++ deploy dedicated in-cluster postgres for zitadel, point zitadel at it

This commit is contained in:
Kochetkov S 2026-08-26 14:22:02 +03:00
parent 2bbf786aa6
commit b911b7ea50
4 changed files with 115 additions and 1 deletions

View File

@ -9,6 +9,7 @@ resources:
- ../../infrastructure/istio-gateway/vad
- ../../infrastructure/vault/vad
- ../../infrastructure/rabbitmq/vad
- ../../infrastructure/postgresql/vad
- ../../infrastructure/kafka/vad
- ../../infrastructure/camunda/vad
- ../../infrastructure/zitadel/vad

View File

@ -0,0 +1,6 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: postgresql.yaml

View File

@ -0,0 +1,104 @@
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: postgresql
namespace: postgresql
spec:
interval: 5m
timeout: 2h
install:
timeout: 2h
remediation:
retries: 3
upgrade:
timeout: 2h
remediation:
retries: 3
values:
global:
security:
allowInsecureImages: true
defaultStorageClass: local-path
postgresql:
auth:
username: ""
database: ""
secretKeys:
userPasswordKey: "postgres-password"
auth:
username: ""
database: ""
secretKeys:
userPasswordKey: "postgres-password"
image:
registry: cr.yandex/crp3ccidau046kdj8g9q
repository: contour/postgresql
tag: 17.0.7
pullPolicy: Always
metrics:
enabled: false
prometheusRule:
enabled: false
primary:
automountServiceAccountToken: true
containerSecurityContext:
readOnlyRootFilesystem: false
persistence:
storageClass: local-path
size: 20Gi
customLivenessProbe:
exec:
command:
- /bin/sh
- -c
- exec pg_isready -U "postgres" -d postgres -h 127.0.0.1 -p 5432
initialDelaySeconds: 30
periodSeconds: 10
timeoutSeconds: 5
successThreshold: 1
failureThreshold: 6
customReadinessProbe:
exec:
command:
- /bin/sh
- -c
- exec pg_isready -U "postgres" -d postgres -h 127.0.0.1 -p 5432
initialDelaySeconds: 5
periodSeconds: 10
timeoutSeconds: 5
successThreshold: 1
failureThreshold: 6
customStartupProbe:
exec:
command:
- /bin/sh
- -c
- exec pg_isready -U "postgres" -d postgres -h 127.0.0.1 -p 5432
initialDelaySeconds: 30
periodSeconds: 10
timeoutSeconds: 5
successThreshold: 1
failureThreshold: 6
nodeSelector:
dedicated: generic
tolerations: []
contour:
enabled: true
adminUser: "postgres"
vault:
enabled: true
role: postgresql
authPath: auth/kubernetes
secretPath: secrets/data/postgresql/admin
secretKey: postgres-password
usersSecretPath: secrets/data/postgresql/users
sharedPreloadLibraries: "timescaledb,pg_stat_statements"
databases:
- name: zitadel
user: zitadel
passwordKey: zitadel
extensions: []
restoreFromDump: false

View File

@ -6,6 +6,9 @@ metadata:
spec:
interval: 5m
timeout: 10m
dependsOn:
- name: postgresql
namespace: postgresql
postRenderers:
- kustomize:
patches:
@ -133,7 +136,7 @@ spec:
- name: ZITADEL_MACHINE_IDENTIFICATION_HOSTNAME_ENABLED
value: "true"
- name: ZITADEL_DATABASE_POSTGRES_HOST
value: "192.168.8.131"
value: "postgresql.postgresql.svc.cluster.local"
- name: ZITADEL_DATABASE_POSTGRES_PORT
value: "5432"
- name: ZITADEL_DATABASE_POSTGRES_USER_USERNAME