Files
pesco-ncr/db/init/01-powerbi-user.sh

30 lines
1.3 KiB
Bash
Raw Normal View History

#!/bin/bash
# Runs once, on first initialization of the MySQL data volume.
# Creates the read-only reporting account used by the Power BI gateway.
#
# MySQL allows table-level grants on objects that do not exist yet, so the
# grants below take effect as soon as Alembic creates the reporting views.
# For an already-initialized database, run scripts/powerbi_grants.sql instead
# (see README → "Power BI").
#
# NOTE: this file must stay executable (git mode 100755). The MySQL image
# *sources* non-executable init scripts into its own entrypoint shell, where
# stray `set` options can break MySQL's startup. The subshell below keeps
# everything scoped even if that happens.
(
set -e
if [ -z "${POWERBI_RO_PASSWORD:-}" ]; then
echo "[init] POWERBI_RO_PASSWORD not set - skipping powerbi_ro user creation."
else
mysql -u root -p"${MYSQL_ROOT_PASSWORD}" <<SQL
CREATE USER IF NOT EXISTS 'powerbi_ro'@'%' IDENTIFIED BY '${POWERBI_RO_PASSWORD}';
GRANT SELECT ON \`${MYSQL_DATABASE}\`.\`vw_ncr_full\` TO 'powerbi_ro'@'%';
GRANT SELECT ON \`${MYSQL_DATABASE}\`.\`vw_ncr_stage_history\` TO 'powerbi_ro'@'%';
GRANT SELECT ON \`${MYSQL_DATABASE}\`.\`vw_ncr_costs\` TO 'powerbi_ro'@'%';
FLUSH PRIVILEGES;
SQL
echo "[init] powerbi_ro user created with SELECT on reporting views."
fi
)