zalando / zalando/postgres-operator
Default privileges do not synced for preparedDatabases
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 5.2k
- Forks
- 1.1k
- Avg merge
- 2d 16h
- Merged PRs (30d)
- 3
Description
Please, answer some short questions which should help us to understand your problem / question better?
- Which image of the operator are you using? registry.opensource.zalan.do/acid/postgres-operator:v1.8.2
- Where do you run it - cloud or metal? Kubernetes or OpenShift? DigitalOcean K8S
- Are you running Postgres Operator in production? yes
- Type of issue? Bug report
There is long living databases, created with ancient versions of operator. We migrate them to preparedDatabases and try to use defaultUsers. However, there is no default privileges defined and DB_reader_user can't read anything. If we create new preparedDatabase then default privileges are created.
I suppose call to execAlterGlobalDefaultPrivileges shoud be added to syncPreparedDatabases function.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating syncPreparedDatabases and execAlterGlobalDefaultPrivileges in the Go operator code, then compare how existing preparedDatabases are synchronized with newly created ones. The issue is done when default privileges are applied for long-lived databases migrated to preparedDatabases, allowing defaultUsers such as DB_reader_user to read their objects.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go, kubernetes, postgresql
- Domain
- databases, devops
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100