values.yaml 79 KB


  1. # Copyright VMware, Inc.
  2. # SPDX-License-Identifier: APACHE-2.0
  3. ## @section Global parameters
  4. ## Please, note that this will override the parameters, including dependencies, configured to use the global value
  5. ##
  6. global:
  7. ## @param global.imageRegistry Global Docker image registry
  8. ##
  9. imageRegistry: ""
  10. ## @param global.imagePullSecrets Global Docker registry secret names as an array
  11. ## e.g.
  12. ## imagePullSecrets:
  13. ## - myRegistryKeySecretName
  14. ##
  15. imagePullSecrets: []
  16. ## @param global.storageClass Global StorageClass for Persistent Volume(s)
  17. ##
  18. storageClass: ""
  19. postgresql:
  20. ## @param global.postgresql.auth.postgresPassword Password for the "postgres" admin user (overrides `auth.postgresPassword`)
  21. ## @param global.postgresql.auth.username Name for a custom user to create (overrides `auth.username`)
  22. ## @param global.postgresql.auth.password Password for the custom user to create (overrides `auth.password`)
  23. ## @param global.postgresql.auth.database Name for a custom database to create (overrides `auth.database`)
  24. ## @param global.postgresql.auth.existingSecret Name of existing secret to use for PostgreSQL credentials (overrides `auth.existingSecret`).
  25. ## @param global.postgresql.auth.secretKeys.adminPasswordKey Name of key in existing secret to use for PostgreSQL credentials (overrides `auth.secretKeys.adminPasswordKey`). Only used when `global.postgresql.auth.existingSecret` is set.
  26. ## @param global.postgresql.auth.secretKeys.userPasswordKey Name of key in existing secret to use for PostgreSQL credentials (overrides `auth.secretKeys.userPasswordKey`). Only used when `global.postgresql.auth.existingSecret` is set.
  27. ## @param global.postgresql.auth.secretKeys.replicationPasswordKey Name of key in existing secret to use for PostgreSQL credentials (overrides `auth.secretKeys.replicationPasswordKey`). Only used when `global.postgresql.auth.existingSecret` is set.
  28. ##
  29. auth:
  30. postgresPassword: ""
  31. username: ""
  32. password: ""
  33. database: ""
  34. existingSecret: ""
  35. secretKeys:
  36. adminPasswordKey: ""
  37. userPasswordKey: ""
  38. replicationPasswordKey: ""
  39. ## @param global.postgresql.service.ports.postgresql PostgreSQL service port (overrides `service.ports.postgresql`)
  40. ##
  41. service:
  42. ports:
  43. postgresql: ""
  44. ## @section Common parameters
  45. ##
  46. ## @param kubeVersion Override Kubernetes version
  47. ##
  48. kubeVersion: ""
  49. ## @param nameOverride String to partially override common.names.fullname template (will maintain the release name)
  50. ##
  51. nameOverride: ""
  52. ## @param fullnameOverride String to fully override common.names.fullname template
  53. ##
  54. fullnameOverride: ""
  55. ## @param clusterDomain Kubernetes Cluster Domain
  56. ##
  57. clusterDomain: cluster.local
  58. ## @param extraDeploy Array of extra objects to deploy with the release (evaluated as a template)
  59. ##
  60. extraDeploy: []
  61. ## @param commonLabels Add labels to all the deployed resources
  62. ##
  63. commonLabels: {}
  64. ## @param commonAnnotations Add annotations to all the deployed resources
  65. ##
  66. commonAnnotations: {}
  67. ## Enable diagnostic mode in the statefulset
  68. ##
  69. diagnosticMode:
  70. ## @param diagnosticMode.enabled Enable diagnostic mode (all probes will be disabled and the command will be overridden)
  71. ##
  72. enabled: false
  73. ## @param diagnosticMode.command Command to override all containers in the statefulset
  74. ##
  75. command:
  76. - sleep
  77. ## @param diagnosticMode.args Args to override all containers in the statefulset
  78. ##
  79. args:
  80. - infinity
  81. ## @section PostgreSQL common parameters
  82. ##
  83. ## Bitnami PostgreSQL image version
  84. ## ref: https://hub.docker.com/r/bitnami/postgresql/tags/
  85. ## @param image.registry [default: REGISTRY_NAME] PostgreSQL image registry
  86. ## @param image.repository [default: REPOSITORY_NAME/postgresql] PostgreSQL image repository
  87. ## @skip image.tag PostgreSQL image tag (immutable tags are recommended)
  88. ## @param image.digest PostgreSQL image digest in the way sha256:aa.... Please note this parameter, if set, will override the tag
  89. ## @param image.pullPolicy PostgreSQL image pull policy
  90. ## @param image.pullSecrets Specify image pull secrets
  91. ## @param image.debug Specify if debug values should be set
  92. ##
  93. image:
  94. registry: docker.io
  95. repository: bitnami/postgresql
  96. tag: 16.1.0-debian-11-r26
  97. digest: ""
  98. ## Specify a imagePullPolicy
  99. ## Defaults to 'Always' if image tag is 'latest', else set to 'IfNotPresent'
  100. ## ref: https://kubernetes.io/docs/concepts/containers/images/#pre-pulled-images
  101. ##
  102. pullPolicy: IfNotPresent
  103. ## Optionally specify an array of imagePullSecrets.
  104. ## Secrets must be manually created in the namespace.
  105. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
  106. ## Example:
  107. ## pullSecrets:
  108. ## - myRegistryKeySecretName
  109. ##
  110. pullSecrets: []
  111. ## Set to true if you would like to see extra information on logs
  112. ##
  113. debug: false
  114. ## Authentication parameters
  115. ## ref: https://github.com/bitnami/containers/tree/main/bitnami/postgresql#setting-the-root-password-on-first-run
  116. ## ref: https://github.com/bitnami/containers/tree/main/bitnami/postgresql#creating-a-database-on-first-run
  117. ## ref: https://github.com/bitnami/containers/tree/main/bitnami/postgresql#creating-a-database-user-on-first-run
  118. ##
  119. auth:
  120. ## @param auth.enablePostgresUser Assign a password to the "postgres" admin user. Otherwise, remote access will be blocked for this user
  121. ##
  122. enablePostgresUser: true
  123. ## @param auth.postgresPassword Password for the "postgres" admin user. Ignored if `auth.existingSecret` is provided
  124. ##
  125. postgresPassword: ""
  126. ## @param auth.username Name for a custom user to create
  127. ##
  128. username: ""
  129. ## @param auth.password Password for the custom user to create. Ignored if `auth.existingSecret` is provided
  130. ##
  131. password: ""
  132. ## @param auth.database Name for a custom database to create
  133. ##
  134. database: ""
  135. ## @param auth.replicationUsername Name of the replication user
  136. ##
  137. replicationUsername: repl_user
  138. ## @param auth.replicationPassword Password for the replication user. Ignored if `auth.existingSecret` is provided
  139. ##
  140. replicationPassword: ""
  141. ## @param auth.existingSecret Name of existing secret to use for PostgreSQL credentials. `auth.postgresPassword`, `auth.password`, and `auth.replicationPassword` will be ignored and picked up from this secret. The secret might also contains the key `ldap-password` if LDAP is enabled. `ldap.bind_password` will be ignored and picked from this secret in this case.
  142. ##
  143. existingSecret: ""
  144. ## @param auth.secretKeys.adminPasswordKey Name of key in existing secret to use for PostgreSQL credentials. Only used when `auth.existingSecret` is set.
  145. ## @param auth.secretKeys.userPasswordKey Name of key in existing secret to use for PostgreSQL credentials. Only used when `auth.existingSecret` is set.
  146. ## @param auth.secretKeys.replicationPasswordKey Name of key in existing secret to use for PostgreSQL credentials. Only used when `auth.existingSecret` is set.
  147. ##
  148. secretKeys:
  149. adminPasswordKey: postgres-password
  150. userPasswordKey: password
  151. replicationPasswordKey: replication-password
  152. ## @param auth.usePasswordFiles Mount credentials as a files instead of using an environment variable
  153. ##
  154. usePasswordFiles: false
  155. ## @param architecture PostgreSQL architecture (`standalone` or `replication`)
  156. ##
  157. architecture: standalone
  158. ## Replication configuration
  159. ## Ignored if `architecture` is `standalone`
  160. ##
  161. replication:
  162. ## @param replication.synchronousCommit Set synchronous commit mode. Allowed values: `on`, `remote_apply`, `remote_write`, `local` and `off`
  163. ## @param replication.numSynchronousReplicas Number of replicas that will have synchronous replication. Note: Cannot be greater than `readReplicas.replicaCount`.
