Skip to content

PBS-8: Introduce <replication_source.authentication> section into the main configuration file - #188

Merged
kamil-holubicki merged 2 commits into
Percona-Lab:mainfrom
kamil-holubicki:PBS-8
Sep 23, 2026
Merged

kamil-holubicki merged 2 commits into
Percona-Lab:mainfrom
kamil-holubicki:PBS-8

Conversation

@kamil-holubicki

Copy link
Copy Markdown
Contributor

No description provided.

# --let $binsrv_encryption_cipher = AES-256-CTR (optional)
# --let $binsrv_encryption_kek_id = alpha (optional)
# --let $binsrv_keyring_data_file_path = $MYSQL_TMP_DIR/keyring_data.json (optional)
# --source set_up_binsrv_environment.inc

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please, add $binsrv_auth_user and $binsrv_auth_password with default values

if ($binsrv_auth_user == '"")
{
  --let $binsrv_auth_user = rpl
}
if ($binsrv_auth_password == "")
{
  --let $binsrv_auth_password = password
}

This way we will be able to reference $binsrv_auth_user / $binsrv_auth_password from the MTR test cases instead of using hardcoded values.

util::exception_location().raise<std::invalid_argument>(
"error validating replication source authentication config: "
"plugin must be \"caching_sha2_password\"");
}

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

password must not be empty

Comment thread README.md Outdated
#### \<replication_source.authentication\> section
Credentials the built-in listener accepts from downstream replicas.
- `<replication_source.authentication.user>` - the MySQL account name a downstream replica must present to log in to the listener (must not be empty).
- `<replication_source.authentication.password>` - the password associated with that account. May be an empty string, matching the MySQL semantics of "no password".

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Update the "may be empty" part.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

kamil-holubicki and others added 2 commits September 22, 2026 15:49
Introduce a new nested "authentication" block under
"replication_source" that carries the credentials the built-in PBS
listener accepts from downstream replicas.

The network_service constructor is collapsed from four positional
parameters (port, read_timeout, write_timeout, username, password)
into a single parameter.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
generate_binsrv_config.inc now writes the new nested "authentication"
block inside the "replication_source" section it emits for every
pull-mode MTR test. The values reuse the credentials the tests
already spoke to the listener with:

  "authentication": {
    "user": "rpl",
    "password": "password",
    "plugin": "caching_sha2_password"
  }

That matches what auth_method_switch.test passes to its mysql client
(--user=rpl --password=password) and what pull_operation used to
hard-code, so no per-test changes are needed - only the shared
include grows a block.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

@percona-ysorokin percona-ysorokin left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@kamil-holubicki
kamil-holubicki merged commit 0dfafe1 into Percona-Lab:main Sep 23, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants