Skip to content

edu-8: tweak self-managed installs for resource delays + security men…#35216

Merged
kay-kim merged 2 commits intoMaterializeInc:mainfrom
kay-kim:edu-8-tweak-self-managed-install
Mar 2, 2026
Merged

edu-8: tweak self-managed installs for resource delays + security men…#35216
kay-kim merged 2 commits intoMaterializeInc:mainfrom
kay-kim:edu-8-tweak-self-managed-install

Conversation

@kay-kim
Copy link
Contributor

@kay-kim kay-kim commented Feb 25, 2026

…tion

@kay-kim kay-kim requested a review from a team as a code owner February 25, 2026 18:58
@github-actions
Copy link

Thanks for opening this PR! Here are a few tips to help make the review process smooth for everyone.

PR title guidelines

  • Use imperative mood: "Fix X" not "Fixed X" or "Fixes X"
  • Be specific: "Fix panic in catalog sync when controller restarts" not "Fix bug" or "Update catalog code"
  • Prefix with area if helpful: compute: , storage: , adapter: , sql:

Pre-merge checklist

  • The PR title is descriptive and will make sense in the git log.
  • This PR has adequate test coverage / QA involvement has been duly considered. (trigger-ci for additional test/nightly runs)
  • If this PR includes major user-facing behavior changes, I have pinged the relevant PM to schedule a changelog post.
  • This PR has an associated up-to-date design doc, is a design doc (template), or is sufficiently small to not require a design.
  • If this PR evolves an existing $T ⇔ Proto$T mapping (possibly in a backwards-incompatible way), then it is tagged with a T-proto label.
  • If this PR will require changes to cloud orchestration or tests, there is a companion cloud PR to account for those changes that is tagged with the release-blocker label (example).

It may take approximately 1-2 minutes for all resources to appear in the
namespace. Allow up to 90 seconds before verifying resource creation with
`kubectl get` commands.
{{< /note >}}
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added the little note here

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Did we ever determine if this was just a resource constraint issue, we should have this warning, but honestly we should fix this so it deploys faster.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agree. I believe we opened a github issue https://github.com/MaterializeInc/database-issues/issues/10099 ... although, I wonder if it should be opened now in linear.


{{< /warning >}}

{{< tip >}}
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just added this little blurb so as to plant seed about auth/security.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we just point to the authentication page rather than suggesting SASL/SCRAM? seems more future proof.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can do so.

{{% yaml-table data="self_managed/authentication_setting" %}}

{{< include-md file="shared-content/auth-kind-warning.md" >}}
{{% include-headless
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

https://preview.materialize.com/materialize/35216/security/self-managed/authentication/

  • Reorg to have SASL section before Password auth
  • Some wording tweaks to be more accurate

Comment on lines +32 to +33
SASL authentication requires users to log in with a password. Passwords are
automatically stored in SCRAM-SHA-256 format in the database.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just wondering why we're calling this out, for reference, we do this for password auth as well.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh ... it was there before.
So, double-checking that "this" means both password + sasl will store password in scram-sha-256 format?
So, people who had configured as password can switch to sasl seamlessly?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

^ yup!


{{< /warning >}}

{{< tip >}}
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we just point to the authentication page rather than suggesting SASL/SCRAM? seems more future proof.

Comment on lines +124 to +128
The simple example used in this tutorial enables [Password
authentication](https://github.com/MaterializeInc/materialize-terraform-self-managed/blob/main/azure/examples/simple/main.tf#L340).
To use SASL/SCRAM-SHA-256, set
[`authenticator_kind`](https://github.com/MaterializeInc/materialize-terraform-self-managed/blob/main/kubernetes/modules/materialize-instance/README.md#input_authenticator_kind)
to `"Sasl"`.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here... can we just point to the authentication page rather than recomending SASL/SCRAM

Comment on lines +119 to +126
{{< tip >}}

The simple example used in this tutorial enables [Password
authentication](https://github.com/MaterializeInc/materialize-terraform-self-managed/blob/main/gcp/examples/simple/main.tf#L332).To
use SASL/SCRAM-SHA-256, set
[`authenticator_kind`](https://github.com/MaterializeInc/materialize-terraform-self-managed/blob/main/kubernetes/modules/materialize-instance/README.md#input_authenticator_kind)
to `"Sasl"`.
{{< /tip >}}
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

same

It may take approximately 1-2 minutes for all resources to appear in the
namespace. Allow up to 90 seconds before verifying resource creation with
`kubectl get` commands.
{{< /note >}}
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Did we ever determine if this was just a resource constraint issue, we should have this warning, but honestly we should fix this so it deploys faster.

@kay-kim kay-kim merged commit 39dfc67 into MaterializeInc:main Mar 2, 2026
9 checks passed
@kay-kim kay-kim deleted the edu-8-tweak-self-managed-install branch March 2, 2026 19:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants