# infrastructure/postgres/statefulset.yaml apiVersion: apps/v1 kind: StatefulSet metadata: name: postgres namespace: postgres labels: app: postgres spec: serviceName: postgres-service replicas: 1 selector: matchLabels: app: postgres persistentVolumeClaimRetentionPolicy: whenDeleted: Retain whenScaled: Retain updateStrategy: type: RollingUpdate template: metadata: labels: app: postgres spec: serviceAccountName: postgres-vault nodeSelector: node-role.kubernetes.io/worker: "true" tolerations: - key: atlas.bstein.dev/spillover operator: Equal value: "true" effect: PreferNoSchedule - key: longhorn operator: Equal value: "true" effect: PreferNoSchedule affinity: nodeAffinity: requiredDuringSchedulingIgnoredDuringExecution: nodeSelectorTerms: - matchExpressions: - key: node-role.kubernetes.io/worker operator: In values: ["true"] - key: hardware operator: In values: ["rpi5", "rpi4"] preferredDuringSchedulingIgnoredDuringExecution: - weight: 100 preference: matchExpressions: - key: hardware operator: In values: ["rpi5"] - weight: 50 preference: matchExpressions: - key: hardware operator: In values: ["rpi4"] containers: - name: postgres image: postgres:15@sha256:6eb0add3b77c081df18aa518ce43df58fdcc40f2e6d868a6fd08038dc7acd425 ports: - name: postgres containerPort: 5432 protocol: TCP # The namespace's 512 MiB default previously killed backend processes. resources: requests: cpu: 250m memory: 1Gi limits: cpu: "2" memory: 2Gi startupProbe: exec: command: [pg_isready, -U, postgres, -d, postgres] periodSeconds: 10 timeoutSeconds: 5 failureThreshold: 60 readinessProbe: exec: command: [pg_isready, -U, postgres, -d, postgres] periodSeconds: 15 timeoutSeconds: 5 failureThreshold: 3 env: - name: PGDATA value: /var/lib/postgresql/data/pgdata - name: POSTGRES_USER value: postgres - name: POSTGRES_PASSWORD_FILE value: /mnt/vault/postgres_password - name: POSTGRES_DB value: postgres volumeMounts: - name: postgres-data mountPath: /var/lib/postgresql/data - name: vault-secrets mountPath: /mnt/vault readOnly: true - name: postgres-exporter image: quay.io/prometheuscommunity/postgres-exporter:v0.15.0@sha256:386b12d19eab2a37d7cd8ca8b4c7491cc7a830d9581f49af6c98a393da9605e6 resources: requests: cpu: 20m memory: 64Mi limits: cpu: 200m memory: 128Mi ports: - name: metrics containerPort: 9187 protocol: TCP env: - name: DATA_SOURCE_URI value: "localhost:5432/postgres?sslmode=disable" - name: DATA_SOURCE_USER value: postgres - name: DATA_SOURCE_PASS_FILE value: /mnt/vault/postgres_password volumeMounts: - name: vault-secrets mountPath: /mnt/vault readOnly: true volumes: - name: vault-secrets csi: driver: secrets-store.csi.k8s.io readOnly: true volumeAttributes: secretProviderClass: postgres-vault volumeClaimTemplates: - metadata: name: postgres-data spec: accessModes: ["ReadWriteOnce"] storageClassName: astreae resources: requests: storage: 100Gi