Repository navigation
Conversation
A single process can run barman-cloud commands for different object stores at the same time. A replica cluster, for instance, archives WAL to its own object store while restoring it from the source one. The Google application credentials were always written to the same file, so a command could run with the credentials of another object store, and an object store using the GKE environment emptied the file the other commands were reading. Write each credentials file to a path that depends on the referenced secret and key, point GOOGLE_APPLICATION_CREDENTIALS at it, and serialize the writes. The GKE environment no longer touches any file. Signed-off-by: Armando Ruocco <armando.ruocco@enterprisedb.com>
leonardoce
force-pushed
the
dev/gcs-credentials-per-store
branch
from
October 2, 2026 08:15
24110fd to
120366b
Compare
Contributor
|
I opened cloudnative-pg/machinery#325 to fix the reason why we need |
leonardoce
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A single process can run barman-cloud commands for different object stores at the same time. In the plugin sidecar, for instance, the designated primary of a replica cluster archives WAL to its own object store while restoring it from the source one. The Google application credentials were always materialized in
/controller/.application_credentials.json, so with two Google Cloud Storage object stores using different credentials a command could run with the identity of the other object store, and an object store relying on the GKE environment rewrote the shared file with empty content while the other commands were reading it.Each credentials file is now written under
/controller/.google-credentials/<secret>/<key>,GOOGLE_APPLICATION_CREDENTIALSpoints at it, and the writes are serialized, becausefileutils.WriteFileAtomicnames its temporary file after the current second. The GKE environment does not touch any file anymore.This is the same problem fixed for the SSE-C customer keys in #284.