commit f40fee97127e61dec2962ce01dc88f2fe5edc407
parent 07d02cfafe9bf443e6d6c933df7bf0b11082e53d
Author: MTRNord <mtrnord1@gmail.com>
Date: Fri, 10 Jan 2025 13:15:39 +0100
prepare pg backups
Diffstat:
4 files changed, 935 insertions(+), 123 deletions(-)
diff --git a/apps/base/mailserver/release.yaml b/apps/base/mailserver/release.yaml
@@ -218,60 +218,17 @@ spec:
dovecot.cf:
create: true
path: dovecot.cf
- data: |
- {{- if .Values.proxyProtocol.enabled }}
- haproxy_trusted_networks = {{ .Values.proxyProtocol.trustedNetworks }}
-
- {{- if and (.Values.deployment.env.ENABLE_IMAP) (not .Values.deployment.env.SMTP_ONLY) }}
- service imap-login {
- inet_listener imap {
- port = 143
- }
-
- inet_listener imaps {
- port = 993
- ssl = yes
- }
-
- inet_listener imap_proxy {
- haproxy = yes
- port = 10143
- ssl = no
- }
-
- inet_listener imaps_proxy {
- haproxy = yes
- port = 10993
- ssl = yes
- }
- }
- {{- end -}}
-
- {{- if and (.Values.deployment.env.ENABLE_POP3) (not .Values.deployment.env.SMTP_ONLY) }}
- service pop3-login {
- inet_listener pop3 {
- port = 110
- }
-
- inet_listener pop3s {
- port = 995
- ssl = yes
- }
-
- inet_listener pop3_proxy {
- haproxy = yes
- port = 10110
- ssl = no
- }
-
- inet_listener pop3s_proxy {
- haproxy = yes
- port = 10995
- ssl = yes
- }
- }
- {{- end -}}
- {{- end -}}
+ data: "{{- if .Values.proxyProtocol.enabled }}\n haproxy_trusted_networks = {{ .Values.proxyProtocol.trustedNetworks
+ }}\n\n {{- if and (.Values.deployment.env.ENABLE_IMAP) (not .Values.deployment.env.SMTP_ONLY) }}\n service
+ imap-login {\n inet_listener imap {\n port = 143\n }\n\n inet_listener imaps {\n
+ \ port = 993\n ssl = yes\n }\n\n inet_listener imap_proxy {\n haproxy
+ = yes\n port = 10143\n ssl = no\n }\n\n inet_listener imaps_proxy {\n haproxy
+ = yes\n port = 10993\n ssl = yes\n }\n } \n {{- end -}}\n\n {{- if and (.Values.deployment.env.ENABLE_POP3)
+ (not .Values.deployment.env.SMTP_ONLY) }}\n service pop3-login {\n inet_listener pop3 {\n port
+ = 110\n }\n\n inet_listener pop3s {\n port = 995\n ssl = yes\n }\n\n
+ \ inet_listener pop3_proxy {\n haproxy = yes\n port = 10110\n ssl = no\n
+ \ }\n\n inet_listener pop3s_proxy {\n haproxy = yes\n port = 10995\n ssl
+ = yes\n } \n }\n {{- end -}}\n{{- end -}}\n"
fts-xapian-plugin.conf:
create: true
path: /etc/dovecot/conf.d/10-plugin.conf
@@ -310,49 +267,19 @@ spec:
user-patches.sh:
create: true
path: user-patches.sh
- data: |
- #!/bin/bash
-
- {{- if .Values.proxyProtocol.enabled }}
- # Make sure to keep this file in sync with https://github.com/docker-mailserver/docker-mailserver/blob/master/target/postfix/master.cf!
- cat <<EOS >> /etc/postfix/master.cf
-
- # Submission with proxy
- 10587 inet n - n - - smtpd
- -o syslog_name=postfix/submission
- -o smtpd_tls_security_level=encrypt
- -o smtpd_sasl_auth_enable=yes
- -o smtpd_sasl_type=dovecot
- -o smtpd_reject_unlisted_recipient=no
- -o smtpd_sasl_authenticated_header=yes
- -o smtpd_client_restrictions=permit_sasl_authenticated,reject
- -o smtpd_relay_restrictions=permit_sasl_authenticated,reject
- -o smtpd_sender_restrictions=\$mua_sender_restrictions
- -o smtpd_discard_ehlo_keywords=
- -o milter_macro_daemon_name=ORIGINATING
- -o cleanup_service_name=sender-cleanup
- -o smtpd_upstream_proxy_protocol=haproxy
-
- # Submissions with proxy
- 10465 inet n - n - - smtpd
- -o syslog_name=postfix/submissions
- -o smtpd_tls_wrappermode=yes
- -o smtpd_sasl_auth_enable=yes
- -o smtpd_sasl_type=dovecot
- -o smtpd_reject_unlisted_recipient=no
- -o smtpd_sasl_authenticated_header=yes
- -o smtpd_client_restrictions=permit_sasl_authenticated,reject
- -o smtpd_relay_restrictions=permit_sasl_authenticated,reject
- -o smtpd_sender_restrictions=\$mua_sender_restrictions
- -o smtpd_discard_ehlo_keywords=
- -o milter_macro_daemon_name=ORIGINATING
- -o cleanup_service_name=sender-cleanup
- -o smtpd_upstream_proxy_protocol=haproxy
-
- # Smtp with proxy
- 12525 inet n - n - 1 postscreen
- -o syslog_name=postfix/smtp-proxy
- -o postscreen_upstream_proxy_protocol=haproxy
- -o postscreen_cache_map=btree:$data_directory/postscreen_10025_cache
- EOS
- {{- end }}
+ data: "#!/bin/bash\n\n{{- if .Values.proxyProtocol.enabled }}\n# Make sure to keep this file in sync with
+ https://github.com/docker-mailserver/docker-mailserver/blob/master/target/postfix/master.cf!\ncat <<EOS
+ >> /etc/postfix/master.cf\n\n# Submission with proxy\n10587 inet n - n - -
+ \ smtpd\n -o syslog_name=postfix/submission\n -o smtpd_tls_security_level=encrypt\n -o smtpd_sasl_auth_enable=yes\n
+ \ -o smtpd_sasl_type=dovecot\n -o smtpd_reject_unlisted_recipient=no\n -o smtpd_sasl_authenticated_header=yes\n
+ \ -o smtpd_client_restrictions=permit_sasl_authenticated,reject\n -o smtpd_relay_restrictions=permit_sasl_authenticated,reject\n
+ \ -o smtpd_sender_restrictions=\\$mua_sender_restrictions\n -o smtpd_discard_ehlo_keywords=\n -o milter_macro_daemon_name=ORIGINATING\n
+ \ -o cleanup_service_name=sender-cleanup\n -o smtpd_upstream_proxy_protocol=haproxy \n\n# Submissions
+ with proxy\n10465 inet n - n - - smtpd\n -o syslog_name=postfix/submissions\n
+ \ -o smtpd_tls_wrappermode=yes\n -o smtpd_sasl_auth_enable=yes\n -o smtpd_sasl_type=dovecot\n -o smtpd_reject_unlisted_recipient=no\n
+ \ -o smtpd_sasl_authenticated_header=yes\n -o smtpd_client_restrictions=permit_sasl_authenticated,reject\n
+ \ -o smtpd_relay_restrictions=permit_sasl_authenticated,reject\n -o smtpd_sender_restrictions=\\$mua_sender_restrictions\n
+ \ -o smtpd_discard_ehlo_keywords=\n -o milter_macro_daemon_name=ORIGINATING\n -o cleanup_service_name=sender-cleanup\n
+ \ -o smtpd_upstream_proxy_protocol=haproxy\n\n# Smtp with proxy\n12525 inet n - n -
+ \ 1 postscreen\n -o syslog_name=postfix/smtp-proxy\n -o postscreen_upstream_proxy_protocol=haproxy\n
+ \ -o postscreen_cache_map=btree:$data_directory/postscreen_10025_cache\nEOS\n{{- end }}\n"
diff --git a/apps/base/matrix/synapse/release.yaml b/apps/base/matrix/synapse/release.yaml
@@ -88,11 +88,11 @@ spec:
modules:
- module: matrix_invitee_server_blocker.InviteeServerBlocker
config:
- broken_servers:
- #- matrix.org
- - matrix.im
- - funami.tech
- - suicideserver.net
+ broken_servers:
+ #- matrix.org
+ - matrix.im
+ - funami.tech
+ - suicideserver.net
persistence:
enabled: true
size: 20Gi
@@ -129,11 +129,11 @@ spec:
modules:
- module: matrix_invitee_server_blocker.InviteeServerBlocker
config:
- broken_servers:
- #- matrix.org
- - matrix.im
- - funami.tech
- - suicideserver.net
+ broken_servers:
+ #- matrix.org
+ - matrix.im
+ - funami.tech
+ - suicideserver.net
federation_reader:
replicaCount: 1
enabled: true
@@ -298,8 +298,8 @@ spec:
- matrix.midnightthoughts.space
tls:
- hosts:
- - midnightthoughts.space
- - matrix.midnightthoughts.space
+ - midnightthoughts.space
+ - matrix.midnightthoughts.space
secretName: midnightthoughts-synapse-tls-secret
annotations:
cert-manager.io/cluster-issuer: letsencrypt-dns
@@ -309,10 +309,10 @@ spec:
- path: /_matrix/client/.*/(login|logout|refresh)
pathType: ImplementationSpecific
backend:
- service:
- name: mas
- port:
- number: 8080
+ service:
+ name: mas
+ port:
+ number: 8080
sops:
kms: []
gcp_kms: []
@@ -321,13 +321,13 @@ sops:
age:
- recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBGRWlOWnhXaXlBRzZsQkNE
- Mnp0SldiWE5rN3YrVldLdlJYeEpkcExHdUdFCkEvbE56dmcvKzU2V0FmOU45Um14
- cXJXSWdyMFVNVEpDTU4wVTNSUnh4dEkKLS0tIDM5VTRHdlNFRGc0dTdZOHAvaHZh
- aXAvZzFmbmtKWnRla01YdU12YlhjdFEKhKpqgLU6uM8XqJ0rpe9g0cY5KtD0n0t+
- dTsMGEhbTY2fBJXw+JQkKJFl9EFloYtp0fx/1jcF6pa/BUYmNICtiQ==
- -----END AGE ENCRYPTED FILE-----
+ -----BEGIN AGE ENCRYPTED FILE-----
+ YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBGRWlOWnhXaXlBRzZsQkNE
+ Mnp0SldiWE5rN3YrVldLdlJYeEpkcExHdUdFCkEvbE56dmcvKzU2V0FmOU45Um14
+ cXJXSWdyMFVNVEpDTU4wVTNSUnh4dEkKLS0tIDM5VTRHdlNFRGc0dTdZOHAvaHZh
+ aXAvZzFmbmtKWnRla01YdU12YlhjdFEKhKpqgLU6uM8XqJ0rpe9g0cY5KtD0n0t+
+ dTsMGEhbTY2fBJXw+JQkKJFl9EFloYtp0fx/1jcF6pa/BUYmNICtiQ==
+ -----END AGE ENCRYPTED FILE-----
lastmodified: "2024-09-25T16:01:47Z"
mac: ENC[AES256_GCM,data:A70zcY2uBFZqrJgEY7hefYSdd2n8JTEoozqjlrSb/hGE1A2a89DpWF193GG+E2iDaD92HRG8ZEPU+5m+SMLfVVa+mW47KCb1Ush8rfkW94qmu/5jSuwJ/NHDW5xErx6Mobv3wrJEXl3m2LMsZu455t1hldzBtGDKCKZtSwJAP1c=,iv:GCIogDOgp/QI44f5SB9TM1X9yE4Z8V2CUTBt5173LDs=,tag:HxNrcAVgGMu9MoDKvhtnUQ==,type:str]
pgp: []
diff --git a/infrastructure/configs/cnpg-cluster-barmancloud-ext.yaml b/infrastructure/configs/cnpg-cluster-barmancloud-ext.yaml
@@ -0,0 +1,884 @@
+apiVersion: apiextensions.k8s.io/v1
+kind: CustomResourceDefinition
+metadata:
+ annotations:
+ controller-gen.kubebuilder.io/version: v0.16.2
+ name: objectstores.barmancloud.cnpg.io
+spec:
+ group: barmancloud.cnpg.io
+ names:
+ kind: ObjectStore
+ listKind: ObjectStoreList
+ plural: objectstores
+ singular: objectstore
+ scope: Namespaced
+ versions:
+ - name: v1
+ schema:
+ openAPIV3Schema:
+ description: ObjectStore is the Schema for the objectstores API.
+ properties:
+ apiVersion:
+ description: |-
+ APIVersion defines the versioned schema of this representation of an object.
+ Servers should convert recognized schemas to the latest internal value, and
+ may reject unrecognized values.
+ More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
+ type: string
+ kind:
+ description: |-
+ Kind is a string value representing the REST resource this object represents.
+ Servers may infer this from the endpoint the client submits requests to.
+ Cannot be updated.
+ In CamelCase.
+ More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
+ type: string
+ metadata:
+ type: object
+ spec:
+ description: ObjectStoreSpec defines the desired state of ObjectStore.
+ properties:
+ configuration:
+ description: |-
+ BarmanObjectStoreConfiguration contains the backup configuration
+ using Barman against an S3-compatible object storage
+ properties:
+ azureCredentials:
+ description: The credentials to use to upload data to Azure Blob Storage
+ properties:
+ connectionString:
+ description: The connection string to be used
+ properties:
+ key:
+ description: The key to select
+ type: string
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - key
+ - name
+ type: object
+ inheritFromAzureAD:
+ description: Use the Azure AD based authentication without providing explicitly
+ the keys.
+ type: boolean
+ storageAccount:
+ description: The storage account where to upload data
+ properties:
+ key:
+ description: The key to select
+ type: string
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - key
+ - name
+ type: object
+ storageKey:
+ description: |-
+ The storage account key to be used in conjunction
+ with the storage account name
+ properties:
+ key:
+ description: The key to select
+ type: string
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - key
+ - name
+ type: object
+ storageSasToken:
+ description: |-
+ A shared-access-signature to be used in conjunction with
+ the storage account name
+ properties:
+ key:
+ description: The key to select
+ type: string
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - key
+ - name
+ type: object
+ type: object
+ data:
+ description: |-
+ The configuration to be used to backup the data files
+ When not defined, base backups files will be stored uncompressed and may
+ be unencrypted in the object store, according to the bucket default
+ policy.
+ properties:
+ additionalCommandArgs:
+ description: |-
+ AdditionalCommandArgs represents additional arguments that can be appended
+ to the 'barman-cloud-backup' command-line invocation. These arguments
+ provide flexibility to customize the backup process further according to
+ specific requirements or configurations.
+
+ Example:
+ In a scenario where specialized backup options are required, such as setting
+ a specific timeout or defining custom behavior, users can use this field
+ to specify additional command arguments.
+
+ Note:
+ It's essential to ensure that the provided arguments are valid and supported
+ by the 'barman-cloud-backup' command, to avoid potential errors or unintended
+ behavior during execution.
+ items:
+ type: string
+ type: array
+ compression:
+ description: |-
+ Compress a backup file (a tar file per tablespace) while streaming it
+ to the object store. Available options are empty string (no
+ compression, default), `gzip`, `bzip2` or `snappy`.
+ enum:
+ - gzip
+ - bzip2
+ - snappy
+ type: string
+ encryption:
+ description: |-
+ Whenever to force the encryption of files (if the bucket is
+ not already configured for that).
+ Allowed options are empty string (use the bucket policy, default),
+ `AES256` and `aws:kms`
+ enum:
+ - AES256
+ - aws:kms
+ type: string
+ immediateCheckpoint:
+ description: |-
+ Control whether the I/O workload for the backup initial checkpoint will
+ be limited, according to the `checkpoint_completion_target` setting on
+ the PostgreSQL server. If set to true, an immediate checkpoint will be
+ used, meaning PostgreSQL will complete the checkpoint as soon as
+ possible. `false` by default.
+ type: boolean
+ jobs:
+ description: |-
+ The number of parallel jobs to be used to upload the backup, defaults
+ to 2
+ format: int32
+ minimum: 1
+ type: integer
+ type: object
+ destinationPath:
+ description: |-
+ The path where to store the backup (i.e. s3://bucket/path/to/folder)
+ this path, with different destination folders, will be used for WALs
+ and for data
+ minLength: 1
+ type: string
+ endpointCA:
+ description: |-
+ EndpointCA store the CA bundle of the barman endpoint.
+ Useful when using self-signed certificates to avoid
+ errors with certificate issuer and barman-cloud-wal-archive
+ properties:
+ key:
+ description: The key to select
+ type: string
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - key
+ - name
+ type: object
+ endpointURL:
+ description: |-
+ Endpoint to be used to upload data to the cloud,
+ overriding the automatic endpoint discovery
+ type: string
+ googleCredentials:
+ description: The credentials to use to upload data to Google Cloud Storage
+ properties:
+ applicationCredentials:
+ description: The secret containing the Google Cloud Storage JSON file with
+ the credentials
+ properties:
+ key:
+ description: The key to select
+ type: string
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - key
+ - name
+ type: object
+ gkeEnvironment:
+ description: |-
+ If set to true, will presume that it's running inside a GKE environment,
+ default to false.
+ type: boolean
+ type: object
+ historyTags:
+ additionalProperties:
+ type: string
+ description: |-
+ HistoryTags is a list of key value pairs that will be passed to the
+ Barman --history-tags option.
+ type: object
+ s3Credentials:
+ description: The credentials to use to upload data to S3
+ properties:
+ accessKeyId:
+ description: The reference to the access key id
+ properties:
+ key:
+ description: The key to select
+ type: string
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - key
+ - name
+ type: object
+ inheritFromIAMRole:
+ description: Use the role based authentication without providing explicitly
+ the keys.
+ type: boolean
+ region:
+ description: The reference to the secret containing the region name
+ properties:
+ key:
+ description: The key to select
+ type: string
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - key
+ - name
+ type: object
+ secretAccessKey:
+ description: The reference to the secret access key
+ properties:
+ key:
+ description: The key to select
+ type: string
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - key
+ - name
+ type: object
+ sessionToken:
+ description: The references to the session key
+ properties:
+ key:
+ description: The key to select
+ type: string
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - key
+ - name
+ type: object
+ type: object
+ serverName:
+ description: |-
+ The server name on S3, the cluster name is used if this
+ parameter is omitted
+ type: string
+ tags:
+ additionalProperties:
+ type: string
+ description: |-
+ Tags is a list of key value pairs that will be passed to the
+ Barman --tags option.
+ type: object
+ wal:
+ description: |-
+ The configuration for the backup of the WAL stream.
+ When not defined, WAL files will be stored uncompressed and may be
+ unencrypted in the object store, according to the bucket default policy.
+ properties:
+ archiveAdditionalCommandArgs:
+ description: |-
+ Additional arguments that can be appended to the 'barman-cloud-wal-archive'
+ command-line invocation. These arguments provide flexibility to customize
+ the WAL archive process further, according to specific requirements or configurations.
+
+ Example:
+ In a scenario where specialized backup options are required, such as setting
+ a specific timeout or defining custom behavior, users can use this field
+ to specify additional command arguments.
+
+ Note:
+ It's essential to ensure that the provided arguments are valid and supported
+ by the 'barman-cloud-wal-archive' command, to avoid potential errors or unintended
+ behavior during execution.
+ items:
+ type: string
+ type: array
+ compression:
+ description: |-
+ Compress a WAL file before sending it to the object store. Available
+ options are empty string (no compression, default), `gzip`, `bzip2` or `snappy`.
+ enum:
+ - gzip
+ - bzip2
+ - snappy
+ type: string
+ encryption:
+ description: |-
+ Whenever to force the encryption of files (if the bucket is
+ not already configured for that).
+ Allowed options are empty string (use the bucket policy, default),
+ `AES256` and `aws:kms`
+ enum:
+ - AES256
+ - aws:kms
+ type: string
+ maxParallel:
+ description: |-
+ Number of WAL files to be either archived in parallel (when the
+ PostgreSQL instance is archiving to a backup object store) or
+ restored in parallel (when a PostgreSQL standby is fetching WAL
+ files from a recovery object store). If not specified, WAL files
+ will be processed one at a time. It accepts a positive integer as a
+ value - with 1 being the minimum accepted value.
+ minimum: 1
+ type: integer
+ restoreAdditionalCommandArgs:
+ description: |-
+ Additional arguments that can be appended to the 'barman-cloud-wal-restore'
+ command-line invocation. These arguments provide flexibility to customize
+ the WAL restore process further, according to specific requirements or configurations.
+
+ Example:
+ In a scenario where specialized backup options are required, such as setting
+ a specific timeout or defining custom behavior, users can use this field
+ to specify additional command arguments.
+
+ Note:
+ It's essential to ensure that the provided arguments are valid and supported
+ by the 'barman-cloud-wal-restore' command, to avoid potential errors or unintended
+ behavior during execution.
+ items:
+ type: string
+ type: array
+ type: object
+ required:
+ - destinationPath
+ type: object
+ instanceSidecarConfiguration:
+ description: InstanceSidecarConfiguration defines the configuration for the sidecar that runs
+ in the instance pods.
+ properties:
+ env:
+ description: The environment to be explicitly passed to the sidecar
+ items:
+ description: EnvVar represents an environment variable present in a Container.
+ properties:
+ name:
+ description: Name of the environment variable. Must be a C_IDENTIFIER.
+ type: string
+ value:
+ description: |-
+ Variable references $(VAR_NAME) are expanded
+ using the previously defined environment variables in the container and
+ any service environment variables. If a variable cannot be resolved,
+ the reference in the input string will be unchanged. Double $$ are reduced
+ to a single $, which allows for escaping the $(VAR_NAME) syntax: i.e.
+ "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)".
+ Escaped references will never be expanded, regardless of whether the variable
+ exists or not.
+ Defaults to "".
+ type: string
+ valueFrom:
+ description: Source for the environment variable's value. Cannot be used
+ if value is not empty.
+ properties:
+ configMapKeyRef:
+ description: Selects a key of a ConfigMap.
+ properties:
+ key:
+ description: The key to select.
+ type: string
+ name:
+ default: ""
+ description: |-
+ Name of the referent.
+ This field is effectively required, but due to backwards compatibility is
+ allowed to be empty. Instances of this type with an empty value here are
+ almost certainly wrong.
+ More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
+ type: string
+ optional:
+ description: Specify whether the ConfigMap or its key
+ must be defined
+ type: boolean
+ required:
+ - key
+ type: object
+ x-kubernetes-map-type: atomic
+ fieldRef:
+ description: |-
+ Selects a field of the pod: supports metadata.name, metadata.namespace, `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`,
+ spec.nodeName, spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
+ properties:
+ apiVersion:
+ description: Version of the schema the FieldPath is written
+ in terms of, defaults to "v1".
+ type: string
+ fieldPath:
+ description: Path of the field to select in the specified
+ API version.
+ type: string
+ required:
+ - fieldPath
+ type: object
+ x-kubernetes-map-type: atomic
+ resourceFieldRef:
+ description: |-
+ Selects a resource of the container: only resources limits and requests
+ (limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and requests.ephemeral-storage) are currently supported.
+ properties:
+ containerName:
+ description: "Container name: required for volumes, optional
+ for env vars"
+ type: string
+ divisor:
+ anyOf:
+ - type: integer
+ - type: string
+ description: Specifies the output format of the exposed
+ resources, defaults to "1"
+ pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
+ x-kubernetes-int-or-string: true
+ resource:
+ description: "Required: resource to select"
+ type: string
+ required:
+ - resource
+ type: object
+ x-kubernetes-map-type: atomic
+ secretKeyRef:
+ description: Selects a key of a secret in the pod's namespace
+ properties:
+ key:
+ description: The key of the secret to select from. Must
+ be a valid secret key.
+ type: string
+ name:
+ default: ""
+ description: |-
+ Name of the referent.
+ This field is effectively required, but due to backwards compatibility is
+ allowed to be empty. Instances of this type with an empty value here are
+ almost certainly wrong.
+ More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
+ type: string
+ optional:
+ description: Specify whether the Secret or its key must
+ be defined
+ type: boolean
+ required:
+ - key
+ type: object
+ x-kubernetes-map-type: atomic
+ type: object
+ required:
+ - name
+ type: object
+ type: array
+ type: object
+ required:
+ - configuration
+ type: object
+ status:
+ description: ObjectStoreStatus defines the observed state of ObjectStore.
