Skip to content

force (re)creation of podman secret 'postgres_multiple_databases' wit… - #71

Open
darkmatterdawn wants to merge 1 commit into
OpenCHAMI:mainfrom
darkmatterdawn:70-allow-adding-to-podman-secret-postgres-multiple-databases
Open

darkmatterdawn wants to merge 1 commit into
OpenCHAMI:mainfrom
darkmatterdawn:70-allow-adding-to-podman-secret-postgres-multiple-databases

Conversation

@darkmatterdawn

Copy link
Copy Markdown
Contributor

…h each run of the script

Pull Request Template

Thank you for your contribution! Please ensure the following before submitting:

Checklist

  • [ x] My code follows the style guidelines of this project
  • [ x] I have added/updated comments where needed
  • I have added tests that prove my fix is effective or my feature works
  • [ x] I have run make test (or equivalent) locally and all tests pass
  • I have updated the relevant documentation (CLI examples, man pages, README, other docs, etc.)
  • [ x] DCO Sign-off: All commits are signed off (git commit -s) with my real name and email
  • REUSE Compliance:
    • Each new/modified source file has SPDX copyright and license headers
    • Any non-commentable files include a <filename>.license sidecar
    • All referenced licenses are present in the LICENSES/ directory

Description

bootstrap script now makes it easier to add microservices' content after the original installation.

Fixes #70

Type of Change

  • Bug fix
  • [x ] New feature
  • Breaking change
  • Documentation update
  • Dependency update

For more info, see Contributing Guidelines.

…h each run of the script

Signed-off-by: Jonathan Hermann <jonathan.hermann@cscs.ch>
@darkmatterdawn
darkmatterdawn force-pushed the 70-allow-adding-to-podman-secret-postgres-multiple-databases branch from a2a82ae to b471211 Compare August 13, 2026 23:35
@synackd

synackd commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

Thanks for the contribution.

My worry here is that we are changing the postgres_multiple_databases secret here without detecting if Postgres needs to be updated. In the case where the package is being upgraded, the bootstrap script will delete the old secret and replace it with new passwords, but the old Postgres credentials will remain and services will be unable to access the database.

Regenerating the secret adds some logic complexity:

  • Do we want to regenerate the Postgres password(s) for each database? Or,
  • Do we want to add logic to preserve the existing Postgres credentials and only add new databases? What happens when one service is removed?

What does the user expect?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: allow adding to podman secret postgres_multiple_databases

2 participants