adshin21andSerdar Dalgıç bbc3eab7e0 Skip owner references on user secrets when secret deletion is disabled (#3165)
* Skip owner references on user secrets when secret deletion is disabled

Kubernetes garbage-collects owner-referenced secrets as soon as the
owning Postgresql resource is deleted, regardless of the operator's
own EnableSecretsDeletion check in Delete() (which only guards the
operator's explicit deleteSecrets() call, not GC). This made
enable_secrets_deletion=false ineffective whenever
enable_owner_references was also enabled, since GC removed the
credential secrets anyway.

Now the generated secrets are not removed when
enable_owner_references: true, enable_secrets_deletion: false.

* Document skip-owner-refs on user secrets when deletion disabled

- refresh inline comment in generateSingleUserSecret
- extend enable_owner_references / enable_secrets_deletion docs in
  operator_parameters.md to describe the interaction
- clarify in operator_parameters.md that the protection takes effect
  on the cluster's next sync after the setting is applied
- add third exception in administrator.md "Owner References and Finalizers"
- add TestGenerateSingleUserSecret_OwnerReferences covering all four
  flag combinations plus the cross-namespace cases

---------

Co-authored-by: Serdar Dalgıç <sd@serdardalgic.org>
2026-08-11 17:22:39 +02:00
2026-07-29 10:51:00 +02:00
2026-07-27 23:50:17 +02:00
2026-07-29 10:51:00 +02:00
2019-06-05 17:07:27 +02:00
2026-06-12 10:42:37 +02:00
2018-11-27 12:00:15 +01:00
2021-01-29 11:12:08 +01:00
2026-01-09 14:22:10 +01:00
2025-12-03 11:00:59 +01:00
2019-07-11 17:19:27 +02:00
2025-12-03 11:00:59 +01:00
2026-07-27 23:50:17 +02:00
2026-07-29 10:51:00 +02:00

Postgres Operator

Tests E2E Tests Coverage Status

The Postgres Operator delivers an easy to run highly-available PostgreSQL clusters on Kubernetes (K8s) powered by Patroni. It is configured only through Postgres manifests (CRDs) to ease integration into automated CI/CD pipelines with no access to Kubernetes API directly, promoting infrastructure as code vs manual operations.

Operator features

  • Rolling updates on Postgres cluster changes, incl. quick minor version updates
  • Live volume resize without pod restarts (AWS EBS, PVC)
  • Database connection pooling with PGBouncer
  • Support fast in place major version upgrade. Supports global upgrade of all clusters.
  • Pod protection during bootstrap phase and configurable maintenance windows
  • Restore and cloning Postgres clusters on AWS, GCS and Azure
  • Additionally logical backups to S3 or GCS bucket can be configured
  • Standby cluster from S3 or GCS WAL archive or remote host
  • Configurable for non-cloud environments
  • Basic credential and user management on K8s, eases application deployments
  • Support for custom TLS certificates
  • UI to create and edit Postgres cluster manifests
  • Compatible with OpenShift
  • Multi-arch support

PostgreSQL features

The Postgres Operator has been developed at Zalando and is being used in production for over five years.

Supported Postgres & K8s versions

Release Postgres versions K8s versions Golang
v2.0.1 14 → 18 1.27+ 1.26.4
v1.15.1 13 → 17 1.27+ 1.25.3
v1.14.0 13 → 17 1.27+ 1.23.4
v1.13.0 12 → 16 1.27+ 1.22.5
v1.12.0 11 → 16 1.27+ 1.22.3
v1.11.0 11 → 16 1.27+ 1.21.7

Getting started

For a quick first impression follow the instructions of this tutorial.

Migrating from v1 to v2 operator

If you have been using Postgres Operator since v1.x (thank you), make sure you have read the migration docs before deploying a v2 operator.

Documentation

There is a browser-friendly version of this documentation at postgres-operator.readthedocs.io

S
Description
Postgres operator creates and manages PostgreSQL clusters running in Kubernetes
Readme
116 MiB
Languages
Go 76.5%
Python 13.4%
Pug 5.9%
Shell 2%
JavaScript 0.7%
Other 1.5%