Finish RPF-WP-0018; RPF-WP-0019 repository-complete
RPF-WP-0018 closed: all seven tasks done. The provider-declaration finding was adopted upstream and its canonical form is the provider: block in tenancy.yaml; adaptive-pricing declined the standing co-signature and supplied typed tier minima instead, recorded in ADR-0002. Three corrections against our own output are recorded in the documents rather than edited away. RPF-WP-0019 T03 done (ceiling of three, memory binding, apps-pg-2 named as overflow, enforced by make apps-pg-verify-capacity). T01/T02 are repository-complete: backup target, retention, per-consumer connection limits, role timeouts and Burstable resources are declared in source and published in s3-consumer-interfaces 1.1.0 before rollout. They stay in progress because no live application, backup success or restore proof exists, and declared configuration is not a section 13 artifact. T04 waits on that window. apps-pg R reason corrected to say the target is declared-not-applied rather than absent. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
e52ae26001
commit
dc4245361d
20 changed files with 650 additions and 73 deletions
14
helm/apps-pg-2-backup.yaml
Normal file
14
helm/apps-pg-2-backup.yaml
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
apiVersion: postgresql.cnpg.io/v1
|
||||
kind: ScheduledBackup
|
||||
metadata:
|
||||
name: apps-pg-2-daily
|
||||
namespace: databases
|
||||
labels:
|
||||
cnpg.io/cluster: apps-pg-2
|
||||
spec:
|
||||
schedule: "0 15 2 * * *"
|
||||
backupOwnerReference: self
|
||||
cluster:
|
||||
name: apps-pg-2
|
||||
immediate: true
|
||||
method: barmanObjectStore
|
||||
45
helm/apps-pg-2-cluster.yaml
Normal file
45
helm/apps-pg-2-cluster.yaml
Normal file
|
|
@ -0,0 +1,45 @@
|
|||
# Provisionable overflow cell for the apps-pg three-consumer ceiling.
|
||||
# Do not apply while empty; see docs/apps-pg.md.
|
||||
apiVersion: postgresql.cnpg.io/v1
|
||||
kind: Cluster
|
||||
metadata:
|
||||
name: apps-pg-2
|
||||
namespace: databases
|
||||
labels:
|
||||
app.kubernetes.io/name: apps-pg-2
|
||||
app.kubernetes.io/component: database
|
||||
app.kubernetes.io/managed-by: manual
|
||||
railiance.io/layer: s3-platform
|
||||
railiance.io/role: shared-apps-database
|
||||
spec:
|
||||
instances: 1
|
||||
imageName: ghcr.io/cloudnative-pg/postgresql:16
|
||||
resources:
|
||||
requests: {cpu: 100m, memory: 256Mi}
|
||||
limits: {cpu: "1", memory: 1Gi}
|
||||
storage:
|
||||
size: 10Gi
|
||||
bootstrap:
|
||||
initdb:
|
||||
database: apps_meta
|
||||
owner: apps_admin
|
||||
secret:
|
||||
name: apps-pg-2-credentials
|
||||
postgresql:
|
||||
parameters:
|
||||
max_connections: "100"
|
||||
log_connections: "on"
|
||||
log_disconnections: "on"
|
||||
log_lock_waits: "on"
|
||||
log_min_duration_statement: "1000"
|
||||
track_io_timing: "on"
|
||||
backup:
|
||||
retentionPolicy: "30d"
|
||||
barmanObjectStore:
|
||||
destinationPath: s3://railiance-platform-pg-backup/apps-pg-2/
|
||||
endpointURL: https://s3.nl-ams.scw.cloud
|
||||
s3Credentials:
|
||||
accessKeyId: {name: platform-pg-backup-s3, key: ACCESS_KEY_ID}
|
||||
secretAccessKey: {name: platform-pg-backup-s3, key: ACCESS_SECRET_KEY}
|
||||
wal: {compression: gzip, maxParallel: 2}
|
||||
data: {compression: gzip, jobs: 2}
|
||||
54
helm/apps-pg-2-networkpolicies.yaml
Normal file
54
helm/apps-pg-2-networkpolicies.yaml
Normal file
|
|
@ -0,0 +1,54 @@
|
|||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
metadata:
|
||||
name: allow-egress-kube-api-apps-pg-2
|
||||
namespace: databases
|
||||
spec:
|
||||
podSelector:
|
||||
matchLabels: {cnpg.io/cluster: apps-pg-2}
|
||||
policyTypes: [Egress]
|
||||
egress:
|
||||
- ports:
|
||||
- {port: 443, protocol: TCP}
|
||||
- {port: 6443, protocol: TCP}
|
||||
- to:
|
||||
- namespaceSelector:
|
||||
matchLabels: {kubernetes.io/metadata.name: kube-system}
|
||||
ports:
|
||||
- {port: 53, protocol: UDP}
|
||||
- {port: 53, protocol: TCP}
|
||||
---
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
metadata:
|
||||
name: allow-ingress-from-cnpg-operator-apps-pg-2
