Repository navigation
Conversation
Signed-off-by: Chris Werner Rau <cwrau@cwrau.info>
cwrau
requested review from
FxKu,
Jan-M,
hughcapet,
idanovinda,
jopadi and
mikkeloscar
as code owners
October 7, 2026 09:23
Author
|
For the label check; I would say this is a minor change, it's not a fix and it's not breaking anything |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem description
The aggregated user-facing ClusterRoles (
:users:view,:users:edit,:users:admin, aggregated into the builtinview,editandadminroles through therbac.authorization.k8s.io/aggregate-to-*labels) only coverpostgresqls. Users who are bound to the builtin roles cannot see or managepostgresteams,operatorconfigurationsorfabriceventstreamswithout hand-written RBAC. In the Helm chart the roles are also only created whenrbac.createAggregateClusterRolesis enabled, and it defaults tofalse.This keeps the existing three roles, names and labels and extends them:
postgresteamsandoperatorconfigurations: get/list/watch in view, edit and admin (the builtin edit and admin roles do not inherit view, so read access is repeated there); write verbs in admin only, because they change operator-wide behaviour and database role membership.fabriceventstreams(groupzalando.org): same access aspostgresqls(read in view, write in edit and admin). The rule is now rendered unconditionally instead of only withenableStreams; RBAC rules for a resource whose CRD is not installed are harmless.rbac.createAggregateClusterRolesnow defaults totruein the chart. This is a behaviour change on upgrade: the three ClusterRoles are created and cluster users bound to the builtin roles gain the access above. Set it tofalseto keep the old behaviour. Anyone who already appliedmanifests/user-facing-clusterroles.yamlby hand under the same names should be aware of the name overlap when Helm tries to create them.manifests/user-facing-clusterroles.yamlcarries the same rules as the chart template.docs/administrator.mddescribes the new coverage and default, drops the statement that the streams rules are only included withenableStreams, and fixes the role name (users, notuser).Existing view access to
postgresqlsis unchanged, nothing is narrowed.Linked issues
Fixes #3196
Checklist
Thanks for submitting a pull request to the Postgres Operator project.
Please, ensure your contribution matches the following items:
acid.zalan.doapi package. (not applicable, no API changes)helm lintandhelm templatefor the default values,rbac.createAggregateClusterRoles=falseandenableStreams=true)