The `catalog-api` AtlasDatabaseUser manifest (`kubernetes/overlays/dev/atlas-db-user.yaml`) sets the top-level `spec.databaseName` (the authentication database) to `sweetrpg-catalog` instead of `admin`. Atlas requires SCRAM-SHA users to authenticate against `admin` and rejects reconciliation otherwise with `DATABASE_NAME_INVALID_ADMIN` - confirmed via the Atlas Operator's reconcile error for this exact resource.
The role's own `databaseName` (already `sweetrpg-catalog`) correctly scopes data access and is unaffected.
A separate, unrelated Atlas Console misconfiguration (a stray per-collection restriction on the live user's role) was also found and fixed directly in Atlas - this issue and its PR cover only the CRD manifest bug.
Fixed in #170.
The `catalog-api` AtlasDatabaseUser manifest (`kubernetes/overlays/dev/atlas-db-user.yaml`) sets the top-level `spec.databaseName` (the authentication database) to `sweetrpg-catalog` instead of `admin`. Atlas requires SCRAM-SHA users to authenticate against `admin` and rejects reconciliation otherwise with `DATABASE_NAME_INVALID_ADMIN` - confirmed via the Atlas Operator's reconcile error for this exact resource.
The role's own `databaseName` (already `sweetrpg-catalog`) correctly scopes data access and is unaffected.
A separate, unrelated Atlas Console misconfiguration (a stray per-collection restriction on the live user's role) was also found and fixed directly in Atlas - this issue and its PR cover only the CRD manifest bug.
Fixed in #170.