SecurityConfiguration.HasData declares 4 LdapGroupMapping seed rows (Admin / Design / Deployment-All / Deployment-SiteA) but the InitialSchema migration only INSERTs the Admin row -- the other three were never captured into a migration. A fresh ScadaLinkConfig2 starts with multi-role getting Admin only, no Design or Deployment access. (The same divergence exists on primary's ScadaLinkConfig, but it has the rows from earlier history.) Insert the missing three idempotently from seed-sites.sh so env2's fresh deploys end up role-aligned with the running primary cluster. The longer-term fix is a new EF migration that captures the HasData diff -- intentionally not done here to avoid touching the primary cluster's existing rows.
2.6 KiB
Executable File
2.6 KiB
Executable File