mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-08-18 16:02:10 +00:00
68daed8501
Attach custom-instance datatables in the DuckDB executor through a DuckDB secret instead of an inline connection string, and route postgres triggers on custom-instance datatables through a dedicated custom_instance_replication_user role (with its own auto-generated password in global_settings). Normalize custom_instance_user attributes on server boot. Claude-Session: https://claude.ai/code/session_01Tp6NNNinCB8dwWqGaFXDRF Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
35 lines
1.5 KiB
SQL
35 lines
1.5 KiB
SQL
-- Dedicated logical-replication role used by postgres triggers on custom-instance
|
|
-- datatables. Its password is stored server-only in global_settings.custom_instance_replication_pwd
|
|
-- (hidden from the config surface); membership in custom_instance_user lets it manage
|
|
-- publications on the datatable tables. custom_instance_user itself must not hold REPLICATION.
|
|
DO $$
|
|
DECLARE
|
|
pwd text;
|
|
BEGIN
|
|
SELECT gen_random_uuid()::text INTO pwd;
|
|
|
|
IF EXISTS (SELECT 1 FROM pg_roles WHERE rolname = 'custom_instance_replication_user') THEN
|
|
EXECUTE format('ALTER USER custom_instance_replication_user WITH PASSWORD %L REPLICATION', pwd);
|
|
ELSE
|
|
EXECUTE format('CREATE USER custom_instance_replication_user WITH PASSWORD %L REPLICATION', pwd);
|
|
END IF;
|
|
|
|
IF EXISTS (SELECT 1 FROM pg_roles WHERE rolname = 'custom_instance_user') THEN
|
|
GRANT custom_instance_user TO custom_instance_replication_user;
|
|
ALTER ROLE custom_instance_user NOREPLICATION;
|
|
END IF;
|
|
|
|
INSERT INTO global_settings (name, value)
|
|
VALUES ('custom_instance_replication_pwd', to_jsonb(pwd::text))
|
|
ON CONFLICT (name) DO UPDATE SET value = EXCLUDED.value;
|
|
|
|
-- Drop any replication password an earlier iteration stored in the operator-facing row.
|
|
UPDATE global_settings
|
|
SET value = value - 'replication_user_pwd'
|
|
WHERE name = 'custom_instance_pg_databases';
|
|
EXCEPTION
|
|
WHEN others THEN
|
|
RAISE NOTICE 'custom_instance_replication_user migration error, skipping: %', SQLERRM;
|
|
END
|
|
$$;
|