  164. ## ref: https://www.postgresql.org/docs/current/runtime-config-wal.html#GUC-SYNCHRONOUS-COMMIT
  165. ##
  166. synchronousCommit: "off"
  167. numSynchronousReplicas: 0
  168. ## @param replication.applicationName Cluster application name. Useful for advanced replication settings
  169. ##
  170. applicationName: my_application
  171. ## @param containerPorts.postgresql PostgreSQL container port
  172. ##
  173. containerPorts:
  174. postgresql: 5432
  175. ## Audit settings
  176. ## https://github.com/bitnami/containers/tree/main/bitnami/postgresql#auditing
  177. ## @param audit.logHostname Log client hostnames
  178. ## @param audit.logConnections Add client log-in operations to the log file
  179. ## @param audit.logDisconnections Add client log-outs operations to the log file
  180. ## @param audit.pgAuditLog Add operations to log using the pgAudit extension
  181. ## @param audit.pgAuditLogCatalog Log catalog using pgAudit
  182. ## @param audit.clientMinMessages Message log level to share with the user
  183. ## @param audit.logLinePrefix Template for log line prefix (default if not set)
  184. ## @param audit.logTimezone Timezone for the log timestamps
  185. ##
  186. audit:
  187. logHostname: false
  188. logConnections: false
  189. logDisconnections: false
  190. pgAuditLog: ""
  191. pgAuditLogCatalog: "off"
  192. clientMinMessages: error
  193. logLinePrefix: ""
  194. logTimezone: ""
  195. ## LDAP configuration
  196. ## @param ldap.enabled Enable LDAP support
  197. ## DEPRECATED ldap.url It will removed in a future, please use 'ldap.uri' instead
  198. ## @param ldap.server IP address or name of the LDAP server.
  199. ## @param ldap.port Port number on the LDAP server to connect to
  200. ## @param ldap.prefix String to prepend to the user name when forming the DN to bind
  201. ## @param ldap.suffix String to append to the user name when forming the DN to bind
  202. ## DEPRECATED ldap.baseDN It will removed in a future, please use 'ldap.basedn' instead
  203. ## DEPRECATED ldap.bindDN It will removed in a future, please use 'ldap.binddn' instead
  204. ## DEPRECATED ldap.bind_password It will removed in a future, please use 'ldap.bindpw' instead
  205. ## @param ldap.basedn Root DN to begin the search for the user in
  206. ## @param ldap.binddn DN of user to bind to LDAP
  207. ## @param ldap.bindpw Password for the user to bind to LDAP
  208. ## DEPRECATED ldap.search_attr It will removed in a future, please use 'ldap.searchAttribute' instead
  209. ## DEPRECATED ldap.search_filter It will removed in a future, please use 'ldap.searchFilter' instead
  210. ## @param ldap.searchAttribute Attribute to match against the user name in the search
  211. ## @param ldap.searchFilter The search filter to use when doing search+bind authentication
  212. ## @param ldap.scheme Set to `ldaps` to use LDAPS
  213. ## DEPRECATED ldap.tls as string is deprecated,please use 'ldap.tls.enabled' instead
  214. ## @param ldap.tls.enabled Se to true to enable TLS encryption
  215. ##
  216. ldap:
  217. enabled: false
  218. server: ""
  219. port: ""
  220. prefix: ""
  221. suffix: ""
  222. basedn: ""
  223. binddn: ""
  224. bindpw: ""
  225. searchAttribute: ""
  226. searchFilter: ""
  227. scheme: ""
  228. tls:
  229. enabled: false
  230. ## @param ldap.uri LDAP URL beginning in the form `ldap[s]://host[:port]/basedn`. If provided, all the other LDAP parameters will be ignored.
  231. ## Ref: https://www.postgresql.org/docs/current/auth-ldap.html
  232. ##
  233. uri: ""
  234. ## @param postgresqlDataDir PostgreSQL data dir folder
  235. ##
  236. postgresqlDataDir: /bitnami/postgresql/data
  237. ## @param postgresqlSharedPreloadLibraries Shared preload libraries (comma-separated list)
  238. ##
  239. postgresqlSharedPreloadLibraries: "pgaudit"
  240. ## Start PostgreSQL pod(s) without limitations on shm memory.
  241. ## By default docker and containerd (and possibly other container runtimes) limit `/dev/shm` to `64M`
  242. ## ref: https://github.com/docker-library/postgres/issues/416
  243. ## ref: https://github.com/containerd/containerd/issues/3654
  244. ##
  245. shmVolume:
  246. ## @param shmVolume.enabled Enable emptyDir volume for /dev/shm for PostgreSQL pod(s)
  247. ##
  248. enabled: true
  249. ## @param shmVolume.sizeLimit Set this to enable a size limit on the shm tmpfs
  250. ## Note: the size of the tmpfs counts against container's memory limit
  251. ## e.g:
  252. ## sizeLimit: 1Gi
  253. ##
  254. sizeLimit: ""
  255. ## TLS configuration
  256. ##
  257. tls:
  258. ## @param tls.enabled Enable TLS traffic support
  259. ##
  260. enabled: false
  261. ## @param tls.autoGenerated Generate automatically self-signed TLS certificates
  262. ##
  263. autoGenerated: false
  264. ## @param tls.preferServerCiphers Whether to use the server's TLS cipher preferences rather than the client's
  265. ##
  266. preferServerCiphers: true
  267. ## @param tls.certificatesSecret Name of an existing secret that contains the certificates
  268. ##
  269. certificatesSecret: ""
  270. ## @param tls.certFilename Certificate filename
  271. ##
  272. certFilename: ""
  273. ## @param tls.certKeyFilename Certificate key filename
  274. ##
  275. certKeyFilename: ""
  276. ## @param tls.certCAFilename CA Certificate filename
  277. ## If provided, PostgreSQL will authenticate TLS/SSL clients by requesting them a certificate
  278. ## ref: https://www.postgresql.org/docs/9.6/auth-methods.html
  279. ##
  280. certCAFilename: ""
  281. ## @param tls.crlFilename File containing a Certificate Revocation List
  282. ##
  283. crlFilename: ""
  284. ## @section PostgreSQL Primary parameters
  285. ##
  286. primary:
  287. ## @param primary.name Name of the primary database (eg primary, master, leader, ...)
  288. ##
  289. name: primary
  290. ## @param primary.configuration PostgreSQL Primary main configuration to be injected as ConfigMap
  291. ## ref: https://www.postgresql.org/docs/current/static/runtime-config.html
  292. ##
  293. configuration: ""
  294. ## @param primary.pgHbaConfiguration PostgreSQL Primary client authentication configuration
  295. ## ref: https://www.postgresql.org/docs/current/static/auth-pg-hba-conf.html
  296. ## e.g:#
  297. ## pgHbaConfiguration: |-
  298. ## local all all trust
  299. ## host all all localhost trust
  300. ## host mydatabase mysuser 192.168.0.0/24 md5
  301. ##
  302. pgHbaConfiguration: ""
  303. ## @param primary.existingConfigmap Name of an existing ConfigMap with PostgreSQL Primary configuration
  304. ## NOTE: `primary.configuration` and `primary.pgHbaConfiguration` will be ignored
  305. ##
  306. existingConfigmap: ""
  307. ## @param primary.extendedConfiguration Extended PostgreSQL Primary configuration (appended to main or default configuration)
  308. ## ref: https://github.com/bitnami/containers/tree/main/bitnami/postgresql#allow-settings-to-be-loaded-from-files-other-than-the-default-postgresqlconf
  309. ##
  310. extendedConfiguration: ""
  311. ## @param primary.existingExtendedConfigmap Name of an existing ConfigMap with PostgreSQL Primary extended configuration
  312. ## NOTE: `primary.extendedConfiguration` will be ignored
  313. ##
  314. existingExtendedConfigmap: ""
  315. ## Initdb configuration
  316. ## ref: https://github.com/bitnami/containers/tree/main/bitnami/postgresql#specifying-initdb-arguments
  317. ##
  318. initdb:
  319. ## @param primary.initdb.args PostgreSQL initdb extra arguments
  320. ##
  321. args: ""
  322. ## @param primary.initdb.postgresqlWalDir Specify a custom location for the PostgreSQL transaction log
  323. ##
  324. postgresqlWalDir: ""
  325. ## @param primary.initdb.scripts Dictionary of initdb scripts
  326. ## Specify dictionary of scripts to be run at first boot
  327. ## e.g:
  328. ## scripts:
  329. ## my_init_script.sh: |
  330. ## #!/bin/sh
  331. ## echo "Do something."
  332. ##
  333. scripts: {}
  334. ## @param primary.initdb.scriptsConfigMap ConfigMap with scripts to be run at first boot
  335. ## NOTE: This will override `primary.initdb.scripts`
  336. ##
  337. scriptsConfigMap: ""
  338. ## @param primary.initdb.scriptsSecret Secret with scripts to be run at first boot (in case it contains sensitive information)
  339. ## NOTE: This can work along `primary.initdb.scripts` or `primary.initdb.scriptsConfigMap`
  340. ##
  341. scriptsSecret: ""
  342. ## @param primary.initdb.user Specify the PostgreSQL username to execute the initdb scripts
  343. ##
  344. user: ""
  345. ## @param primary.initdb.password Specify the PostgreSQL password to execute the initdb scripts
  346. ##
  347. password: ""
  348. ## Configure current cluster's primary server to be the standby server in other cluster.
  349. ## This will allow cross cluster replication and provide cross cluster high availability.
  350. ## You will need to configure pgHbaConfiguration if you want to enable this feature with local cluster replication enabled.
  351. ## @param primary.standby.enabled Whether to enable current cluster's primary as standby server of another cluster or not
  352. ## @param primary.standby.primaryHost The Host of replication primary in the other cluster
  353. ## @param primary.standby.primaryPort The Port of replication primary in the other cluster
  354. ##
  355. standby:
  356. enabled: false
  357. primaryHost: ""
  358. primaryPort: ""
  359. ## @param primary.extraEnvVars Array with extra environment variables to add to PostgreSQL Primary nodes
  360. ## e.g:
  361. ## extraEnvVars:
  362. ## - name: FOO
  363. ## value: "bar"
  364. ##
  365. extraEnvVars: []
  366. ## @param primary.extraEnvVarsCM Name of existing ConfigMap containing extra env vars for PostgreSQL Primary nodes
  367. ##
  368. extraEnvVarsCM: ""
  369. ## @param primary.extraEnvVarsSecret Name of existing Secret containing extra env vars for PostgreSQL Primary nodes
  370. ##
  371. extraEnvVarsSecret: ""
  372. ## @param primary.command Override default container command (useful when using custom images)
  373. ##
  374. command: []
  375. ## @param primary.args Override default container args (useful when using custom images)
  376. ##
  377. args: []
  378. ## Configure extra options for PostgreSQL Primary containers' liveness, readiness and startup probes
  379. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#configure-probes
  380. ## @param primary.livenessProbe.enabled Enable livenessProbe on PostgreSQL Primary containers
  381. ## @param primary.livenessProbe.initialDelaySeconds Initial delay seconds for livenessProbe
  382. ## @param primary.livenessProbe.periodSeconds Period seconds for livenessProbe
  383. ## @param primary.livenessProbe.timeoutSeconds Timeout seconds for livenessProbe
  384. ## @param primary.livenessProbe.failureThreshold Failure threshold for livenessProbe
  385. ## @param primary.livenessProbe.successThreshold Success threshold for livenessProbe
  386. ##
  387. livenessProbe:
  388. enabled: true
  389. initialDelaySeconds: 30
  390. periodSeconds: 10
  391. timeoutSeconds: 5
  392. failureThreshold: 6
  393. successThreshold: 1
  394. ## @param primary.readinessProbe.enabled Enable readinessProbe on PostgreSQL Primary containers
  395. ## @param primary.readinessProbe.initialDelaySeconds Initial delay seconds for readinessProbe
  396. ## @param primary.readinessProbe.periodSeconds Period seconds for readinessProbe
  397. ## @param primary.readinessProbe.timeoutSeconds Timeout seconds for readinessProbe
  398. ## @param primary.readinessProbe.failureThreshold Failure threshold for readinessProbe
  399. ## @param primary.readinessProbe.successThreshold Success threshold for readinessProbe
  400. ##
  401. readinessProbe:
  402. enabled: true
  403. initialDelaySeconds: 5
  404. periodSeconds: 10
  405. timeoutSeconds: 5
  406. failureThreshold: 6
  407. successThreshold: 1
  408. ## @param primary.startupProbe.enabled Enable startupProbe on PostgreSQL Primary containers
  409. ## @param primary.startupProbe.initialDelaySeconds Initial delay seconds for startupProbe
  410. ## @param primary.startupProbe.periodSeconds Period seconds for startupProbe
  411. ## @param primary.startupProbe.timeoutSeconds Timeout seconds for startupProbe
  412. ## @param primary.startupProbe.failureThreshold Failure threshold for startupProbe
  413. ## @param primary.startupProbe.successThreshold Success threshold for startupProbe
  414. ##
  415. startupProbe:
  416. enabled: false
  417. initialDelaySeconds: 30
  418. periodSeconds: 10
  419. timeoutSeconds: 1
  420. failureThreshold: 15
  421. successThreshold: 1
  422. ## @param primary.customLivenessProbe Custom livenessProbe that overrides the default one
  423. ##
  424. customLivenessProbe: {}
  425. ## @param primary.customReadinessProbe Custom readinessProbe that overrides the default one
  426. ##
  427. customReadinessProbe: {}
  428. ## @param primary.customStartupProbe Custom startupProbe that overrides the default one
  429. ##
  430. customStartupProbe: {}
  431. ## @param primary.lifecycleHooks for the PostgreSQL Primary container to automate configuration before or after startup
  432. ##
  433. lifecycleHooks: {}
  434. ## PostgreSQL Primary resource requests and limits
  435. ## ref: https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/
  436. ## @param primary.resources.limits The resources limits for the PostgreSQL Primary containers
  437. ## @param primary.resources.requests.memory The requested memory for the PostgreSQL Primary containers
  438. ## @param primary.resources.requests.cpu The requested cpu for the PostgreSQL Primary containers
  439. ##
  440. resources:
  441. limits: {}
  442. requests:
  443. memory: 256Mi
  444. cpu: 250m
  445. ## Pod Security Context
  446. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
  447. ## @param primary.podSecurityContext.enabled Enable security context
  448. ## @param primary.podSecurityContext.fsGroupChangePolicy Set filesystem group change policy
  449. ## @param primary.podSecurityContext.sysctls Set kernel settings using the sysctl interface
  450. ## @param primary.podSecurityContext.supplementalGroups Set filesystem extra groups
  451. ## @param primary.podSecurityContext.fsGroup Group ID for the pod
  452. ##
  453. podSecurityContext:
  454. enabled: true
  455. fsGroupChangePolicy: Always
  456. sysctls: []
  457. supplementalGroups: []
  458. fsGroup: 1001
  459. ## Container Security Context
  460. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
  461. ## @param primary.containerSecurityContext.enabled Enabled containers' Security Context
  462. ## @param primary.containerSecurityContext.seLinuxOptions [object,nullable] Set SELinux options in container
  463. ## @param primary.containerSecurityContext.runAsUser Set containers' Security Context runAsUser
  464. ## @param primary.containerSecurityContext.runAsNonRoot Set container's Security Context runAsNonRoot
  465. ## @param primary.containerSecurityContext.privileged Set container's Security Context privileged
  466. ## @param primary.containerSecurityContext.readOnlyRootFilesystem Set container's Security Context readOnlyRootFilesystem
  467. ## @param primary.containerSecurityContext.allowPrivilegeEscalation Set container's Security Context allowPrivilegeEscalation
  468. ## @param primary.containerSecurityContext.capabilities.drop List of capabilities to be dropped
  469. ## @param primary.containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile
  470. ##
  471. containerSecurityContext:
  472. enabled: true
  473. seLinuxOptions: null
  474. runAsUser: 1001
  475. runAsNonRoot: true
  476. privileged: false
  477. readOnlyRootFilesystem: false
  478. allowPrivilegeEscalation: false
  479. capabilities:
  480. drop: ["ALL"]
  481. seccompProfile:
  482. type: "RuntimeDefault"
  483. ## @param primary.automountServiceAccountToken Mount Service Account token in pod
  484. ##
  485. automountServiceAccountToken: false
  486. ## @param primary.hostAliases PostgreSQL primary pods host aliases
  487. ## https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/
  488. ##
  489. hostAliases: []
  490. ## @param primary.hostNetwork Specify if host network should be enabled for PostgreSQL pod (postgresql primary)
  491. ##
  492. hostNetwork: false
  493. ## @param primary.hostIPC Specify if host IPC should be enabled for PostgreSQL pod (postgresql primary)
  494. ##
  495. hostIPC: false
  496. ## @param primary.labels Map of labels to add to the statefulset (postgresql primary)
  497. ##
  498. labels: {}
  499. ## @param primary.annotations Annotations for PostgreSQL primary pods
  500. ##
  501. annotations: {}
  502. ## @param primary.podLabels Map of labels to add to the pods (postgresql primary)
  503. ##
  504. podLabels: {}
  505. ## @param primary.podAnnotations Map of annotations to add to the pods (postgresql primary)
  506. ##
  507. podAnnotations: {}
  508. ## @param primary.podAffinityPreset PostgreSQL primary pod affinity preset. Ignored if `primary.affinity` is set. Allowed values: `soft` or `hard`
  509. ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity
  510. ##
  511. podAffinityPreset: ""
  512. ## @param primary.podAntiAffinityPreset PostgreSQL primary pod anti-affinity preset. Ignored if `primary.affinity` is set. Allowed values: `soft` or `hard`
  513. ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity
  514. ##
  515. podAntiAffinityPreset: soft
  516. ## PostgreSQL Primary node affinity preset
  517. ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity
  518. ##
  519. nodeAffinityPreset:
  520. ## @param primary.nodeAffinityPreset.type PostgreSQL primary node affinity preset type. Ignored if `primary.affinity` is set. Allowed values: `soft` or `hard`
  521. ##
  522. type: ""
  523. ## @param primary.nodeAffinityPreset.key PostgreSQL primary node label key to match Ignored if `primary.affinity` is set.
