Greenmask 0.2.24
Changes
- feat: add the HashedPassword transformer. It writes a bcrypt hash of one known password into a column, so test accounts can log in after the restore. The password is read from an environment variable via
resolve_env, so it stays out of the config and the dump #482. Closes #480 - feat: add server-side encryption for the S3 storage. The new
sseparameter sets the encryption mode (AES256,aws:kmsoraws:kms:dsse),kms_key_arnselects the KMS key for the KMS-backed modes, andbucket_key_enabledturns on S3 Bucket Keys to cut KMS request cost on large dumps. Encryption is applied to both single-part and multipart uploads, so dumps larger thanmax_part_sizeare covered as well #473 #484 - feat: forward PostgreSQL notices to the log. Messages raised with
RAISE NOTICEorRAISE WARNINGwere previously discarded at every log level. Notices from restore scripts are logged between theexecuting scriptandscript execution completeentries:WARNINGatwarn,NOTICE,INFOandLOGatinfo,DEBUGatdebug#479. Notices raised while dumping or restoring table data (for example by row-level triggers) are tagged with the worker id and logged atdebug, exceptWARNING, which stays atwarn, so a trigger raising one notice per row does not flood the log #485 - fix: validate the S3 storage config before the dump starts. An unknown
ssevalue now fails immediately instead of on the first upload, once the dump has already been produced. Settingkms_key_arnorbucket_key_enabledwithout a KMS-backedsseis rejected as well — previously the KMS key was silently dropped and the dump was encrypted with a key other than the configured one #484 - fix: use the upstream Minio image for the integration test storage service #483
- docs: extend the supporting a new PostgreSQL version guide #477
Full Changelog: v0.2.23...v0.2.24
Contributors
@YauhenBichel
@Jadyn-Iinuma-AuditBoard
@lukasbaumgart
@wwoytenko
Links
Feel free to reach out to us if you have any questions or need assistance: