A plain CREATE ROLE ... PASSWORD stores PostgreSQL's native 16-byte SCRAM salt. DocumentDB has no check_password_hook, so that salt is served verbatim to Mongo clients, which reject it at SASL step2 with 'invalid salt length of 16'. Provision the user through documentdb_api.create_user / update_user instead: DocumentDB builds the SCRAM-SHA-256 verifier with documentdb.scramDefaultSaltLen (28 bytes) via its own scram_build_secret. create_user only accepts a read-only role or the clusterAdmin + readWriteAnyDatabase pair, so use the latter for R/W. - CREATE EXTENSION documentdb now runs before user provisioning so the API functions exist. - Spec built with jq (password JSON-escaped) and passed in a $DDB$ dollar-quoted SQL literal; idempotent via update_user when the role already exists. - Set password_encryption = 'scram-sha-256' explicitly in postgresql.conf.
27 KiB
Executable File
27 KiB
Executable File