You are looking at the documentation of a prior release. To read the documentation of the latest release, please
visit here.
New to KubeDB? Please start here.
Rotate Authentication of ClickHouse
This guide will give an overview on how KubeDB Ops-manager operator Rotate Authentication configuration.
Before You Begin
- You should be familiar with the following
KubeDBconcepts:
How Rotate ClickHouse Authentication Configuration Process Works
The Rotate ClickHouse Authentication process consists of the following steps:
At first, a user creates a
ClickHouseCustom Resource Object (CRO).KubeDBProvisioner operator watches theClickHouseCRO.When the operator finds a
ClickHouseCR, it creates required number ofPetSetsand related necessary stuff like secrets, services, etc.Then, in order to rotate the authentication configuration of the
ClickHouse, the user creates aClickHouseOpsRequestCR with desired information.KubeDBOps-manager operator watches theClickHouseOpsRequestCR.When it finds a
ClickHouseOpsRequestCR, it pauses theClickHouseobject which is referred from theClickHouseOpsRequest. So, theKubeDBProvisioner operator doesn’t perform any operations on theClickHouseobject during the rotating Authentication process.Then the
KubeDBOps-manager operator will update necessary configuration based on the Ops Request yaml to update credentials.Then the
KubeDBOps-manager operator will restart all the Pods of the database so that they restart with the new authenticationENVsor other configuration defined in theClickHouseOpsRequestCR.After the successful rotating of the
ClickHouseAuthentication, theKubeDBOps-manager operator resumes theClickHouseobject so that theKubeDBProvisioner operator resumes its usual operations.
In the next docs, we are going to show a step-by-step guide on rotating Authentication configuration of a ClickHouse using ClickHouseOpsRequest CRD.































