# Schema migration as a Job, not an init container and not a start-up hook. # Running migrations at start-up races between replicas and couples a rollback # of the code to a rollback of the schema. The Job name carries the target # revision so a re-apply at the same revision is a no-op rather than a rerun. apiVersion: batch/v1 kind: Job metadata: name: canned-prompts-schema-migration-0002 namespace: canned-prompts labels: app.kubernetes.io/name: canned-prompts-migration app.kubernetes.io/component: migration spec: backoffLimit: 2 ttlSecondsAfterFinished: 86400 template: metadata: labels: app.kubernetes.io/name: canned-prompts-migration # Carries part-of so the egress NetworkPolicy selects this Job too. # Without it the Job matches only the default-deny and cannot reach # PostgreSQL or DNS. app.kubernetes.io/part-of: canned-prompts spec: automountServiceAccountToken: false restartPolicy: Never securityContext: runAsNonRoot: true runAsUser: 10001 runAsGroup: 10001 fsGroup: 10001 seccompProfile: type: RuntimeDefault containers: - name: migrate image: forgejo.coulomb.social/coulomb/canned-prompts@sha256:14c7b92f20d63f2e70ea17b0b45d3c483521fbbaf14ee5bc277fa541e10452e2 command: ["alembic"] args: ["upgrade", "head"] workingDir: /app env: # The migration role owns the schema; the runtime role does not. - name: CANNED_PROMPTS_DATABASE_URL_FILE value: /var/run/secrets/postgres-migration/url # Authenticate as the leased migration login, then SET ROLE to the # durable owner before creating anything. Leases are revoked; an # object owned by a dead login has to be normalized afterwards. # Required by the rapp-postgres database-owner boundary. - name: CANNED_PROMPTS_MIGRATION_ROLE value: canned_prompts_owner securityContext: allowPrivilegeEscalation: false capabilities: drop: ["ALL"] readOnlyRootFilesystem: true resources: requests: cpu: 25m memory: 64Mi limits: cpu: 500m memory: 256Mi volumeMounts: - name: postgres-migration mountPath: /var/run/secrets/postgres-migration readOnly: true volumes: - name: postgres-migration secret: defaultMode: 0440 secretName: canned-prompts-postgres-migration items: - key: url path: url