Skip to content

Avoid privilege escalation while polling PostgreSQL - #863

Open
jakduch wants to merge 1 commit into
theforeman:masterfrom
jakduch:fix/862-postgresql-status-no-become
Open

jakduch wants to merge 1 commit into
theforeman:masterfrom
jakduch:fix/862-postgresql-status-no-become

Conversation

@jakduch

@jakduch jakduch commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

Summary

  • poll the PostgreSQL service state without privilege escalation during backups
  • avoid a fresh sudo handshake while the host is settling after foreman.target stops
  • add a regression test for the non-escalated status check

Testing

  • ansible-lint src/roles/backup
  • direct execution of test_postgresql_stop_poll_does_not_escalate_privileges
  • git diff --check

Fixes #862

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 53 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Advanced

Run ID: cf216874-7909-4799-899c-d85687597c72

📥 Commits

Reviewing files that changed from the base of the PR and between 6c79648 and 36af07a.

📒 Files selected for processing (2)
  • src/roles/backup/tasks/main.yaml
  • tests/unit/check_role_test.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jakduch

jakduch commented Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

The remaining red jobs are caused by the shared development-memory issue, not by the PostgreSQL polling change: the SOS journal records candlepin.service being killed by the OOM killer. #865 limits the Candlepin heap for development tuning and has passed the complete CI matrix.

@jakduch
jakduch force-pushed the fix/862-postgresql-status-no-become branch from d8e8770 to 36af07a Compare September 26, 2026 11:43
@jakduch

jakduch commented Sep 26, 2026

Copy link
Copy Markdown
Contributor Author

The failing deployment jobs hit the Candlepin heap/OOM problem fixed on current master by #865. I rebased this branch onto that fix; CI is running again.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Avoid privilege escalation timeout while waiting for PostgreSQL

1 participant