diff --git a/postgresql/cutover/test/pgha-dryrun.yaml b/postgresql/cutover/test/pgha-dryrun.yaml index 1a252a0..7045b11 100644 --- a/postgresql/cutover/test/pgha-dryrun.yaml +++ b/postgresql/cutover/test/pgha-dryrun.yaml @@ -53,6 +53,18 @@ # — Zalando's script itself is never patched or forked. This affects real # production too (superuser there is also PGadmin, not postgres) and must # be carried into the real staging/production compose files as well. +# +# NOTE: the placeholder "postgres" role created by the wrapper above must +# be a genuine SUPERUSER (not just exist) — confirmed by tracing the +# failure past the ALTER VIEW step: Spilo's post_init.sh unconditionally +# cats and pipes in Zalando's own _zmon_schema.dump, whose first lines are +# "RESET ROLE; SET ROLE TO postgres;" followed by +# "CREATE EXTENSION IF NOT EXISTS plpython3u", which requires superuser +# privileges. A plain NOLOGIN role satisfies SET ROLE (membership-based) +# but not the subsequent superuser-only extension creation. Since the role +# is NOLOGIN, granting SUPERUSER carries no real exposure — it can never be +# used to establish a connection. This must also be carried into the real +# staging/production compose files alongside the post_init override above. # ───────────────────────────────────────────────────────────────────────── version: "3.6" @@ -173,7 +185,7 @@ services: cat > /scripts/post_init_wrapper.sh <<'WRAP' #!/bin/bash set -e - psql -d "$$2" -v ON_ERROR_STOP=1 -c 'DO $$do$$ BEGIN IF NOT EXISTS (SELECT 1 FROM pg_catalog.pg_roles WHERE rolname = $$x$$postgres$$x$$) THEN CREATE ROLE postgres; END IF; END $$do$$;' + psql -d "$$2" -v ON_ERROR_STOP=1 -c 'DO $$do$$ BEGIN IF NOT EXISTS (SELECT 1 FROM pg_catalog.pg_roles WHERE rolname = $$x$$postgres$$x$$) THEN CREATE ROLE postgres WITH SUPERUSER NOLOGIN; END IF; END $$do$$;' exec /scripts/post_init.sh "$$@" WRAP chmod +x /scripts/post_init_wrapper.sh @@ -222,7 +234,7 @@ services: cat > /scripts/post_init_wrapper.sh <<'WRAP' #!/bin/bash set -e - psql -d "$$2" -v ON_ERROR_STOP=1 -c 'DO $$do$$ BEGIN IF NOT EXISTS (SELECT 1 FROM pg_catalog.pg_roles WHERE rolname = $$x$$postgres$$x$$) THEN CREATE ROLE postgres; END IF; END $$do$$;' + psql -d "$$2" -v ON_ERROR_STOP=1 -c 'DO $$do$$ BEGIN IF NOT EXISTS (SELECT 1 FROM pg_catalog.pg_roles WHERE rolname = $$x$$postgres$$x$$) THEN CREATE ROLE postgres WITH SUPERUSER NOLOGIN; END IF; END $$do$$;' exec /scripts/post_init.sh "$$@" WRAP chmod +x /scripts/post_init_wrapper.sh