# k8s/temporal/temporal-values.yaml # Temporal — workflow engine # Uses external CNPG PostgreSQL for persistence (ddb-cluster) # Visibility via same PostgreSQL instance, separate database. # # IMPORTANT — chart schema note (root-caused after Postgres never actually # taking effect despite looking configured): # We're pinned to temporalio/helm-charts @ 0.74.0 (see targetRevision in # k8s/argocd/apps/60-applications.yaml), which uses the OLD flat persistence # schema: # server.config.persistence..driver: "sql"|"cassandra" # server.config.persistence..sql: {...} # NOT the newer `datastores:`-wrapped schema # (server.config.persistence.datastores..sql) shown in the current # chart's values/values.postgresql.yaml example - that key was introduced in # a later major version and doesn't exist in 0.74.0. Helm doesn't validate # unknown keys, so a `datastores:` block here is silently a no-op: Temporal # would keep defaulting to Cassandra (with empty hosts: []) regardless of # anything nested inside it. Verified via `helm template` against the actual # 0.74.0 chart before writing this file - see chat history for the # side-by-side proof (rendered manifest showed CASSANDRA_HOST env vars and # temporal-cassandra-tool commands using the old datastores:-based values). # # Likewise `schema.setup.enabled` / `schema.update.enabled` / # `schema.createDatabase.enabled` are the real toggles for the schema-setup # Job (all default true) - there is no `jobs.autoSetup` key in this chart. # ── Disable every bundled/optional sub-chart ───────────────────────────────── # postgresql/mysql: never enable - we never want the chart to deploy its own # DB, only to know how to talk to our external CNPG instance (which happens # via server.config.persistence.*.sql below, independent of these flags). postgresql: enabled: false mysql: enabled: false cassandra: enabled: false elasticsearch: enabled: false prometheus: enabled: false grafana: enabled: false # ── Schema setup/update Jobs ────────────────────────────────────────────────── # The `temporal` and `temporal_visibility` databases are provisioned # declaratively by CNPG Database CRs (k8s/data/temporal-database.yaml, # temporal-visibility-database.yaml), so createDatabase stays disabled (the # `temporal` role also lacks CREATEDB). setup/update run temporal-sql-tool as # the `temporal` owner against those existing DBs to install and migrate the # Temporal server schema — without them both DBs have zero tables and the # server dies on "no usable database connection found" (no schema_version row). schema: createDatabase: enabled: false setup: enabled: true update: enabled: true # ── Temporal server config (PostgreSQL persistence) ────────────────────────── server: replicaCount: 1 # temporalio/server:1.30.0+ dropped the `dockerize` binary and switched to # built-in sprig config templating. The chart still defaults to the legacy # configMapsToMount: "dockerize" + setConfigFilePath: false, which produces a # config the 1.30 server never loads — it then falls back to its embedded # env-only template (Cassandra default) and dies with # "Persistence.DataStores[default](value).Cassandra.Hosts: zero value". # Switch to the sprig ConfigMap and point the server at it (chart's own # recommendation for 1.30.0+ images; sprig mode requires setConfigFilePath). configMapsToMount: "sprig" setConfigFilePath: true jobService: enabled: false affinity: podAntiAffinity: preferredDuringSchedulingIgnoredDuringExecution: - weight: 100 podAffinityTerm: labelSelector: matchLabels: app.kubernetes.io/instance: temporal topologyKey: kubernetes.io/hostname config: logLevel: "info" persistence: defaultStore: default visibilityStore: visibility numHistoryShards: 512 default: driver: "sql" sql: driver: "postgres12" host: "ddb-cluster-rw.ddb.svc.cluster.local" port: 5432 database: "temporal" user: "temporal" # existingSecret + secretKey: point directly at the CNPG-generated # Secret (kubernetes.io/basic-auth, keys: username/password/...) # rather than duplicating the password in git as plaintext. When # existingSecret is set the chart's own server-secret.yaml Secret # template is skipped entirely (see templates/server-secret.yaml: # `not $driverConfig.existingSecret` guards its creation). existingSecret: "temporal-db-role" secretKey: "password" maxConns: 20 maxIdleConns: 10 maxConnLifetime: "1h" # NOTE: no `connectAttributes: { tx_isolation: ... }` here — tx_isolation # is a MySQL-only connection parameter. The Postgres `pq` driver rejects # it ("unrecognized configuration parameter"), which killed every DB # connection (schema-setup job AND server) with the misleading # "no usable database connection found". Postgres defaults to READ # COMMITTED isolation anyway, so nothing is lost by omitting it. visibility: driver: "sql" sql: driver: "postgres12" host: "ddb-cluster-rw.ddb.svc.cluster.local" port: 5432 database: "temporal_visibility" user: "temporal" existingSecret: "temporal-db-role" secretKey: "password" maxConns: 20 maxIdleConns: 10 maxConnLifetime: "1h" service: type: ClusterIP # ── Temporal Web UI ──────────────────────────────────────────────────────── web: replicaCount: 1 service: type: ClusterIP # ── Ingress ──────────────────────────────────────────────────────── ingress: enabled: false