39 lines
1.1 KiB
YAML
39 lines
1.1 KiB
YAML
# Dedicated CNPG Postgres for Authentik (GitOps, wave 2 — before authentik w3).
|
|||
|
|
# CNPG generates secret `authentik-db-app` + service `authentik-db-rw` in ns iam;
|
||
|
|
# authentik-values reads them locally (no cross-ns secret copy).
|
||
|
|
apiVersion: postgresql.cnpg.io/v1
|
||
|
|
kind: Cluster
|
||
|
|
metadata:
|
||
|
|
name: authentik-db
|
||
|
|
namespace: iam
|
||
|
|
annotations:
|
||
|
|
argocd.argoproj.io/sync-options: SkipDryRunOnMissingResource=true
|
||
|
|
spec:
|
||
|
|
instances: 3
|
||
|
|
imageName: ghcr.io/cloudnative-pg/postgresql:16.2
|
||
|
|
bootstrap:
|
||
|
|
initdb:
|
||
|
|
database: authentik
|
||
|
|
owner: app
|
||
|
|
encoding: UTF8
|
||
|
|
localeCollate: C
|
||
|
|
localeCType: C
|
||
|
|
enableSuperuserAccess: false
|
||
|
|
resources:
|
||
|
|
requests: { memory: "512Mi", cpu: "250m" }
|
||
|
|
limits: { memory: "2Gi", cpu: "1" }
|
||
|
|
storage:
|
||
|
|
size: 10Gi
|
||
|
|
storageClass: longhorn-cnpg
|
||
|
|
monitoring:
|
||
|
|
enablePodMonitor: true
|
||
|
|
affinity:
|
||
|
|
# preferred + tolerations: HA across nodes without deadlocking a partly-
|
||
|
|
# schedulable 3-CP (same as forgejo-db).
|
||
|
|
podAntiAffinityType: preferred
|
||
|
|
topologyKey: kubernetes.io/hostname
|
||
|
|
tolerations:
|
||
|
|
- key: node-role.kubernetes.io/control-plane
|
||
|
|
operator: Exists
|
||
|
|
effect: NoSchedule
|