|
||||
namespace: databases
|
||||
spec:
|
||||
podSelector:
|
||||
matchLabels: {cnpg.io/cluster: apps-pg-2}
|
||||
policyTypes: [Ingress]
|
||||
ingress:
|
||||
- from:
|
||||
- namespaceSelector:
|
||||
matchLabels: {kubernetes.io/metadata.name: cnpg-system}
|
||||
ports:
|
||||
- {port: 5432, protocol: TCP}
|
||||
- {port: 8000, protocol: TCP}
|
||||
- {port: 9187, protocol: TCP}
|
||||
---
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
metadata:
|
||||
name: allow-ingress-from-app-namespaces-apps-pg-2
|
||||
namespace: databases
|
||||
spec:
|
||||
podSelector:
|
||||
matchLabels: {cnpg.io/cluster: apps-pg-2}
|
||||
policyTypes: [Ingress]
|
||||
ingress:
|
||||
- from:
|
||||
- namespaceSelector:
|
||||
matchLabels: {railiance.io/postgres-client: apps-pg-2}
|
||||
podSelector: {}
|
||||
ports:
|
||||
- {port: 5432, protocol: TCP}
|
||||
14
helm/apps-pg-backup.yaml
Normal file
14
helm/apps-pg-backup.yaml
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
apiVersion: postgresql.cnpg.io/v1
|
||||
kind: ScheduledBackup
|
||||
metadata:
|
||||
name: apps-pg-daily
|
||||
namespace: databases
|
||||
labels:
|
||||
cnpg.io/cluster: apps-pg
|
||||
spec:
|
||||
schedule: "0 15 2 * * *"
|
||||
backupOwnerReference: self
|
||||
cluster:
|
||||
name: apps-pg
|
||||
immediate: true
|
||||
method: barmanObjectStore
|
||||
|
|
@ -26,6 +26,13 @@ metadata:
|
|||
spec:
|
||||
instances: 1 # bump to 3 when node RAM > 8GB
|
||||
imageName: ghcr.io/cloudnative-pg/postgresql:16
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 256Mi
|
||||
limits:
|
||||
cpu: "1"
|
||||
memory: 1Gi
|
||||
storage:
|
||||
size: 10Gi
|
||||
bootstrap:
|
||||
|
|
@ -43,14 +50,41 @@ spec:
|
|||
- name: vergabe # RAILIANCE-WP-0002 T04 (vergabe-teilnahme)
|
||||
ensure: present
|
||||
login: true
|
||||
connectionLimit: 20
|
||||
passwordSecret:
|
||||
name: vergabe-app-credentials
|
||||
- name: coulomb_social # CSOC-WP-0002 (coulomb-social)
|
||||
|
||||
ensure: present
|
||||
login: true
|
||||
connectionLimit: 20
|
||||
passwordSecret:
|
||||
name: coulomb-social-app-credentials
|
||||
postgresql:
|
||||
parameters:
|
||||
max_connections: "100"
|
||||
log_connections: "on"
|
||||
log_disconnections: "on"
|
||||
log_lock_waits: "on"
|
||||
log_min_duration_statement: "1000"
|
||||
track_io_timing: "on"
|
||||
backup:
|
||||
retentionPolicy: "30d"
|
||||
barmanObjectStore:
|
||||
destinationPath: s3://railiance-platform-pg-backup/apps-pg/
|
||||
endpointURL: https://s3.nl-ams.scw.cloud
|
||||
s3Credentials:
|
||||
accessKeyId:
|
||||
name: platform-pg-backup-s3
|
||||
key: ACCESS_KEY_ID
|
||||
secretAccessKey:
|
||||
name: platform-pg-backup-s3
|
||||
key: ACCESS_SECRET_KEY
|
||||
wal:
|
||||
compression: gzip
|
||||
maxParallel: 2
|
||||
data:
|
||||
compression: gzip
|
||||
jobs: 2
|
||||
# HA replica + connection pooler are deferred (RAILIANCE-WP-0003 Notes):
|
||||
# services:
|
||||
# additional:
|
||||
|
|
|
|||
7
helm/apps-pg-consumer-controls.sql
Normal file
7
helm/apps-pg-consumer-controls.sql
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
-- Idempotent controls not expressible in the installed CNPG managed.roles CRD.
|
||||
-- Apply as the controlled apps-pg cluster administrator only after notifying
|
||||
-- both consumers of the published limits in docs/s3-consumer-interfaces.md.
|
||||
ALTER ROLE vergabe SET statement_timeout = '15s';
|
||||
ALTER ROLE vergabe SET idle_in_transaction_session_timeout = '15s';
|
||||
ALTER ROLE coulomb_social SET statement_timeout = '15s';
|
||||
ALTER ROLE coulomb_social SET idle_in_transaction_session_timeout = '15s';
|
||||
|
|
@ -22,8 +22,19 @@ spec:
|
|||
- Egress
|
||||
egress:
|
||||
- ports:
|
||||
- port: 443
|
||||
protocol: TCP
|
||||
- port: 6443
|
||||
protocol: TCP
|
||||
- to:
|
||||
- namespaceSelector:
|
||||
matchLabels:
|
||||
kubernetes.io/metadata.name: kube-system
|
||||
ports:
|
||||
- port: 53
|
||||
protocol: UDP
|
||||
- port: 53
|
||||
protocol: TCP
|
||||
---
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue