MCPcopy Create free account
hub / github.com/PostHog/duckgres / resetPassword

Method resetPassword

controlplane/provisioning/api.go:446–486  ·  view source on GitHub ↗
(c *gin.Context)

Source from the content-addressed store, hash-verified

444 warehouse := &configstore.ManagedWarehouse{
445 DataStore: ds,
446 DuckLake: configstore.ManagedWarehouseDuckLake{Enabled: ducklakeEnabled},
447 // Stamp the authoritative Duckling CR name: the org ID verbatim. Org IDs
448 // are validated as lowercase DNS-1123 labels at this endpoint, so no
449 // transform is needed — and nothing downstream ever derives the name.
450 DucklingName: orgID,
451 }
452 if warehouse.DucklingName == "" {
453 c.JSON(http.StatusBadRequest, gin.H{"error": "duckling_name is required"})
454 return
455 }
456 // Metadata backend (the Postgres that hosts the DuckLake catalog).
457 // Provisioning shape differs per type; the catalog choice above is
458 // orthogonal.
459 switch req.MetadataStore.Type {
460 case configstore.MetadataStoreKindCnpgShard:
461 // No per-claim config — the composition picks the active shard from
462 // chart values and provisions the per-tenant role+database there.
463 warehouse.MetadataStore.Kind = configstore.MetadataStoreKindCnpgShard
464
465 case configstore.MetadataStoreKindExternal:
466 // A pre-existing Postgres. Endpoint (RDS host) + the AWS Secrets Manager
467 // secret name for the password are required; user/database default to
468 // "postgres" at the XRD.
469 ext := req.MetadataStore.External
470 if ext == nil || ext.Endpoint == "" || ext.PasswordAWSSecret == "" {
471 c.JSON(http.StatusBadRequest, gin.H{"error": "metadata_store.type 'external' requires metadata_store.external.endpoint and metadata_store.external.password_aws_secret"})
472 return
473 }
474 warehouse.MetadataStore = configstore.ManagedWarehouseMetadataStore{
475 Kind: configstore.MetadataStoreKindExternal,
476 Endpoint: ext.Endpoint,
477 Username: ext.User,
478 DatabaseName: ext.Database,
479 PasswordAWSSecret: ext.PasswordAWSSecret,
480 }
481
482 default:
483 c.JSON(http.StatusBadRequest, gin.H{"error": fmt.Sprintf("metadata_store.type must be %q or %q (got %q)", configstore.MetadataStoreKindCnpgShard, configstore.MetadataStoreKindExternal, req.MetadataStore.Type)})
484 return
485 }
486
487 // Generate the root password. The plaintext is returned in this
488 // response only — it is never stored, only the bcrypt hash is
489 // persisted via the transactional Provision below.

Callers

nothing calls this directly

Calls 7

GeneratePasswordFunction · 0.92
HashPasswordFunction · 0.92
DefaultFunction · 0.92
GetManagedWarehouseMethod · 0.65
UpdateOrgUserPasswordMethod · 0.65
CaptureMethod · 0.65
ErrorMethod · 0.45

Tested by

no test coverage detected