@ type Controller struct {
|
||||
|
||||
PodServiceAccount *v1.ServiceAccount
|
||||
PodServiceAccountRoleBinding *rbacv1beta1.RoleBinding
|
||||
namespacesWithDefinedRBAC sync.Map
|
||||
}
|
||||
|
||||
// NewController creates a new controller
|
||||
|
||||
@@ -493,17 +493,16 @@ func (c *Controller) postgresqlDelete(obj interface{}) {
|
||||
}
|
||||
|
||||
/*
|
||||
Ensures the pod service account and role bindings exists in a namespace before a PG cluster is created there so that a user does not have to deploy these credentials manually.
|
||||
StatefulSets require the service account to create pods; Patroni requires relevant RBAC bindings to access endpoints.
|
||||
Ensures the pod service account and role bindings exists in a namespace
|
||||
before a PG cluster is created there so that a user does not have to deploy
|
||||
these credentials manually. StatefulSets require the service account to
|
||||
create pods; Patroni requires relevant RBAC bindings to access endpoints.
|
||||
|
||||
The operator does not sync accounts/role bindings after creation.
|
||||
*/
|
||||
func (c *Controller) submitRBACCredentials(event ClusterEvent) error {
|
||||
|
||||
namespace := event.NewSpec.GetNamespace()
|
||||
if _, ok := c.namespacesWithDefinedRBAC.Load(namespace); ok {
|
||||
return nil
|
||||
}
|
||||
|
||||
if err := c.createPodServiceAccount(namespace); err != nil {
|
||||
return fmt.Errorf("could not create pod service account %v : %v", c.opConfig.PodServiceAccountName, err)
|
||||
@@ -512,7 +511,6 @@ func (c *Controller) submitRBACCredentials(event ClusterEvent) error {
|
||||
if err := c.createRoleBindings(namespace); err != nil {
|
||||
return fmt.Errorf("could not create role binding %v : %v", c.PodServiceAccountRoleBinding.Name, err)
|
||||
}
|
||||
c.namespacesWithDefinedRBAC.Store(namespace, true)
|
||||
return nil
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user