  524. ## E.g.
  525. ## key: "kubernetes.io/e2e-az-name"
  526. ##
  527. key: ""
  528. ## @param primary.nodeAffinityPreset.values PostgreSQL primary node label values to match. Ignored if `primary.affinity` is set.
  529. ## E.g.
  530. ## values:
  531. ## - e2e-az1
  532. ## - e2e-az2
  533. ##
  534. values: []
  535. ## @param primary.affinity Affinity for PostgreSQL primary pods assignment
  536. ## ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
  537. ## Note: primary.podAffinityPreset, primary.podAntiAffinityPreset, and primary.nodeAffinityPreset will be ignored when it's set
  538. ##
  539. affinity: {}
  540. ## @param primary.nodeSelector Node labels for PostgreSQL primary pods assignment
  541. ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/
  542. ##
  543. nodeSelector: {}
  544. ## @param primary.tolerations Tolerations for PostgreSQL primary pods assignment
  545. ## ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
  546. ##
  547. tolerations: []
  548. ## @param primary.topologySpreadConstraints Topology Spread Constraints for pod assignment spread across your cluster among failure-domains. Evaluated as a template
  549. ## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/#spread-constraints-for-pods
  550. ##
  551. topologySpreadConstraints: []
  552. ## @param primary.priorityClassName Priority Class to use for each pod (postgresql primary)
  553. ##
  554. priorityClassName: ""
  555. ## @param primary.schedulerName Use an alternate scheduler, e.g. "stork".
  556. ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/
  557. ##
  558. schedulerName: ""
  559. ## @param primary.terminationGracePeriodSeconds Seconds PostgreSQL primary pod needs to terminate gracefully
  560. ## ref: https://kubernetes.io/docs/concepts/workloads/pods/pod/#termination-of-pods
  561. ##
  562. terminationGracePeriodSeconds: ""
  563. ## @param primary.updateStrategy.type PostgreSQL Primary statefulset strategy type
  564. ## @param primary.updateStrategy.rollingUpdate PostgreSQL Primary statefulset rolling update configuration parameters
  565. ## ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies
  566. ##
  567. updateStrategy:
  568. type: RollingUpdate
  569. rollingUpdate: {}
  570. ## @param primary.extraVolumeMounts Optionally specify extra list of additional volumeMounts for the PostgreSQL Primary container(s)
  571. ##
  572. extraVolumeMounts: []
  573. ## @param primary.extraVolumes Optionally specify extra list of additional volumes for the PostgreSQL Primary pod(s)
  574. ##
  575. extraVolumes: []
  576. ## @param primary.sidecars Add additional sidecar containers to the PostgreSQL Primary pod(s)
  577. ## For example:
  578. ## sidecars:
  579. ## - name: your-image-name
  580. ## image: your-image
  581. ## imagePullPolicy: Always
  582. ## ports:
  583. ## - name: portname
  584. ## containerPort: 1234
  585. ##
  586. sidecars: []
  587. ## @param primary.initContainers Add additional init containers to the PostgreSQL Primary pod(s)
  588. ## Example
  589. ##
  590. ## initContainers:
  591. ## - name: do-something
  592. ## image: busybox
  593. ## command: ['do', 'something']
  594. ##
  595. initContainers: []
  596. ## @param primary.extraPodSpec Optionally specify extra PodSpec for the PostgreSQL Primary pod(s)
  597. ##
  598. extraPodSpec: {}
  599. ## Network Policies
  600. ## Ref: https://kubernetes.io/docs/concepts/services-networking/network-policies/
  601. ##
  602. networkPolicy:
  603. ## @param primary.networkPolicy.enabled Specifies whether a NetworkPolicy should be created
  604. ##
  605. enabled: true
  606. ## @param primary.networkPolicy.allowExternal Don't require server label for connections
  607. ## The Policy model to apply. When set to false, only pods with the correct
  608. ## server label will have network access to the ports server is listening
  609. ## on. When true, server will accept connections from any source
  610. ## (with the correct destination port).
  611. ##
  612. allowExternal: true
  613. ## @param primary.networkPolicy.allowExternalEgress Allow the pod to access any range of port and all destinations.
  614. ##
  615. allowExternalEgress: false
  616. ## @param primary.networkPolicy.extraIngress [array] Add extra ingress rules to the NetworkPolice
  617. ## e.g:
  618. ## extraIngress:
  619. ## - ports:
  620. ## - port: 1234
  621. ## from:
  622. ## - podSelector:
  623. ## - matchLabels:
  624. ## - role: frontend
  625. ## - podSelector:
  626. ## - matchExpressions:
  627. ## - key: role
  628. ## operator: In
  629. ## values:
  630. ## - frontend
  631. extraIngress: []
  632. ## @param primary.networkPolicy.extraEgress [array] Add extra ingress rules to the NetworkPolicy
  633. ## e.g:
  634. ## extraEgress:
  635. ## - ports:
  636. ## - port: 1234
  637. ## to:
  638. ## - podSelector:
  639. ## - matchLabels:
  640. ## - role: frontend
  641. ## - podSelector:
  642. ## - matchExpressions:
  643. ## - key: role
  644. ## operator: In
  645. ## values:
  646. ## - frontend
  647. ##
  648. extraEgress: []
  649. ## @param primary.networkPolicy.ingressNSMatchLabels [object] Labels to match to allow traffic from other namespaces
  650. ## @param primary.networkPolicy.ingressNSPodMatchLabels [object] Pod labels to match to allow traffic from other namespaces
  651. ##
  652. ingressNSMatchLabels: {}
  653. ingressNSPodMatchLabels: {}
  654. ## PostgreSQL Primary service configuration
  655. ##
  656. service:
  657. ## @param primary.service.type Kubernetes Service type
  658. ##
  659. type: ClusterIP
  660. ## @param primary.service.ports.postgresql PostgreSQL service port
  661. ##
  662. ports:
  663. postgresql: 5432
  664. ## Node ports to expose
  665. ## NOTE: choose port between <30000-32767>
  666. ## @param primary.service.nodePorts.postgresql Node port for PostgreSQL
  667. ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport
  668. ##
  669. nodePorts:
  670. postgresql: ""
  671. ## @param primary.service.clusterIP Static clusterIP or None for headless services
  672. ## e.g:
  673. ## clusterIP: None
  674. ##
  675. clusterIP: ""
  676. ## @param primary.service.annotations Annotations for PostgreSQL primary service
  677. ##
  678. annotations: {}
  679. ## @param primary.service.loadBalancerIP Load balancer IP if service type is `LoadBalancer`
  680. ## Set the LoadBalancer service type to internal only
  681. ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer
  682. ##
  683. loadBalancerIP: ""
  684. ## @param primary.service.externalTrafficPolicy Enable client source IP preservation
  685. ## ref https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip
  686. ##
  687. externalTrafficPolicy: Cluster
  688. ## @param primary.service.loadBalancerSourceRanges Addresses that are allowed when service is LoadBalancer
  689. ## https://kubernetes.io/docs/tasks/access-application-cluster/configure-cloud-provider-firewall/#restrict-access-for-loadbalancer-service
  690. ##
  691. ## loadBalancerSourceRanges:
  692. ## - 10.10.10.0/24
  693. ##
  694. loadBalancerSourceRanges: []
  695. ## @param primary.service.extraPorts Extra ports to expose in the PostgreSQL primary service
  696. ##
  697. extraPorts: []
  698. ## @param primary.service.sessionAffinity Session Affinity for Kubernetes service, can be "None" or "ClientIP"
  699. ## If "ClientIP", consecutive client requests will be directed to the same Pod
  700. ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies
  701. ##
  702. sessionAffinity: None
  703. ## @param primary.service.sessionAffinityConfig Additional settings for the sessionAffinity
  704. ## sessionAffinityConfig:
  705. ## clientIP:
  706. ## timeoutSeconds: 300
  707. ##
  708. sessionAffinityConfig: {}
  709. ## Headless service properties
  710. ##
  711. headless:
  712. ## @param primary.service.headless.annotations Additional custom annotations for headless PostgreSQL primary service
  713. ##
  714. annotations: {}
  715. ## PostgreSQL Primary persistence configuration
  716. ##
  717. persistence:
  718. ## @param primary.persistence.enabled Enable PostgreSQL Primary data persistence using PVC
  719. ##
  720. enabled: true
  721. ## @param primary.persistence.existingClaim Name of an existing PVC to use
  722. ##
  723. existingClaim: ""
  724. ## @param primary.persistence.mountPath The path the volume will be mounted at
  725. ## Note: useful when using custom PostgreSQL images
  726. ##
  727. mountPath: /bitnami/postgresql
  728. ## @param primary.persistence.subPath The subdirectory of the volume to mount to
  729. ## Useful in dev environments and one PV for multiple services
  730. ##
  731. subPath: ""
  732. ## @param primary.persistence.storageClass PVC Storage Class for PostgreSQL Primary data volume
  733. ## If defined, storageClassName: <storageClass>
  734. ## If set to "-", storageClassName: "", which disables dynamic provisioning
  735. ## If undefined (the default) or set to null, no storageClassName spec is
  736. ## set, choosing the default provisioner. (gp2 on AWS, standard on
  737. ## GKE, AWS & OpenStack)
  738. ##
  739. storageClass: ""
  740. ## @param primary.persistence.accessModes PVC Access Mode for PostgreSQL volume
  741. ##
  742. accessModes:
  743. - ReadWriteOnce
  744. ## @param primary.persistence.size PVC Storage Request for PostgreSQL volume
  745. ##
  746. size: 8Gi
  747. ## @param primary.persistence.annotations Annotations for the PVC
  748. ##
  749. annotations: {}
  750. ## @param primary.persistence.labels Labels for the PVC
  751. ##
  752. labels: {}
  753. ## @param primary.persistence.selector Selector to match an existing Persistent Volume (this value is evaluated as a template)
  754. ## selector:
  755. ## matchLabels:
  756. ## app: my-app
  757. ##
  758. selector: {}
  759. ## @param primary.persistence.dataSource Custom PVC data source
  760. ##
  761. dataSource: {}
  762. ## PostgreSQL Primary Persistent Volume Claim Retention Policy
  763. ## ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#persistentvolumeclaim-retention
  764. ##
  765. persistentVolumeClaimRetentionPolicy:
  766. ## @param primary.persistentVolumeClaimRetentionPolicy.enabled Enable Persistent volume retention policy for Primary Statefulset
  767. ##
  768. enabled: false
  769. ## @param primary.persistentVolumeClaimRetentionPolicy.whenScaled Volume retention behavior when the replica count of the StatefulSet is reduced
  770. ##
  771. whenScaled: Retain
  772. ## @param primary.persistentVolumeClaimRetentionPolicy.whenDeleted Volume retention behavior that applies when the StatefulSet is deleted
  773. ##
  774. whenDeleted: Retain
  775. ## @section PostgreSQL read only replica parameters (only used when `architecture` is set to `replication`)
  776. ##
  777. readReplicas:
  778. ## @param readReplicas.name Name of the read replicas database (eg secondary, slave, ...)
  779. ##
  780. name: read
  781. ## @param readReplicas.replicaCount Number of PostgreSQL read only replicas
  782. ##
  783. replicaCount: 1
  784. ## @param readReplicas.extendedConfiguration Extended PostgreSQL read only replicas configuration (appended to main or default configuration)
  785. ## ref: https://github.com/bitnami/containers/tree/main/bitnami/postgresql#allow-settings-to-be-loaded-from-files-other-than-the-default-postgresqlconf
  786. ##
  787. extendedConfiguration: ""
  788. ## @param readReplicas.extraEnvVars Array with extra environment variables to add to PostgreSQL read only nodes
  789. ## e.g:
  790. ## extraEnvVars:
  791. ## - name: FOO
  792. ## value: "bar"
  793. ##
  794. extraEnvVars: []
  795. ## @param readReplicas.extraEnvVarsCM Name of existing ConfigMap containing extra env vars for PostgreSQL read only nodes
  796. ##
  797. extraEnvVarsCM: ""
  798. ## @param readReplicas.extraEnvVarsSecret Name of existing Secret containing extra env vars for PostgreSQL read only nodes
  799. ##
  800. extraEnvVarsSecret: ""
  801. ## @param readReplicas.command Override default container command (useful when using custom images)
  802. ##
  803. command: []
  804. ## @param readReplicas.args Override default container args (useful when using custom images)
  805. ##
  806. args: []
  807. ## Configure extra options for PostgreSQL read only containers' liveness, readiness and startup probes
  808. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#configure-probes
  809. ## @param readReplicas.livenessProbe.enabled Enable livenessProbe on PostgreSQL read only containers
  810. ## @param readReplicas.livenessProbe.initialDelaySeconds Initial delay seconds for livenessProbe
  811. ## @param readReplicas.livenessProbe.periodSeconds Period seconds for livenessProbe
  812. ## @param readReplicas.livenessProbe.timeoutSeconds Timeout seconds for livenessProbe
  813. ## @param readReplicas.livenessProbe.failureThreshold Failure threshold for livenessProbe
  814. ## @param readReplicas.livenessProbe.successThreshold Success threshold for livenessProbe
  815. ##
  816. livenessProbe:
  817. enabled: true
  818. initialDelaySeconds: 30
  819. periodSeconds: 10
  820. timeoutSeconds: 5
  821. failureThreshold: 6
  822. successThreshold: 1
  823. ## @param readReplicas.readinessProbe.enabled Enable readinessProbe on PostgreSQL read only containers
  824. ## @param readReplicas.readinessProbe.initialDelaySeconds Initial delay seconds for readinessProbe
  825. ## @param readReplicas.readinessProbe.periodSeconds Period seconds for readinessProbe
  826. ## @param readReplicas.readinessProbe.timeoutSeconds Timeout seconds for readinessProbe
  827. ## @param readReplicas.readinessProbe.failureThreshold Failure threshold for readinessProbe
  828. ## @param readReplicas.readinessProbe.successThreshold Success threshold for readinessProbe
  829. ##
  830. readinessProbe:
  831. enabled: true
  832. initialDelaySeconds: 5
  833. periodSeconds: 10
  834. timeoutSeconds: 5
  835. failureThreshold: 6
  836. successThreshold: 1
  837. ## @param readReplicas.startupProbe.enabled Enable startupProbe on PostgreSQL read only containers
  838. ## @param readReplicas.startupProbe.initialDelaySeconds Initial delay seconds for startupProbe
  839. ## @param readReplicas.startupProbe.periodSeconds Period seconds for startupProbe
  840. ## @param readReplicas.startupProbe.timeoutSeconds Timeout seconds for startupProbe
  841. ## @param readReplicas.startupProbe.failureThreshold Failure threshold for startupProbe
  842. ## @param readReplicas.startupProbe.successThreshold Success threshold for startupProbe
  843. ##
  844. startupProbe:
  845. enabled: false
  846. initialDelaySeconds: 30
  847. periodSeconds: 10
  848. timeoutSeconds: 1
  849. failureThreshold: 15
  850. successThreshold: 1
  851. ## @param readReplicas.customLivenessProbe Custom livenessProbe that overrides the default one
  852. ##
  853. customLivenessProbe: {}
  854. ## @param readReplicas.customReadinessProbe Custom readinessProbe that overrides the default one
  855. ##
  856. customReadinessProbe: {}
  857. ## @param readReplicas.customStartupProbe Custom startupProbe that overrides the default one
  858. ##
  859. customStartupProbe: {}
  860. ## @param readReplicas.lifecycleHooks for the PostgreSQL read only container to automate configuration before or after startup
  861. ##
  862. lifecycleHooks: {}
  863. ## PostgreSQL read only resource requests and limits
  864. ## ref: https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/
  865. ## @param readReplicas.resources.limits The resources limits for the PostgreSQL read only containers
  866. ## @param readReplicas.resources.requests.memory The requested memory for the PostgreSQL read only containers
  867. ## @param readReplicas.resources.requests.cpu The requested cpu for the PostgreSQL read only containers
  868. ##
  869. resources:
  870. limits: {}
  871. requests:
  872. memory: 256Mi
  873. cpu: 250m
  874. ## Pod Security Context
  875. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
  876. ## @param readReplicas.podSecurityContext.enabled Enable security context
  877. ## @param readReplicas.podSecurityContext.fsGroupChangePolicy Set filesystem group change policy
  878. ## @param readReplicas.podSecurityContext.sysctls Set kernel settings using the sysctl interface
  879. ## @param readReplicas.podSecurityContext.supplementalGroups Set filesystem extra groups
