diff --git a/clusters/vad/kustomization.yaml b/clusters/vad/kustomization.yaml index 916ece8..a956f9b 100644 --- a/clusters/vad/kustomization.yaml +++ b/clusters/vad/kustomization.yaml @@ -9,6 +9,7 @@ resources: - ../../infrastructure/istio-gateway/vad - ../../infrastructure/vault/vad - ../../infrastructure/rabbitmq/vad + - ../../infrastructure/postgresql/vad - ../../infrastructure/kafka/vad - ../../infrastructure/camunda/vad - ../../infrastructure/zitadel/vad diff --git a/infrastructure/postgresql/vad/kustomization.yaml b/infrastructure/postgresql/vad/kustomization.yaml new file mode 100644 index 0000000..f7fbc19 --- /dev/null +++ b/infrastructure/postgresql/vad/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ../base +patches: + - path: postgresql.yaml diff --git a/infrastructure/postgresql/vad/postgresql.yaml b/infrastructure/postgresql/vad/postgresql.yaml new file mode 100644 index 0000000..737c604 --- /dev/null +++ b/infrastructure/postgresql/vad/postgresql.yaml @@ -0,0 +1,104 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: postgresql + namespace: postgresql +spec: + interval: 5m + timeout: 2h + + install: + timeout: 2h + remediation: + retries: 3 + + upgrade: + timeout: 2h + remediation: + retries: 3 + + values: + global: + security: + allowInsecureImages: true + defaultStorageClass: local-path + postgresql: + auth: + username: "" + database: "" + secretKeys: + userPasswordKey: "postgres-password" + auth: + username: "" + database: "" + secretKeys: + userPasswordKey: "postgres-password" + image: + registry: cr.yandex/crp3ccidau046kdj8g9q + repository: contour/postgresql + tag: 17.0.7 + pullPolicy: Always + metrics: + enabled: false + prometheusRule: + enabled: false + primary: + automountServiceAccountToken: true + containerSecurityContext: + readOnlyRootFilesystem: false + persistence: + storageClass: local-path + size: 20Gi + customLivenessProbe: + exec: + command: + - /bin/sh + - -c + - exec pg_isready -U "postgres" -d postgres -h 127.0.0.1 -p 5432 + initialDelaySeconds: 30 + periodSeconds: 10 + timeoutSeconds: 5 + successThreshold: 1 + failureThreshold: 6 + customReadinessProbe: + exec: + command: + - /bin/sh + - -c + - exec pg_isready -U "postgres" -d postgres -h 127.0.0.1 -p 5432 + initialDelaySeconds: 5 + periodSeconds: 10 + timeoutSeconds: 5 + successThreshold: 1 + failureThreshold: 6 + customStartupProbe: + exec: + command: + - /bin/sh + - -c + - exec pg_isready -U "postgres" -d postgres -h 127.0.0.1 -p 5432 + initialDelaySeconds: 30 + periodSeconds: 10 + timeoutSeconds: 5 + successThreshold: 1 + failureThreshold: 6 + nodeSelector: + dedicated: generic + tolerations: [] + contour: + enabled: true + adminUser: "postgres" + vault: + enabled: true + role: postgresql + authPath: auth/kubernetes + secretPath: secrets/data/postgresql/admin + secretKey: postgres-password + usersSecretPath: secrets/data/postgresql/users + sharedPreloadLibraries: "timescaledb,pg_stat_statements" + databases: + - name: zitadel + user: zitadel + passwordKey: zitadel + extensions: [] + restoreFromDump: false diff --git a/infrastructure/zitadel/vad/zitadel.yaml b/infrastructure/zitadel/vad/zitadel.yaml index f54d6d2..0c24dbd 100644 --- a/infrastructure/zitadel/vad/zitadel.yaml +++ b/infrastructure/zitadel/vad/zitadel.yaml @@ -6,6 +6,9 @@ metadata: spec: interval: 5m timeout: 10m + dependsOn: + - name: postgresql + namespace: postgresql postRenderers: - kustomize: patches: @@ -133,7 +136,7 @@ spec: - name: ZITADEL_MACHINE_IDENTIFICATION_HOSTNAME_ENABLED value: "true" - name: ZITADEL_DATABASE_POSTGRES_HOST - value: "192.168.8.131" + value: "postgresql.postgresql.svc.cluster.local" - name: ZITADEL_DATABASE_POSTGRES_PORT value: "5432" - name: ZITADEL_DATABASE_POSTGRES_USER_USERNAME