# Schema migration as a Job, not an init container and not a start-up hook. # Running migrations at start-up races between replicas and couples a rollback # of the code to a rollback of the schema. The Job name carries the target # revision so a re-apply at the same revision is a no-op rather than a rerun. apiVersion: batch/v1 kind: Job metadata: name: canned-prompts-schema-migration-0002 namespace: canned-prompts labels: app.kubernetes.io/name: canned-prompts-migration app.kubernetes.io/component: migration spec: backoffLimit: 2 ttlSecondsAfterFinished: 86400 template: metadata: labels: app.kubernetes.io/name: canned-prompts-migration spec: automountServiceAccountToken: false restartPolicy: Never securityContext: runAsNonRoot: true runAsUser: 10001 runAsGroup: 10001 fsGroup: 10001 seccompProfile: type: RuntimeDefault containers: - name: migrate image: forgejo.coulomb.social/coulomb/canned-prompts@sha256:e0ded3c7fe2548c910445deaa31ec42e84f129a92aa324841e231a53fee1f123 command: ["alembic"] args: ["upgrade", "head"] workingDir: /app env: # The migration role owns the schema; the runtime role does not. - name: CANNED_PROMPTS_DATABASE_URL_FILE value: /var/run/secrets/postgres-migration/url securityContext: allowPrivilegeEscalation: false capabilities: drop: ["ALL"] readOnlyRootFilesystem: true resources: requests: cpu: 25m memory: 64Mi limits: cpu: 500m memory: 256Mi volumeMounts: - name: postgres-migration mountPath: /var/run/secrets/postgres-migration readOnly: true volumes: - name: postgres-migration secret: defaultMode: 0440 secretName: canned-prompts-postgres-migration items: - key: url path: url