  880. ## @param readReplicas.podSecurityContext.fsGroup Group ID for the pod
  881. ##
  882. podSecurityContext:
  883. enabled: true
  884. fsGroupChangePolicy: Always
  885. sysctls: []
  886. supplementalGroups: []
  887. fsGroup: 1001
  888. ## Container Security Context
  889. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
  890. ## @param readReplicas.containerSecurityContext.enabled Enabled containers' Security Context
  891. ## @param readReplicas.containerSecurityContext.seLinuxOptions [object,nullable] Set SELinux options in container
  892. ## @param readReplicas.containerSecurityContext.runAsUser Set containers' Security Context runAsUser
  893. ## @param readReplicas.containerSecurityContext.runAsNonRoot Set container's Security Context runAsNonRoot
  894. ## @param readReplicas.containerSecurityContext.privileged Set container's Security Context privileged
  895. ## @param readReplicas.containerSecurityContext.readOnlyRootFilesystem Set container's Security Context readOnlyRootFilesystem
  896. ## @param readReplicas.containerSecurityContext.allowPrivilegeEscalation Set container's Security Context allowPrivilegeEscalation
  897. ## @param readReplicas.containerSecurityContext.capabilities.drop List of capabilities to be dropped
  898. ## @param readReplicas.containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile
  899. ##
  900. containerSecurityContext:
  901. enabled: true
  902. seLinuxOptions: null
  903. runAsUser: 1001
  904. runAsNonRoot: true
  905. privileged: false
  906. readOnlyRootFilesystem: false
  907. allowPrivilegeEscalation: false
  908. capabilities:
  909. drop: ["ALL"]
  910. seccompProfile:
  911. type: "RuntimeDefault"
  912. ## @param readReplicas.automountServiceAccountToken Mount Service Account token in pod
  913. ##
  914. automountServiceAccountToken: false
  915. ## @param readReplicas.hostAliases PostgreSQL read only pods host aliases
  916. ## https://kubernetes.io/docs/concepts/services-networking/add-entries-to-pod-etc-hosts-with-host-aliases/
  917. ##
  918. hostAliases: []
  919. ## @param readReplicas.hostNetwork Specify if host network should be enabled for PostgreSQL pod (PostgreSQL read only)
  920. ##
  921. hostNetwork: false
  922. ## @param readReplicas.hostIPC Specify if host IPC should be enabled for PostgreSQL pod (postgresql primary)
  923. ##
  924. hostIPC: false
  925. ## @param readReplicas.labels Map of labels to add to the statefulset (PostgreSQL read only)
  926. ##
  927. labels: {}
  928. ## @param readReplicas.annotations Annotations for PostgreSQL read only pods
  929. ##
  930. annotations: {}
  931. ## @param readReplicas.podLabels Map of labels to add to the pods (PostgreSQL read only)
  932. ##
  933. podLabels: {}
  934. ## @param readReplicas.podAnnotations Map of annotations to add to the pods (PostgreSQL read only)
  935. ##
  936. podAnnotations: {}
  937. ## @param readReplicas.podAffinityPreset PostgreSQL read only pod affinity preset. Ignored if `primary.affinity` is set. Allowed values: `soft` or `hard`
  938. ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity
  939. ##
  940. podAffinityPreset: ""
  941. ## @param readReplicas.podAntiAffinityPreset PostgreSQL read only pod anti-affinity preset. Ignored if `primary.affinity` is set. Allowed values: `soft` or `hard`
  942. ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#inter-pod-affinity-and-anti-affinity
  943. ##
  944. podAntiAffinityPreset: soft
  945. ## PostgreSQL read only node affinity preset
  946. ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity
  947. ##
  948. nodeAffinityPreset:
  949. ## @param readReplicas.nodeAffinityPreset.type PostgreSQL read only node affinity preset type. Ignored if `primary.affinity` is set. Allowed values: `soft` or `hard`
  950. ##
  951. type: ""
  952. ## @param readReplicas.nodeAffinityPreset.key PostgreSQL read only node label key to match Ignored if `primary.affinity` is set.
  953. ## E.g.
  954. ## key: "kubernetes.io/e2e-az-name"
  955. ##
  956. key: ""
  957. ## @param readReplicas.nodeAffinityPreset.values PostgreSQL read only node label values to match. Ignored if `primary.affinity` is set.
  958. ## E.g.
  959. ## values:
  960. ## - e2e-az1
  961. ## - e2e-az2
  962. ##
  963. values: []
  964. ## @param readReplicas.affinity Affinity for PostgreSQL read only pods assignment
  965. ## ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#affinity-and-anti-affinity
  966. ## Note: primary.podAffinityPreset, primary.podAntiAffinityPreset, and primary.nodeAffinityPreset will be ignored when it's set
  967. ##
  968. affinity: {}
  969. ## @param readReplicas.nodeSelector Node labels for PostgreSQL read only pods assignment
  970. ## ref: https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/
  971. ##
  972. nodeSelector: {}
  973. ## @param readReplicas.tolerations Tolerations for PostgreSQL read only pods assignment
  974. ## ref: https://kubernetes.io/docs/concepts/configuration/taint-and-toleration/
  975. ##
  976. tolerations: []
  977. ## @param readReplicas.topologySpreadConstraints Topology Spread Constraints for pod assignment spread across your cluster among failure-domains. Evaluated as a template
  978. ## Ref: https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/#spread-constraints-for-pods
  979. ##
  980. topologySpreadConstraints: []
  981. ## @param readReplicas.priorityClassName Priority Class to use for each pod (PostgreSQL read only)
  982. ##
  983. priorityClassName: ""
  984. ## @param readReplicas.schedulerName Use an alternate scheduler, e.g. "stork".
  985. ## ref: https://kubernetes.io/docs/tasks/administer-cluster/configure-multiple-schedulers/
  986. ##
  987. schedulerName: ""
  988. ## @param readReplicas.terminationGracePeriodSeconds Seconds PostgreSQL read only pod needs to terminate gracefully
  989. ## ref: https://kubernetes.io/docs/concepts/workloads/pods/pod/#termination-of-pods
  990. ##
  991. terminationGracePeriodSeconds: ""
  992. ## @param readReplicas.updateStrategy.type PostgreSQL read only statefulset strategy type
  993. ## @param readReplicas.updateStrategy.rollingUpdate PostgreSQL read only statefulset rolling update configuration parameters
  994. ## ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#update-strategies
  995. ##
  996. updateStrategy:
  997. type: RollingUpdate
  998. rollingUpdate: {}
  999. ## @param readReplicas.extraVolumeMounts Optionally specify extra list of additional volumeMounts for the PostgreSQL read only container(s)
  1000. ##
  1001. extraVolumeMounts: []
  1002. ## @param readReplicas.extraVolumes Optionally specify extra list of additional volumes for the PostgreSQL read only pod(s)
  1003. ##
  1004. extraVolumes: []
  1005. ## @param readReplicas.sidecars Add additional sidecar containers to the PostgreSQL read only pod(s)
  1006. ## For example:
  1007. ## sidecars:
  1008. ## - name: your-image-name
  1009. ## image: your-image
  1010. ## imagePullPolicy: Always
  1011. ## ports:
  1012. ## - name: portname
  1013. ## containerPort: 1234
  1014. ##
  1015. sidecars: []
  1016. ## @param readReplicas.initContainers Add additional init containers to the PostgreSQL read only pod(s)
  1017. ## Example
  1018. ##
  1019. ## initContainers:
  1020. ## - name: do-something
  1021. ## image: busybox
  1022. ## command: ['do', 'something']
  1023. ##
  1024. initContainers: []
  1025. ## @param readReplicas.extraPodSpec Optionally specify extra PodSpec for the PostgreSQL read only pod(s)
  1026. ##
  1027. extraPodSpec: {}
  1028. ## Network Policies
  1029. ## Ref: https://kubernetes.io/docs/concepts/services-networking/network-policies/
  1030. ##
  1031. networkPolicy:
  1032. ## @param readReplicas.networkPolicy.enabled Specifies whether a NetworkPolicy should be created
  1033. ##
  1034. enabled: true
  1035. ## @param readReplicas.networkPolicy.allowExternal Don't require server label for connections
  1036. ## The Policy model to apply. When set to false, only pods with the correct
  1037. ## server label will have network access to the ports server is listening
  1038. ## on. When true, server will accept connections from any source
  1039. ## (with the correct destination port).
