Merge pull request #35 from matter-labs/backup-user
Some checks failed
Release / Release (push) Has been cancelled
CI / Lint (push) Has been cancelled
CI / Ansible lint (push) Has been cancelled

feat: Added user with backup permissions only
This commit is contained in:
Aleksandr Stepanov
2024-11-27 15:45:36 +01:00
committed by GitHub
2 changed files with 21 additions and 0 deletions

View File

@ -64,6 +64,9 @@ postgres_replica_user_password: ""
postgres_replica_auth_method: "scram-sha-256" postgres_replica_auth_method: "scram-sha-256"
postgres_replication_bind_address: "" postgres_replication_bind_address: ""
postgres_replica_address: "" postgres_replica_address: ""
backup_db_user: ""
backup_db_password: ""
backup_db_name: ""
# Enable TLS for traefik # Enable TLS for traefik
enable_tls: false enable_tls: false

View File

@ -40,3 +40,21 @@
login_user: "{{ database_username }}" login_user: "{{ database_username }}"
login_password: "{{ database_password }}" login_password: "{{ database_password }}"
query: "SELECT pg_reload_conf()" query: "SELECT pg_reload_conf()"
- name: Create postgres backup user
community.postgresql.postgresql_user:
login_host: "{{ postgres_replication_bind_address }}"
login_user: "{{ database_username }}"
login_password: "{{ database_password }}"
name: "{{ backup_db_user }}"
password: "{{ backup_db_password }}"
- name: Grant role pg_read_all_data to backup user
community.postgresql.postgresql_membership:
login_host: "{{ postgres_replication_bind_address }}"
login_user: "{{ database_username }}"
login_password: "{{ database_password }}"
group: pg_read_all_data
target_roles:
- "{{ backup_db_user }}"
state: present