+ type: object
+ required:
+ - metadata
+ - spec
+ type: object
+ served: true
+ storage: true
+ subresources:
+ status: {}
+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+ labels:
+ app.kubernetes.io/managed-by: kustomize
+ app.kubernetes.io/name: plugin-barman-cloud
+ name: plugin-barman-cloud
+ namespace: postgres-cluster
+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: Role
+metadata:
+ labels:
+ app.kubernetes.io/managed-by: kustomize
+ app.kubernetes.io/name: plugin-barman-cloud
+ name: leader-election-role
+ namespace: postgres-cluster
+rules:
+ - apiGroups:
+ - ""
+ resources:
+ - configmaps
+ verbs:
+ - get
+ - list
+ - watch
+ - create
+ - update
+ - patch
+ - delete
+ - apiGroups:
+ - coordination.k8s.io
+ resources:
+ - leases
+ verbs:
+ - get
+ - list
+ - watch
+ - create
+ - update
+ - patch
+ - delete
+ - apiGroups:
+ - ""
+ resources:
+ - events
+ verbs:
+ - create
+ - patch
+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: ClusterRole
+metadata:
+ name: metrics-auth-role
+rules:
+ - apiGroups:
+ - authentication.k8s.io
+ resources:
+ - tokenreviews
+ verbs:
+ - create
+ - apiGroups:
+ - authorization.k8s.io
+ resources:
+ - subjectaccessreviews
+ verbs:
+ - create
+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: ClusterRole
+metadata:
+ name: metrics-reader
+rules:
+ - nonResourceURLs:
+ - /metrics
+ verbs:
+ - get
+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: ClusterRole
+metadata:
+ labels:
+ app.kubernetes.io/managed-by: kustomize
+ app.kubernetes.io/name: plugin-barman-cloud
+ name: objectstore-editor-role
+rules:
+ - apiGroups:
+ - barmancloud.cnpg.io
+ resources:
+ - objectstores
+ verbs:
+ - create
+ - delete
+ - get
+ - list
+ - patch
+ - update
+ - watch
+ - apiGroups:
+ - barmancloud.cnpg.io
+ resources:
+ - objectstores/status
+ verbs:
+ - get
+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: ClusterRole
+metadata:
+ labels:
+ app.kubernetes.io/managed-by: kustomize
+ app.kubernetes.io/name: plugin-barman-cloud
+ name: objectstore-viewer-role
+rules:
+ - apiGroups:
+ - barmancloud.cnpg.io
+ resources:
+ - objectstores
+ verbs:
+ - get
+ - list
+ - watch
+ - apiGroups:
+ - barmancloud.cnpg.io
+ resources:
+ - objectstores/status
+ verbs:
+ - get
+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: ClusterRole
+metadata:
+ name: plugin-barman-cloud
+rules:
+ - apiGroups:
+ - ""
+ resources:
+ - secrets
+ verbs:
+ - create
+ - delete
+ - get
+ - list
+ - watch
+ - apiGroups:
+ - barmancloud.cnpg.io
+ resources:
+ - objectstores
+ verbs:
+ - create
+ - delete
+ - get
+ - list
+ - patch
+ - update
+ - watch
+ - apiGroups:
+ - barmancloud.cnpg.io
+ resources:
+ - objectstores/finalizers
+ verbs:
+ - update
+ - apiGroups:
+ - barmancloud.cnpg.io
+ resources:
+ - objectstores/status
+ verbs:
+ - get
+ - patch
+ - update
+ - apiGroups:
+ - postgresql.cnpg.io
+ resources:
+ - backups
+ verbs:
+ - get
+ - list
+ - watch
+ - apiGroups:
+ - rbac.authorization.k8s.io
+ resources:
+ - rolebindings
+ - roles
+ verbs:
+ - create
+ - get
+ - list
+ - patch
+ - update
+ - watch
+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: RoleBinding
+metadata:
+ labels:
+ app.kubernetes.io/managed-by: kustomize
+ app.kubernetes.io/name: plugin-barman-cloud
+ name: leader-election-rolebinding
+ namespace: postgres-cluster
+roleRef:
+ apiGroup: rbac.authorization.k8s.io
+ kind: Role
+ name: leader-election-role
+subjects:
+ - kind: ServiceAccount
+ name: plugin-barman-cloud
+ namespace: postgres-cluster
+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: ClusterRoleBinding
