What happened?
DefaultPrivileges managed resources for PostgreSQL are reported as Ready/Synced and treated as up to date, but the corresponding ALTER DEFAULT PRIVILEGES statements are never applied to the database if other unrelated DEFAULT PRIVILEGES already exist.
How can we reproduce it?
- On a Postgres instance, create a role 'authenticated' and any default privileges for that role on the schema 'schema_a'.
- Add a DefaultPrivileges for a different role and schema:
apiVersion: postgresql.sql.m.crossplane.io/v1alpha1
kind: DefaultPrivileges
metadata:
name: example-dp-table
namespace: default
spec:
providerConfigRef:
name: example
forProvider:
database: postgres
schema: example
objectType: table
role: authenticated
targetRole: example_owner
privileges:
- SELECT
- INSERT
- UPDATE
- DELETE
- TRUNCATE
- REFERENCES
- TRIGGER
- MAINTAIN
Crossplane will show the DefaultPrivileges Ready/Synced without applying them in the DB.
What environment did it happen in?
Crossplane version: 2.4.0
provider: xpkg.upbound.io/crossplane-contrib/provider-sql:v0.16.1
Kubernetes version: 1.35.1 (minikube)
What happened?
DefaultPrivileges managed resources for PostgreSQL are reported as Ready/Synced and treated as up to date, but the corresponding ALTER DEFAULT PRIVILEGES statements are never applied to the database if other unrelated DEFAULT PRIVILEGES already exist.
How can we reproduce it?
Crossplane will show the DefaultPrivileges Ready/Synced without applying them in the DB.
What environment did it happen in?
Crossplane version: 2.4.0
provider: xpkg.upbound.io/crossplane-contrib/provider-sql:v0.16.1
Kubernetes version: 1.35.1 (minikube)