fix: MQTTAuth device lookup by Spec.DeviceID + PG15+ GRANT (v0.2.5)

- MQTTAuth: replaced Get(Name=deviceID) with List+filter by Spec.DeviceID
  (K8s object name != deviceID — caused deny for all devices)
- EnsureTenantDB: added GRANT role TO CURRENT_USER before CREATE DATABASE OWNER
  (PG15+ requires SET ROLE privileges for target owner)
- Image: naeel/iot-operator:v0.2.5
- E2E test passed: device create → MQTT publish → SQS → Postgres → REST API
This commit is contained in:
Naeel
2026-04-12 19:00:56 +03:00
parent d5a177e23c
commit f0cc6df9a6
7 changed files with 73 additions and 8 deletions
+2 -2
View File
@@ -3,7 +3,7 @@
#
# Компоненты:
# - ServiceAccount + ClusterRole + ClusterRoleBinding (RBAC для CRD controller)
# - Deployment: naeel/iot-operator:v0.2.3
# - Deployment: naeel/iot-operator:v0.2.5
# - Service: ClusterIP :9090 (REST API, MQTT auth/acl, admin UI)
#
# iot-operator обслуживает:
@@ -85,7 +85,7 @@ spec:
serviceAccountName: iot-operator
containers:
- name: operator
image: naeel/iot-operator:v0.2.3
image: naeel/iot-operator:v0.2.5
imagePullPolicy: Always
ports:
- name: api