Overarching Goal:
- Create an ojo_auth function that is nice to use interactively to set up an analysts personal, long-lived workspace.
- Use the same function to authenticate programatically in a deployed setting, especially github actions and google cloud run instances
Currently, ojo_auth:
- Gets system home env var
- Looks for system .Renviron file
- Looks for system ssl certs
- Expects them to be in a very specific location,
$HOME/.postgresql/ojodb/*
- Errors is they aren't found
- Toggles on whether to edit the .Renvironment file permanently
- If yes:
- Creates a backup if a sys .Renviron exists
- Toggles on whether to overwrite this file
- If yes, will remove
OJO_ env vars before proceeding
- If no, error
- Creates a new sys .Renviron if not
- Writes .Renviron fields
- Hardcodes
verify-ca as SSL_MODE
- If no:
- Uses
Sys.setenv to set values temporarily
It wants to, but doesn't succeed in:
- Allowing for an admin vs default user setup
- Mostly not working because role switching isn't set up downstream
It maybe shouldn't:
- Handle admin vs default since this can be toggled at the ojo_connect layer via sql, independent of base auth config
- Edit the .Renviron directly
It needs to:
- Gracefully handle windows paths
- Not hardcode ssl cert location
- Allow locations or individual file paths to be passed for ssl certs
- Should be able to ingest from
- Function Arguments
- Config/yaml file
- Renviron
- System Env Variables
It could:
- Set file mode (0600) of ssl key
- Read ojodb specific R options
- Get ssl certs via bitwarden vault
- Integrate deeply with googlesecretmanager
- Use a special list argument that helps build config values
- This pattern allows easier change of arguments required, etc.
- Could be used by bitwarden/secretmanager packages or helpers to inject their values directly by producing the correct list
- Have no breaking changes
Overarching Goal:
Currently,
ojo_auth:$HOME/.postgresql/ojodb/*OJO_env vars before proceedingverify-caas SSL_MODESys.setenvto set values temporarilyIt wants to, but doesn't succeed in:
It maybe shouldn't:
It needs to:
It could: