From a172c355c26aaa171ae93ac8f9f790271d373761 Mon Sep 17 00:00:00 2001 From: tcondeixa Date: Wed, 22 Jul 2026 11:13:32 +0200 Subject: [PATCH 1/5] inject IRSA credentials into wal-g envdir for standby and clone clusters --- postgres-appliance/scripts/configure_spilo.py | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/postgres-appliance/scripts/configure_spilo.py b/postgres-appliance/scripts/configure_spilo.py index 61f00acfa..f0032b861 100755 --- a/postgres-appliance/scripts/configure_spilo.py +++ b/postgres-appliance/scripts/configure_spilo.py @@ -917,6 +917,12 @@ def write_walg_environment(placeholders, prefix, overwrite): if placeholders.get(name): walg[name] = placeholders.get(name) + # fall back to bare IRSA vars if prefixed versions are not set + irsa_names = ['AWS_ROLE_ARN', 'AWS_WEB_IDENTITY_TOKEN_FILE', 'AWS_STS_REGIONAL_ENDPOINTS'] + for name in irsa_names: + if not walg.get(name) and placeholders.get(name): + walg[name] = placeholders.get(name) + write_envdir_names = s3_names + walg_names + aws_imds_names elif walg.get('WAL_GS_BUCKET') or walg.get('WALG_GS_PREFIX'): write_envdir_names = gs_names + walg_names From 24708a28a9dc5f8dd6b0ab3863baae991775289c Mon Sep 17 00:00:00 2001 From: tcondeixa Date: Wed, 2 Sep 2026 15:31:16 +0200 Subject: [PATCH 2/5] Fix AWS_ACCESS_KEY_ID being overwritten with S3 prefix when using IRSA --- postgres-appliance/scripts/configure_spilo.py | 3 --- 1 file changed, 3 deletions(-) diff --git a/postgres-appliance/scripts/configure_spilo.py b/postgres-appliance/scripts/configure_spilo.py index f0032b861..8f72bbd66 100755 --- a/postgres-appliance/scripts/configure_spilo.py +++ b/postgres-appliance/scripts/configure_spilo.py @@ -965,9 +965,6 @@ def write_walg_environment(placeholders, prefix, overwrite): bucket_path = '/spilo/{WAL_BUCKET_SCOPE_PREFIX}{SCOPE}{WAL_BUCKET_SCOPE_SUFFIX}/wal/{PGVERSION}'.format(**walg) prefix_template = '{0}://{{WAL_{1}_BUCKET}}{2}'.format(store_type.lower(), store_type, bucket_path) walg[prefix_env_name] = prefix_template.format(**walg) - # Set WALG_*_PREFIX for future compatibility - if store_type in ('S3', 'GS') and not walg.get(write_envdir_names[1]): - walg[write_envdir_names[1]] = walg[prefix_env_name] if not os.path.exists(walg['WALG_ENV_DIR']): os.makedirs(walg['WALG_ENV_DIR']) From 560eece145ea4a7e1d3dc411653e004dbb09404c Mon Sep 17 00:00:00 2001 From: tcondeixa Date: Wed, 2 Sep 2026 16:15:14 +0200 Subject: [PATCH 3/5] Fix AWS_REGION extracted from path instead of bucket name when PGVERSION unknown --- postgres-appliance/scripts/configure_spilo.py | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/postgres-appliance/scripts/configure_spilo.py b/postgres-appliance/scripts/configure_spilo.py index 8f72bbd66..fe9e5baba 100755 --- a/postgres-appliance/scripts/configure_spilo.py +++ b/postgres-appliance/scripts/configure_spilo.py @@ -895,9 +895,12 @@ def write_walg_environment(placeholders, prefix, overwrite): if aws_region: walg['AWS_REGION'] = aws_region elif not aws_region: - # try to determine region from the endpoint or bucket name - name = walg.get('WAL_S3_BUCKET') or walg.get('WALG_S3_PREFIX') - match = re.search(r'.*(\w{2}-\w+-\d)-.*', name) + # try to determine region from the bucket name + prefix = walg.get('WAL_S3_BUCKET') or walg.get('WALG_S3_PREFIX') or '' + # extract bucket name only to avoid false matches on path segments (e.g. /wal/ suffix) + bucket_match = re.match(r'^(?:s3://)?([^/]+)', prefix) + name = bucket_match.group(1) if bucket_match else prefix + match = re.search(r'(\w{2}-\w+-\d)-', name) if match: aws_region = match.group(1) else: From 76119c0fadf6c7eeaaf2af1e77f1b92d43712926 Mon Sep 17 00:00:00 2001 From: tcondeixa Date: Wed, 2 Sep 2026 16:45:19 +0200 Subject: [PATCH 4/5] Fall back to bare AWS_REGION when CLONE_AWS_REGION is not set --- postgres-appliance/scripts/configure_spilo.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/postgres-appliance/scripts/configure_spilo.py b/postgres-appliance/scripts/configure_spilo.py index fe9e5baba..f28651300 100755 --- a/postgres-appliance/scripts/configure_spilo.py +++ b/postgres-appliance/scripts/configure_spilo.py @@ -921,7 +921,7 @@ def write_walg_environment(placeholders, prefix, overwrite): walg[name] = placeholders.get(name) # fall back to bare IRSA vars if prefixed versions are not set - irsa_names = ['AWS_ROLE_ARN', 'AWS_WEB_IDENTITY_TOKEN_FILE', 'AWS_STS_REGIONAL_ENDPOINTS'] + irsa_names = ['AWS_ROLE_ARN', 'AWS_WEB_IDENTITY_TOKEN_FILE', 'AWS_STS_REGIONAL_ENDPOINTS', 'AWS_REGION'] for name in irsa_names: if not walg.get(name) and placeholders.get(name): walg[name] = placeholders.get(name) From a23f25e69d2741a5ee64357cf958f21c056e5eb9 Mon Sep 17 00:00:00 2001 From: tcondeixa Date: Tue, 8 Sep 2026 12:17:55 +0200 Subject: [PATCH 5/5] fix local variable shadowing function parameter prefix in write_walg_environment Signed-off-by: tcondeixa --- postgres-appliance/scripts/configure_spilo.py | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/postgres-appliance/scripts/configure_spilo.py b/postgres-appliance/scripts/configure_spilo.py index f28651300..ec92a9b46 100755 --- a/postgres-appliance/scripts/configure_spilo.py +++ b/postgres-appliance/scripts/configure_spilo.py @@ -896,10 +896,10 @@ def write_walg_environment(placeholders, prefix, overwrite): walg['AWS_REGION'] = aws_region elif not aws_region: # try to determine region from the bucket name - prefix = walg.get('WAL_S3_BUCKET') or walg.get('WALG_S3_PREFIX') or '' + bucket_or_prefix = walg.get('WAL_S3_BUCKET') or walg.get('WALG_S3_PREFIX') or '' # extract bucket name only to avoid false matches on path segments (e.g. /wal/ suffix) - bucket_match = re.match(r'^(?:s3://)?([^/]+)', prefix) - name = bucket_match.group(1) if bucket_match else prefix + bucket_match = re.match(r'^(?:s3://)?([^/]+)', bucket_or_prefix) + name = bucket_match.group(1) if bucket_match else bucket_or_prefix match = re.search(r'(\w{2}-\w+-\d)-', name) if match: aws_region = match.group(1)