Files
devops-infra-helm-charts-gcp/helm-templates/postgresql/values.yaml
T
Mukul Sharma d4bb8985fb Add a hand-written PostgreSQL chart for toolshed
Not Bitnami's: that registry has been actively unstable here (it broke
Contour twice, infra issue #4) and PostgreSQL publishes no official chart.
A single StatefulSet, PVC and Service is small enough that owning it costs
less than depending on an unstable repackage.

Credentials come from an existing Secret rather than being generated by
the chart — a chart that generates its own password regenerates it on
every render and silently locks you out of the existing volume.

Details that matter and are easy to get wrong:
  - PGDATA is a subdirectory of the mount, not the mount itself. initdb
    refuses to run in a directory that already has contents.
  - Probes run through a shell. Kubernetes does not expand $(VAR) inside
    exec probe commands, only in command/args.
  - fsGroup 70 so the volume stays writable after the entrypoint drops
    from root to the postgres user on the Alpine variant.
  - shared_buffers cut to 32MB from PostgreSQL's 128MB default. The node
    has 8GB and was at its ceiling before this.

Verified with helm template.
2026-09-04 16:21:26 +05:30

46 lines
1.2 KiB
YAML

# Chart defaults. Real configuration lives in
# helm-overrides/k8s-admin-prd-ase1/postgresql/custom-values.yaml.
fullnameOverride: postgresql
image:
# Pulled from Docker Hub, like every other infra component here (gitea,
# vault, harbor). The base-images mirror in Harbor exists to remove
# Docker Hub from the *application build* path and to minimise shipped
# app images — it is not in play for platform components.
repository: postgres
tag: "16-alpine"
pullPolicy: IfNotPresent
# Name of the Secret holding username/password. Created by External
# Secrets from Vault, not by this chart — a chart that generates its own
# database password regenerates it on every render, which silently locks
# you out of an existing volume.
existingSecret: postgresql-credentials
secretKeys:
username: username
password: password
database: toolshed
service:
port: 5432
persistence:
enabled: true
storageClass: local-path
size: 5Gi
# Tuned down hard. The box has 8GB total and is at its ceiling; PostgreSQL's
# default shared_buffers of 128MB is most of this pod's budget on its own.
config:
sharedBuffers: 32MB
maxConnections: "50"
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
memory: 256Mi