diff --git a/conf/type/__postgres_role/explorer/state b/conf/type/__postgres_role/explorer/state new file mode 100755 index 00000000..8c102df9 --- /dev/null +++ b/conf/type/__postgres_role/explorer/state @@ -0,0 +1,27 @@ +#!/bin/sh +# +# 2011 Steven Armstrong (steven-cdist at armstrong.cc) +# +# This file is part of cdist. +# +# cdist is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, either version 3 of the License, or +# (at your option) any later version. +# +# cdist is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with cdist. If not, see . +# + +name="$__object_id" + +if su - postgres -c "psql -c '\du' | grep -q '^ *$name *|'"; then + echo "present" +else + echo "absent" +fi diff --git a/conf/type/__postgres_role/gencode-remote b/conf/type/__postgres_role/gencode-remote new file mode 100755 index 00000000..5f1401b1 --- /dev/null +++ b/conf/type/__postgres_role/gencode-remote @@ -0,0 +1,54 @@ +#!/bin/sh +# +# 2011 Steven Armstrong (steven-cdist at armstrong.cc) +# +# This file is part of cdist. +# +# cdist is free software: you can redistribute it and/or modify +# it under the terms of the GNU General Public License as published by +# the Free Software Foundation, either version 3 of the License, or +# (at your option) any later version. +# +# cdist is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with cdist. If not, see . +# + +name="$__object_id" +state_is="$(cat "$__object/explorer/state")" +state_should="$(cat "$__object/parameter/state")" + +if [ "$state_is" != "$state_should" ]; then + case "$state_should" in + present) + optional="password + login + createdb + createrole + superuser" + for parameter in $optional; do + if [ -f "$__object/parameter/$parameter" ]; then + value="$(cat "$__object/parameter/$parameter")" + eval $parameter=$value + fi + done + + [ -n "$password" ] && password="PASSWORD '$password'" + [ "$login" = "true" ] && login="LOGIN" || login="NOLOGIN" + [ "$createdb" = "true" ] && createdb="CREATEDB" || createdb="NOCREATEDB" + [ "$createrole" = "true" ] && createrole="CREATEROLE" || createrole="NOCREATEROLE" + [ "$superuser" = "true" ] && superuser="SUPERUSER" || superuser="NOSUPERUSER" + [ "$inherit" = "true" ] && inherit="INHERIT" || inherit="NOINHERIT" + + cmd="CREATE ROLE $name WITH $password $login $createdb $createrole $superuser $inherit" + echo "su - postgres -c \"/usr/bin/psql -c \\\"$cmd\\\"\"" + ;; + absent) + echo "su - postgres -c \"/usr/bin/dropuser \\\"$name\\\"\"" + ;; + esac +fi diff --git a/conf/type/__postgres_role/man.text b/conf/type/__postgres_role/man.text new file mode 100644 index 00000000..415473d5 --- /dev/null +++ b/conf/type/__postgres_role/man.text @@ -0,0 +1,52 @@ +cdist-type__postgres_role(7) +============================ +Steven Armstrong + + +NAME +---- +cdist-type__postgres_role - manage postgres roles + + +DESCRIPTION +----------- +This cdist type allows you to create or drop postgres roles. + + +REQUIRED PARAMETERS +------------------- +state:: + either 'present' or 'absent' + + +OPTIONAL PARAMETERS +------------------- +All optional parameter map directly to the corresponding postgres createrole +parameters. + +password:: +login:: +createdb:: +createrole:: +superuser:: +inherit:: + + +EXAMPLES +-------- + +-------------------------------------------------------------------------------- +__postgres_role myrole --state present +-------------------------------------------------------------------------------- + + +SEE ALSO +-------- +- cdist-type(7) +- http://www.postgresql.org/docs/current/static/sql-createrole.html + + +COPYING +------- +Copyright \(C) 2011 Steven Armstrong. Free use of this software is +granted under the terms of the GNU General Public License version 3 (GPLv3). diff --git a/conf/type/__postgres_role/parameter/optional b/conf/type/__postgres_role/parameter/optional new file mode 100644 index 00000000..c5abb57f --- /dev/null +++ b/conf/type/__postgres_role/parameter/optional @@ -0,0 +1,6 @@ +password +login +createdb +createrole +superuser +inherit diff --git a/conf/type/__postgres_role/parameter/required b/conf/type/__postgres_role/parameter/required new file mode 100644 index 00000000..ff72b5c7 --- /dev/null +++ b/conf/type/__postgres_role/parameter/required @@ -0,0 +1 @@ +state