Changing database server password in Containerized PostgreSQL (AWS and Azure)
- Exec into primary pod and change database password using the following command:
$ kubectl exec -it <primary-pod-name> -n netbackup -- bash
# /usr/openv/db/bin/nbdb_admin -dba "<new-password>"
# exit
- Update the database connection secret with new password:
Set the new password:
$ kubectl patch secret <secret-name> -n netbackup -p '{"stringData": {"dbadminpassword": "<new-password>" }}'
Verify the new password:
$ kubectl get secret <secret-name> -n netbackup -o jsonpath='{.data.dbadminpassword}' | base64 --decode
- Restart the Postgres and primary pods:
Identify Postgres and primary statefulsets:
$ kubectl get statefulset -n netbackup
Restart Postgres pod:
$ kubectl rollout restart "statefulset/nb-postgresql" -n netbackup
Wait for the Postgres pod to restart:
$ kubectl rollout status --watch --timeout=600s "statefulset/nb-postgresql" -n netbackup
Restart primary pod:
$ kubectl rollout restart "statefulset/<primary-statefulset>" -n netbackup
Wait for primary pod to restart:
$ kubectl rollout status --watch --timeout=600s "statefulset/<primary-statefulset>" -n netbackup
- (For Cloud Scale with decoupled web services only) Restart the web services pod:
Identify nbwsapp statefulset:
kubectl get statefulset -n netbackup
Restart nbwsapp pod:
kubectl rollout restart "statefulset/<nbwsapp-statefulset>" -n netbackup
Wait for the nbswapp pod to restart:
kubectl rollout status --watch --timeout=600s "statefulset/<nbwsapp-statefulset>" -n netbackup
- (For Cloud Scale with decoupled bpdbm services only) Restart the bpdbm services pod:
Identify bpdbm statefulset:
kubectl get statefulset -n netbackup
Restart bpdbm pod:
kubectl rollout restart "statefulset/<bpdbm-statefulset>" -n netbackup
Wait for the bpdbm pod to restart:
kubectl rollout status --watch --timeout=600s "statefulset/<bpdbm-statefulset>" -n netbackup