feat(cnpg): make better (#496)

This commit is contained in:
Antoine Lecompte
2026-08-19 15:27:09 -04:00
committed by GitHub
parent 569c17ff63
commit 045491d437
34 changed files with 586 additions and 18 deletions
@@ -4,14 +4,25 @@ metadata:
name: {{ .Values.clusterName }}
spec:
instances: {{ .Values.instances }}
imageName: {{ .Values.imageName }}
{{- with .Values.resources }}
resources: {{- toYaml . | nindent 4 }}
{{- end }}
{{- with .Values.affinity }}
affinity: {{- toYaml . | nindent 4 }}
{{- end }}
storage:
size: {{ .Values.storage }}
{{- with .Values.storageClass }}
storageClass: {{ . }}
{{- end }}
{{- if .Values.backup.enabled }}
plugins:
- name: barman-cloud.cloudnative-pg.io
isWALArchiver: true
parameters:
barmanObjectName: {{ .Values.clusterName }}
{{- end }}
bootstrap:
initdb:
database: {{ .Values.database }}
@@ -0,0 +1,25 @@
{{- if .Values.backup.enabled }}
apiVersion: barmancloud.cnpg.io/v1
kind: ObjectStore
metadata:
name: {{ .Values.clusterName }}
spec:
retentionPolicy: {{ .Values.backup.retentionPolicy }}
configuration:
destinationPath: s3://{{ required "backup.bucket is required" .Values.backup.bucket }}/
endpointURL: {{ required "backup.endpointURL is required" .Values.backup.endpointURL }}
endpointCA:
name: {{ required "backup.secretName is required" .Values.backup.secretName }}
key: CA_CERT
s3Credentials:
accessKeyId:
name: {{ .Values.backup.secretName }}
key: ACCESS_KEY_ID
secretAccessKey:
name: {{ .Values.backup.secretName }}
key: ACCESS_SECRET_KEY
wal:
compression: gzip
data:
compression: gzip
{{- end }}
@@ -0,0 +1,15 @@
{{- if .Values.backup.enabled }}
apiVersion: postgresql.cnpg.io/v1
kind: ScheduledBackup
metadata:
name: {{ .Values.clusterName }}-daily
spec:
schedule: {{ .Values.backup.schedule | quote }}
immediate: true
backupOwnerReference: self
cluster:
name: {{ .Values.clusterName }}
method: plugin
pluginConfiguration:
name: barman-cloud.cloudnative-pg.io
{{- end }}
+19
View File
@@ -7,6 +7,25 @@ storage: 1Gi
storageClass: ""
database: yucca
owner: yucca
# Pinned operand image: the operator's compiled-in default changes (and can
# jump Postgres majors) on operator upgrades, so never leave this implicit.
imageName: ghcr.io/cloudnative-pg/postgresql:17.2
# Per-instance postgres pod resources (CNPG spec.resources). Empty = BestEffort
# (dev default); real clusters set this via the HelmRelease.
resources: {}
# CNPG spec.affinity. Real clusters set podAntiAffinityType: required — the
# default "preferred" can co-schedule two instances, and local PVs
# (WaitForFirstConsumer) then pin that co-location permanently.
affinity: {}
# Barman Cloud plugin backups (WAL archiving + daily base backup) to an
# S3-compatible object store. Requires the plugin-barman-cloud release in
# cnpg-system, so dev (no cert-manager, no plugin) keeps this off.
backup:
enabled: false
bucket: ""
endpointURL: ""
# Secret holding ACCESS_KEY_ID / ACCESS_SECRET_KEY / CA_CERT (the RGW
# endpoints use self-signed TLS and barman cannot skip verification).
secretName: ""
retentionPolicy: 30d
schedule: "0 0 2 * * *"