  1040. ##
  1041. allowExternal: true
  1042. ## @param readReplicas.networkPolicy.allowExternalEgress Allow the pod to access any range of port and all destinations.
  1043. ##
  1044. allowExternalEgress: false
  1045. ## @param readReplicas.networkPolicy.extraIngress [array] Add extra ingress rules to the NetworkPolice
  1046. ## e.g:
  1047. ## extraIngress:
  1048. ## - ports:
  1049. ## - port: 1234
  1050. ## from:
  1051. ## - podSelector:
  1052. ## - matchLabels:
  1053. ## - role: frontend
  1054. ## - podSelector:
  1055. ## - matchExpressions:
  1056. ## - key: role
  1057. ## operator: In
  1058. ## values:
  1059. ## - frontend
  1060. extraIngress: []
  1061. ## @param readReplicas.networkPolicy.extraEgress [array] Add extra ingress rules to the NetworkPolicy
  1062. ## e.g:
  1063. ## extraEgress:
  1064. ## - ports:
  1065. ## - port: 1234
  1066. ## to:
  1067. ## - podSelector:
  1068. ## - matchLabels:
  1069. ## - role: frontend
  1070. ## - podSelector:
  1071. ## - matchExpressions:
  1072. ## - key: role
  1073. ## operator: In
  1074. ## values:
  1075. ## - frontend
  1076. ##
  1077. extraEgress: []
  1078. ## @param readReplicas.networkPolicy.ingressNSMatchLabels [object] Labels to match to allow traffic from other namespaces
  1079. ## @param readReplicas.networkPolicy.ingressNSPodMatchLabels [object] Pod labels to match to allow traffic from other namespaces
  1080. ##
  1081. ingressNSMatchLabels: {}
  1082. ingressNSPodMatchLabels: {}
  1083. ## PostgreSQL read only service configuration
  1084. ##
  1085. service:
  1086. ## @param readReplicas.service.type Kubernetes Service type
  1087. ##
  1088. type: ClusterIP
  1089. ## @param readReplicas.service.ports.postgresql PostgreSQL service port
  1090. ##
  1091. ports:
  1092. postgresql: 5432
  1093. ## Node ports to expose
  1094. ## NOTE: choose port between <30000-32767>
  1095. ## @param readReplicas.service.nodePorts.postgresql Node port for PostgreSQL
  1096. ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#type-nodeport
  1097. ##
  1098. nodePorts:
  1099. postgresql: ""
  1100. ## @param readReplicas.service.clusterIP Static clusterIP or None for headless services
  1101. ## e.g:
  1102. ## clusterIP: None
  1103. ##
  1104. clusterIP: ""
  1105. ## @param readReplicas.service.annotations Annotations for PostgreSQL read only service
  1106. ##
  1107. annotations: {}
  1108. ## @param readReplicas.service.loadBalancerIP Load balancer IP if service type is `LoadBalancer`
  1109. ## Set the LoadBalancer service type to internal only
  1110. ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#internal-load-balancer
  1111. ##
  1112. loadBalancerIP: ""
  1113. ## @param readReplicas.service.externalTrafficPolicy Enable client source IP preservation
  1114. ## ref https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip
  1115. ##
  1116. externalTrafficPolicy: Cluster
  1117. ## @param readReplicas.service.loadBalancerSourceRanges Addresses that are allowed when service is LoadBalancer
  1118. ## https://kubernetes.io/docs/tasks/access-application-cluster/configure-cloud-provider-firewall/#restrict-access-for-loadbalancer-service
  1119. ##
  1120. ## loadBalancerSourceRanges:
  1121. ## - 10.10.10.0/24
  1122. ##
  1123. loadBalancerSourceRanges: []
  1124. ## @param readReplicas.service.extraPorts Extra ports to expose in the PostgreSQL read only service
  1125. ##
  1126. extraPorts: []
  1127. ## @param readReplicas.service.sessionAffinity Session Affinity for Kubernetes service, can be "None" or "ClientIP"
  1128. ## If "ClientIP", consecutive client requests will be directed to the same Pod
  1129. ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#virtual-ips-and-service-proxies
  1130. ##
  1131. sessionAffinity: None
  1132. ## @param readReplicas.service.sessionAffinityConfig Additional settings for the sessionAffinity
  1133. ## sessionAffinityConfig:
  1134. ## clientIP:
  1135. ## timeoutSeconds: 300
  1136. ##
  1137. sessionAffinityConfig: {}
  1138. ## Headless service properties
  1139. ##
  1140. headless:
  1141. ## @param readReplicas.service.headless.annotations Additional custom annotations for headless PostgreSQL read only service
  1142. ##
  1143. annotations: {}
  1144. ## PostgreSQL read only persistence configuration
  1145. ##
  1146. persistence:
  1147. ## @param readReplicas.persistence.enabled Enable PostgreSQL read only data persistence using PVC
  1148. ##
  1149. enabled: true
  1150. ## @param readReplicas.persistence.existingClaim Name of an existing PVC to use
  1151. ##
  1152. existingClaim: ""
  1153. ## @param readReplicas.persistence.mountPath The path the volume will be mounted at
  1154. ## Note: useful when using custom PostgreSQL images
  1155. ##
  1156. mountPath: /bitnami/postgresql
  1157. ## @param readReplicas.persistence.subPath The subdirectory of the volume to mount to
  1158. ## Useful in dev environments and one PV for multiple services
  1159. ##
  1160. subPath: ""
  1161. ## @param readReplicas.persistence.storageClass PVC Storage Class for PostgreSQL read only data volume
  1162. ## If defined, storageClassName: <storageClass>
  1163. ## If set to "-", storageClassName: "", which disables dynamic provisioning
  1164. ## If undefined (the default) or set to null, no storageClassName spec is
  1165. ## set, choosing the default provisioner. (gp2 on AWS, standard on
  1166. ## GKE, AWS & OpenStack)
  1167. ##
  1168. storageClass: ""
  1169. ## @param readReplicas.persistence.accessModes PVC Access Mode for PostgreSQL volume
  1170. ##
  1171. accessModes:
  1172. - ReadWriteOnce
  1173. ## @param readReplicas.persistence.size PVC Storage Request for PostgreSQL volume
  1174. ##
  1175. size: 8Gi
  1176. ## @param readReplicas.persistence.annotations Annotations for the PVC
  1177. ##
  1178. annotations: {}
  1179. ## @param readReplicas.persistence.labels Labels for the PVC
  1180. ##
  1181. labels: {}
  1182. ## @param readReplicas.persistence.selector Selector to match an existing Persistent Volume (this value is evaluated as a template)
  1183. ## selector:
  1184. ## matchLabels:
  1185. ## app: my-app
  1186. ##
  1187. selector: {}
  1188. ## @param readReplicas.persistence.dataSource Custom PVC data source
  1189. ##
  1190. dataSource: {}
  1191. ## PostgreSQL Read only Persistent Volume Claim Retention Policy
  1192. ## ref: https://kubernetes.io/docs/concepts/workloads/controllers/statefulset/#persistentvolumeclaim-retention
  1193. ##
  1194. persistentVolumeClaimRetentionPolicy:
  1195. ## @param readReplicas.persistentVolumeClaimRetentionPolicy.enabled Enable Persistent volume retention policy for read only Statefulset
  1196. ##
  1197. enabled: false
  1198. ## @param readReplicas.persistentVolumeClaimRetentionPolicy.whenScaled Volume retention behavior when the replica count of the StatefulSet is reduced
  1199. ##
  1200. whenScaled: Retain
  1201. ## @param readReplicas.persistentVolumeClaimRetentionPolicy.whenDeleted Volume retention behavior that applies when the StatefulSet is deleted
  1202. ##
  1203. whenDeleted: Retain
  1204. ## @section Backup parameters
  1205. ## This section implements a trivial logical dump cronjob of the database.
  1206. ## This only comes with the consistency guarantees of the dump program.
  1207. ## This is not a snapshot based roll forward/backward recovery backup.
