mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-09-30 22:27:39 +02:00
* Skip ALTER ROLE when the stored SCRAM verifier already matches the password With password_encryption = scram-sha-256, syncSecrets compared the stored rolpassword with a freshly generated verifier. SCRAM verifiers embed a random salt, so the strings never match and every sync cycle re-issued ALTER ROLE ... PASSWORD for every managed role, re-salting the verifier each time. Besides the WAL and audit noise, this invalidates SCRAM pass-through credentials cached by connection poolers (e.g. pgbouncer behind auth_query), causing a short window of 'password authentication failed' server logins after every sync. Verify the stored hash against the desired password instead: for SCRAM verifiers the salt and iteration count are taken from the stored value and the derived keys are compared. Hashes whose type does not match the configured password_encryption are still reported as outdated, so switching between md5 and scram-sha-256 keeps re-hashing roles as before. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Update pkg/util/util.go --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Ida Novindasari <idanovinda@gmail.com> Co-authored-by: Felix Kunde <felix-kunde@gmx.de>