Skip to content

AtlasDatabaseUser misconfigured: wrong role database and wrong auth database #37

Description

@paulyhedral

The `admin-api` AtlasDatabaseUser manifest (`kubernetes/overlays/dev/atlas-db-user.yaml`) has two bugs:

  1. The role's `databaseName` was `users` instead of `sweetrpg-admin`, so the Operator-provisioned user got `readWrite` on the wrong database.
  2. The top-level `spec.databaseName` (the authentication database) was set to `sweetrpg-admin` instead of `admin`. Atlas requires SCRAM-SHA users to authenticate against `admin` and rejects reconciliation otherwise with `DATABASE_NAME_INVALID_ADMIN`.

Confirmed in the running cluster: `admin-api` pod logs showed `(AtlasError) user is not allowed to do action [find] on [sweetrpg-admin.banners]` on every query, and the Atlas Operator logged a reconcile error for this exact resource once the Operator had project write access.

Fixed in #36.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions