Password Change Procedure for Couchbase Buckets

Viewed 148

I have both memcached and Couchbase buckets on a Version 4 Couchbase Community Edition Server. Our buckets have passwords (the "SASL auth" kind) and it is time to change those passwords. The normal procedure we use for this kind of thing is to...

  1. create a new account on the shared resource.
  2. redeploy the clients with the new account's credentials.
  3. once, all clients are using the new credentials, delete/disable the original account.

However, with Couchbase, I don't see a way to create a new Bucket account. If I just change the password on the server everything using that server (even the high-availability stuff) will stop working until it can be redeployed.

I hate to have to scheduled down-time for something like this. Is there some kind of migration-process recommendation I have missed?

1 Answers

Unfortunately, it doesn't seem like a "one bucket, two passwords" approach is possible with SASL-authenticated buckets. You might be able to hack your way there with LDAP or PAM, but it doesn't sound like you're using either.

However, it would appear that something like this behavior is supported in the upcoming version 5 (which allegedly has a developer release out, but I am unable to find a download). In version 5, you would be able to create two users with different passwords, and alternate your clients between them, updating the password on the off-cycle account whenever you switch.

Related