The `admin-api` AtlasDatabaseUser manifest (`kubernetes/overlays/dev/atlas-db-user.yaml`) has two bugs:
- The role's `databaseName` was `users` instead of `sweetrpg-admin`, so the Operator-provisioned user got `readWrite` on the wrong database.
- The top-level `spec.databaseName` (the authentication database) was set to `sweetrpg-admin` instead of `admin`. Atlas requires SCRAM-SHA users to authenticate against `admin` and rejects reconciliation otherwise with `DATABASE_NAME_INVALID_ADMIN`.
Confirmed in the running cluster: `admin-api` pod logs showed `(AtlasError) user is not allowed to do action [find] on [sweetrpg-admin.banners]` on every query, and the Atlas Operator logged a reconcile error for this exact resource once the Operator had project write access.
Fixed in #36.
The `admin-api` AtlasDatabaseUser manifest (`kubernetes/overlays/dev/atlas-db-user.yaml`) has two bugs:
Confirmed in the running cluster: `admin-api` pod logs showed `(AtlasError) user is not allowed to do action [find] on [sweetrpg-admin.banners]` on every query, and the Atlas Operator logged a reconcile error for this exact resource once the Operator had project write access.
Fixed in #36.