Not Bitnami's: that registry has been actively unstable here (it broke Contour twice, infra issue #4) and PostgreSQL publishes no official chart. A single StatefulSet, PVC and Service is small enough that owning it costs less than depending on an unstable repackage. Credentials come from an existing Secret rather than being generated by the chart — a chart that generates its own password regenerates it on every render and silently locks you out of the existing volume. Details that matter and are easy to get wrong: - PGDATA is a subdirectory of the mount, not the mount itself. initdb refuses to run in a directory that already has contents. - Probes run through a shell. Kubernetes does not expand $(VAR) inside exec probe commands, only in command/args. - fsGroup 70 so the volume stays writable after the entrypoint drops from root to the postgres user on the Alpine variant. - shared_buffers cut to 32MB from PostgreSQL's 128MB default. The node has 8GB and was at its ceiling before this. Verified with helm template.
19 lines
696 B
YAML
19 lines
696 B
YAML
apiVersion: v2
|
|
name: postgresql
|
|
description: |
|
|
Single-instance PostgreSQL for this homelab.
|
|
|
|
Hand-written rather than vendoring Bitnami's chart: Broadcom has been
|
|
retiring and freezing images behind that repo (see claude.md infra issue
|
|
#4, where it broke Contour twice), and PostgreSQL publishes no official
|
|
Helm chart of its own. A single StatefulSet with one PVC is small enough
|
|
that owning it outright costs less than depending on an unstable
|
|
repackage.
|
|
|
|
Not highly available and not intended to be. One replica, one PVC, no
|
|
replication, no connection pooler. Adding any of those to a single-node
|
|
cluster would be theatre.
|
|
type: application
|
|
version: 0.1.0
|
|
appVersion: "16"
|