Skip to content

DefaultPrivileges except the first one are not applied but show ready/synced #458

Description

@hsahmed

What happened?

DefaultPrivileges managed resources for PostgreSQL are reported as Ready/Synced and treated as up to date, but the corresponding ALTER DEFAULT PRIVILEGES statements are never applied to the database if other unrelated DEFAULT PRIVILEGES already exist.

How can we reproduce it?

  1. On a Postgres instance, create a role 'authenticated' and any default privileges for that role on the schema 'schema_a'.
  2. Add a DefaultPrivileges for a different role and schema:
apiVersion: postgresql.sql.m.crossplane.io/v1alpha1
kind: DefaultPrivileges
metadata:
  name: example-dp-table
  namespace: default
spec:
  providerConfigRef:
    name: example
  forProvider:
    database: postgres
    schema: example
    objectType: table
    role: authenticated
    targetRole: example_owner
    privileges:
      - SELECT
      - INSERT
      - UPDATE
      - DELETE
      - TRUNCATE
      - REFERENCES
      - TRIGGER
      - MAINTAIN

Crossplane will show the DefaultPrivileges Ready/Synced without applying them in the DB.

What environment did it happen in?

Crossplane version: 2.4.0
provider: xpkg.upbound.io/crossplane-contrib/provider-sql:v0.16.1
Kubernetes version: 1.35.1 (minikube)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions