fix(ddb): use app user credentials in db-permissions Job
ddb-cluster-superuser secret doesn't exist (not configured). Use ddb-cluster-app secret instead - app is DB owner, can grant permissions.
This commit is contained in:
@@ -55,11 +55,11 @@ spec:
|
|||||||
|
|
||||||
echo "Granting schema permissions to app users..."
|
echo "Granting schema permissions to app users..."
|
||||||
|
|
||||||
# Get postgres password
|
# Get app user password
|
||||||
export PGPASSWORD=$(cat /postgres-secret/password)
|
export PGPASSWORD=$(cat /postgres-secret/password)
|
||||||
|
|
||||||
# Grant for authentik
|
# Grant for authentik (as app user, owner of the DB)
|
||||||
psql -h ddb-cluster-rw -U postgres -d authentik << 'SQL'
|
psql -h ddb-cluster-rw -U app -d authentik << 'SQL'
|
||||||
GRANT ALL ON SCHEMA public TO app;
|
GRANT ALL ON SCHEMA public TO app;
|
||||||
GRANT ALL ON SCHEMA public TO authentik;
|
GRANT ALL ON SCHEMA public TO authentik;
|
||||||
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON TABLES TO app;
|
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON TABLES TO app;
|
||||||
@@ -69,7 +69,7 @@ spec:
|
|||||||
SQL
|
SQL
|
||||||
|
|
||||||
# Grant for temporal
|
# Grant for temporal
|
||||||
psql -h ddb-cluster-rw -U postgres -d temporal << 'SQL'
|
psql -h ddb-cluster-rw -U app -d temporal << 'SQL'
|
||||||
GRANT ALL ON SCHEMA public TO app;
|
GRANT ALL ON SCHEMA public TO app;
|
||||||
GRANT ALL ON SCHEMA public TO temporal;
|
GRANT ALL ON SCHEMA public TO temporal;
|
||||||
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON TABLES TO app;
|
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON TABLES TO app;
|
||||||
@@ -79,7 +79,7 @@ spec:
|
|||||||
SQL
|
SQL
|
||||||
|
|
||||||
# Grant for temporal_visibility
|
# Grant for temporal_visibility
|
||||||
psql -h ddb-cluster-rw -U postgres -d temporal_visibility << 'SQL'
|
psql -h ddb-cluster-rw -U app -d temporal_visibility << 'SQL'
|
||||||
GRANT ALL ON SCHEMA public TO app;
|
GRANT ALL ON SCHEMA public TO app;
|
||||||
GRANT ALL ON SCHEMA public TO temporal;
|
GRANT ALL ON SCHEMA public TO temporal;
|
||||||
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON TABLES TO app;
|
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON TABLES TO app;
|
||||||
@@ -96,4 +96,4 @@ spec:
|
|||||||
volumes:
|
volumes:
|
||||||
- name: postgres-secret
|
- name: postgres-secret
|
||||||
secret:
|
secret:
|
||||||
secretName: ddb-cluster-superuser
|
secretName: ddb-cluster-app
|
||||||
|
|||||||
Reference in New Issue
Block a user