+metadata:
+ name: metrics-auth-rolebinding
+roleRef:
+ apiGroup: rbac.authorization.k8s.io
+ kind: ClusterRole
+ name: metrics-auth-role
+subjects:
+ - kind: ServiceAccount
+ name: plugin-barman-cloud
+ namespace: postgres-cluster
+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: ClusterRoleBinding
+metadata:
+ labels:
+ app.kubernetes.io/managed-by: kustomize
+ app.kubernetes.io/name: plugin-barman-cloud
+ name: plugin-barman-cloud-binding
+roleRef:
+ apiGroup: rbac.authorization.k8s.io
+ kind: ClusterRole
+ name: plugin-barman-cloud
+subjects:
+ - kind: ServiceAccount
+ name: plugin-barman-cloud
+ namespace: postgres-cluster
+---
+apiVersion: v1
+data:
+ SIDECAR_IMAGE: |
+ Z2hjci5pby9jbG91ZG5hdGl2ZS1wZy9wbHVnaW4tYmFybWFuLWNsb3VkLXNpZGVjYXI6dj
+ AuMS4w
+kind: Secret
+metadata:
+ name: plugin-barman-cloud-498t9gthct
+ namespace: postgres-cluster
+type: Opaque
+---
+apiVersion: v1
+kind: Service
+metadata:
+ annotations:
+ cnpg.io/pluginClientSecret: barman-cloud-client-tls
+ cnpg.io/pluginPort: "9090"
+ cnpg.io/pluginServerSecret: barman-cloud-server-tls
+ labels:
+ app: barman-cloud
+ cnpg.io/pluginName: barman-cloud.cloudnative-pg.io
+ name: barman-cloud
+ namespace: postgres-cluster
+spec:
+ ports:
+ - port: 9090
+ protocol: TCP
+ targetPort: 9090
+ selector:
+ app: barman-cloud
+---
+apiVersion: apps/v1
+kind: Deployment
+metadata:
+ labels:
+ app: barman-cloud
+ name: barman-cloud
+ namespace: postgres-cluster
+spec:
+ replicas: 1
+ selector:
+ matchLabels:
+ app: barman-cloud
+ strategy:
+ type: Recreate
+ template:
+ metadata:
+ labels:
+ app: barman-cloud
+ spec:
+ containers:
+ - args:
+ - operator
+ - --server-cert=/server/tls.crt
+ - --server-key=/server/tls.key
+ - --client-cert=/client/tls.crt
+ - --server-address=:9090
+ - --leader-elect
+ - --log-level=debug
+ env:
+ - name: SIDECAR_IMAGE
+ valueFrom:
+ secretKeyRef:
+ key: SIDECAR_IMAGE
+ name: plugin-barman-cloud-498t9gthct
+ image: ghcr.io/cloudnative-pg/plugin-barman-cloud:v0.1.0
+ name: barman-cloud
+ ports:
+ - containerPort: 9090
+ protocol: TCP
+ readinessProbe:
+ initialDelaySeconds: 10
+ periodSeconds: 10
+ tcpSocket:
+ port: 9090
+ resources: {}
+ volumeMounts:
+ - mountPath: /server
+ name: server
+ - mountPath: /client
+ name: client
+ serviceAccountName: plugin-barman-cloud
+ volumes:
+ - name: server
+ secret:
+ secretName: barman-cloud-server-tls
+ - name: client
+ secret:
+ secretName: barman-cloud-client-tls
+---
+apiVersion: cert-manager.io/v1
+kind: Certificate
+metadata:
+ name: barman-cloud-client
+ namespace: postgres-cluster
+spec:
+ commonName: barman-cloud-client
+ duration: 2160h
+ isCA: false
+ issuerRef:
+ group: cert-manager.io
+ kind: Issuer
+ name: selfsigned-issuer
+ renewBefore: 360h
+ secretName: barman-cloud-client-tls
+ usages:
+ - client auth
+---
+apiVersion: cert-manager.io/v1
+kind: Certificate
+metadata:
+ name: barman-cloud-server
+ namespace: postgres-cluster
+spec:
+ commonName: barman-cloud
+ dnsNames:
+ - barman-cloud
+ duration: 2160h
+ isCA: false
+ issuerRef:
+ group: cert-manager.io
+ kind: Issuer
+ name: selfsigned-issuer
+ renewBefore: 360h
+ secretName: barman-cloud-server-tls
+ usages:
+ - server auth
+---
+apiVersion: cert-manager.io/v1
+kind: Issuer
+metadata:
+ name: selfsigned-issuer
+ namespace: postgres-cluster
+spec:
+ selfSigned: {}
diff --git a/infrastructure/configs/kustomization.yaml b/infrastructure/configs/kustomization.yaml
@@ -6,3 +6,4 @@ resources:
- priority-classes.yaml
#- postgres-clusters.yaml
- cnpg-cluster.yaml
+ - cnpg-cluster-barmancloud-ext.yaml