fix(temporal): provision schema via CNPG temporal_visibility DB + drop mysql-only tx_isolation param

This commit is contained in:
Story Crater Bot
2026-08-18 15:08:03 -07:00
parent e2781c72e2
commit 51c07a845f
3 changed files with 26 additions and 10 deletions
+15 -10
View File
@@ -43,19 +43,20 @@ grafana:
enabled: false
# ── Schema setup/update Jobs ──────────────────────────────────────────────────
# Disabled: ddb-cluster's seed job (k8s/data/db-init-job.yaml) already creates
# the `temporal` and `temporal_visibility` databases and runs the Temporal
# schema migrations out of band. Leaving these at their chart default (true)
# would spin up a schema Job on every sync that tries to wait-for-cassandra
# and run cassandra-tool commands (see note above) - pointless for us even
# once correctly pointed at Postgres, since schema is already seeded.
# The `temporal` and `temporal_visibility` databases are provisioned
# declaratively by CNPG Database CRs (k8s/data/temporal-database.yaml,
# temporal-visibility-database.yaml), so createDatabase stays disabled (the
# `temporal` role also lacks CREATEDB). setup/update run temporal-sql-tool as
# the `temporal` owner against those existing DBs to install and migrate the
# Temporal server schema — without them both DBs have zero tables and the
# server dies on "no usable database connection found" (no schema_version row).
schema:
createDatabase:
enabled: false
setup:
enabled: false
enabled: true
update:
enabled: false
enabled: true
# ── Temporal server config (PostgreSQL persistence) ──────────────────────────
server:
@@ -106,8 +107,12 @@ server:
maxConns: 20
maxIdleConns: 10
maxConnLifetime: "1h"
connectAttributes:
tx_isolation: "READ-COMMITTED"
# NOTE: no `connectAttributes: { tx_isolation: ... }` here — tx_isolation
# is a MySQL-only connection parameter. The Postgres `pq` driver rejects
# it ("unrecognized configuration parameter"), which killed every DB
# connection (schema-setup job AND server) with the misleading
# "no usable database connection found". Postgres defaults to READ
# COMMITTED isolation anyway, so nothing is lost by omitting it.
visibility:
driver: "sql"
sql:
+1
View File
@@ -16,5 +16,6 @@ resources:
- forgejo-database.yaml
- authentik-database.yaml
- temporal-database.yaml
- temporal-visibility-database.yaml
# db-role-secrets.enc.yaml is applied out-of-band (SOPS-encrypted, bootstrap) —
# NOT listed here, or the data-schemas ArgoCD app would fail on the ciphertext.
@@ -0,0 +1,10 @@
apiVersion: postgresql.cnpg.io/v1
kind: Database
metadata:
name: temporal-visibility
namespace: ddb
spec:
name: temporal_visibility
owner: temporal
cluster:
name: ddb-cluster