  1208. ## ref: https://kubernetes.io/docs/concepts/workloads/controllers/cron-jobs/
  1209. backup:
  1210. ## @param backup.enabled Enable the logical dump of the database "regularly"
  1211. enabled: false
  1212. cronjob:
  1213. ## @param backup.cronjob.schedule Set the cronjob parameter schedule
  1214. schedule: "@daily"
  1215. ## @param backup.cronjob.timeZone Set the cronjob parameter timeZone
  1216. timeZone: ""
  1217. ## @param backup.cronjob.concurrencyPolicy Set the cronjob parameter concurrencyPolicy
  1218. concurrencyPolicy: Allow
  1219. ## @param backup.cronjob.failedJobsHistoryLimit Set the cronjob parameter failedJobsHistoryLimit
  1220. failedJobsHistoryLimit: 1
  1221. ## @param backup.cronjob.successfulJobsHistoryLimit Set the cronjob parameter successfulJobsHistoryLimit
  1222. successfulJobsHistoryLimit: 3
  1223. ## @param backup.cronjob.startingDeadlineSeconds Set the cronjob parameter startingDeadlineSeconds
  1224. startingDeadlineSeconds: ""
  1225. ## @param backup.cronjob.ttlSecondsAfterFinished Set the cronjob parameter ttlSecondsAfterFinished
  1226. ttlSecondsAfterFinished: ""
  1227. ## @param backup.cronjob.restartPolicy Set the cronjob parameter restartPolicy
  1228. restartPolicy: OnFailure
  1229. ## @param backup.cronjob.podSecurityContext.enabled Enable PodSecurityContext for CronJob/Backup
  1230. ## @param backup.cronjob.podSecurityContext.fsGroupChangePolicy Set filesystem group change policy
  1231. ## @param backup.cronjob.podSecurityContext.sysctls Set kernel settings using the sysctl interface
  1232. ## @param backup.cronjob.podSecurityContext.supplementalGroups Set filesystem extra groups
  1233. ## @param backup.cronjob.podSecurityContext.fsGroup Group ID for the CronJob
  1234. podSecurityContext:
  1235. enabled: true
  1236. fsGroupChangePolicy: Always
  1237. sysctls: []
  1238. supplementalGroups: []
  1239. fsGroup: 1001
  1240. ## backup container's Security Context
  1241. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
  1242. ## @param backup.cronjob.containerSecurityContext.enabled Enabled containers' Security Context
  1243. ## @param backup.cronjob.containerSecurityContext.seLinuxOptions [object,nullable] Set SELinux options in container
  1244. ## @param backup.cronjob.containerSecurityContext.runAsUser Set containers' Security Context runAsUser
  1245. ## @param backup.cronjob.containerSecurityContext.runAsNonRoot Set container's Security Context runAsNonRoot
  1246. ## @param backup.cronjob.containerSecurityContext.privileged Set container's Security Context privileged
  1247. ## @param backup.cronjob.containerSecurityContext.readOnlyRootFilesystem Set container's Security Context readOnlyRootFilesystem
  1248. ## @param backup.cronjob.containerSecurityContext.allowPrivilegeEscalation Set container's Security Context allowPrivilegeEscalation
  1249. ## @param backup.cronjob.containerSecurityContext.capabilities.drop List of capabilities to be dropped
  1250. ## @param backup.cronjob.containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile
  1251. containerSecurityContext:
  1252. enabled: true
  1253. seLinuxOptions: null
  1254. runAsUser: 1001
  1255. runAsNonRoot: true
  1256. privileged: false
  1257. readOnlyRootFilesystem: false
  1258. allowPrivilegeEscalation: false
  1259. capabilities:
  1260. drop: ["ALL"]
  1261. seccompProfile:
  1262. type: "RuntimeDefault"
  1263. ## @param backup.cronjob.command Set backup container's command to run
  1264. command:
  1265. - /bin/sh
  1266. - -c
  1267. - "pg_dumpall --clean --if-exists --load-via-partition-root --quote-all-identifiers --no-password --file=${PGDUMP_DIR}/pg_dumpall-$(date '+%Y-%m-%d-%H-%M').pgdump"
  1268. ## @param backup.cronjob.labels Set the cronjob labels
  1269. labels: {}
  1270. ## @param backup.cronjob.annotations Set the cronjob annotations
  1271. annotations: {}
  1272. ## @param backup.cronjob.nodeSelector Node labels for PostgreSQL backup CronJob pod assignment
  1273. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/assign-pods-nodes/
  1274. ##
  1275. nodeSelector: {}
  1276. storage:
  1277. ## @param backup.cronjob.storage.existingClaim Provide an existing `PersistentVolumeClaim` (only when `architecture=standalone`)
  1278. ## If defined, PVC must be created manually before volume will be bound
  1279. ##
  1280. existingClaim: ""
  1281. ## @param backup.cronjob.storage.resourcePolicy Setting it to "keep" to avoid removing PVCs during a helm delete operation. Leaving it empty will delete PVCs after the chart deleted
  1282. ##
  1283. resourcePolicy: ""
  1284. ## @param backup.cronjob.storage.storageClass PVC Storage Class for the backup data volume
  1285. ## If defined, storageClassName: <storageClass>
  1286. ## If set to "-", storageClassName: "", which disables dynamic provisioning
  1287. ## If undefined (the default) or set to null, no storageClassName spec is
  1288. ## set, choosing the default provisioner.
  1289. ##
  1290. storageClass: ""
  1291. ## @param backup.cronjob.storage.accessModes PV Access Mode
  1292. ##
  1293. accessModes:
  1294. - ReadWriteOnce
  1295. ## @param backup.cronjob.storage.size PVC Storage Request for the backup data volume
  1296. ##
  1297. size: 8Gi
  1298. ## @param backup.cronjob.storage.annotations PVC annotations
  1299. ##
  1300. annotations: {}
  1301. ## @param backup.cronjob.storage.mountPath Path to mount the volume at
  1302. ##
  1303. mountPath: /backup/pgdump
  1304. ## @param backup.cronjob.storage.subPath Subdirectory of the volume to mount at
  1305. ## and one PV for multiple services.
  1306. ##
  1307. subPath: ""
  1308. ## Fine tuning for volumeClaimTemplates
  1309. ##
  1310. volumeClaimTemplates:
  1311. ## @param backup.cronjob.storage.volumeClaimTemplates.selector A label query over volumes to consider for binding (e.g. when using local volumes)
  1312. ## A label query over volumes to consider for binding (e.g. when using local volumes)
  1313. ## See https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.20/#labelselector-v1-meta for more details
  1314. ##
  1315. selector: {}
  1316. ## @section NetworkPolicy parameters
  1317. ##
  1318. ## Add networkpolicies
  1319. ##
  1320. networkPolicy:
  1321. ## @param networkPolicy.enabled Enable network policies
  1322. ##
  1323. enabled: false
  1324. ## @param networkPolicy.metrics.enabled Enable network policies for metrics (prometheus)
  1325. ## @param networkPolicy.metrics.namespaceSelector [object] Monitoring namespace selector labels. These labels will be used to identify the prometheus' namespace.
  1326. ## @param networkPolicy.metrics.podSelector [object] Monitoring pod selector labels. These labels will be used to identify the Prometheus pods.
  1327. ##
  1328. metrics:
  1329. enabled: false
  1330. ## e.g:
  1331. ## namespaceSelector:
  1332. ## label: monitoring
  1333. ##
  1334. namespaceSelector: {}
  1335. ## e.g:
  1336. ## podSelector:
  1337. ## label: monitoring
  1338. ##
  1339. podSelector: {}
  1340. ## Ingress Rules
  1341. ##
  1342. ingressRules:
  1343. ## @param networkPolicy.ingressRules.primaryAccessOnlyFrom.enabled Enable ingress rule that makes PostgreSQL primary node only accessible from a particular origin.
  1344. ## @param networkPolicy.ingressRules.primaryAccessOnlyFrom.namespaceSelector [object] Namespace selector label that is allowed to access the PostgreSQL primary node. This label will be used to identified the allowed namespace(s).
  1345. ## @param networkPolicy.ingressRules.primaryAccessOnlyFrom.podSelector [object] Pods selector label that is allowed to access the PostgreSQL primary node. This label will be used to identified the allowed pod(s).
  1346. ## @param networkPolicy.ingressRules.primaryAccessOnlyFrom.customRules Custom network policy for the PostgreSQL primary node.
  1347. ##
  1348. primaryAccessOnlyFrom:
  1349. enabled: false
  1350. ## e.g:
  1351. ## namespaceSelector:
  1352. ## label: ingress
  1353. ##
  1354. namespaceSelector: {}
  1355. ## e.g:
  1356. ## podSelector:
  1357. ## label: access
  1358. ##
  1359. podSelector: {}
  1360. ## custom ingress rules
  1361. ## e.g:
  1362. ## customRules:
  1363. ## - from:
  1364. ## - namespaceSelector:
  1365. ## matchLabels:
  1366. ## label: example
  1367. ##
  1368. customRules: []
  1369. ## @param networkPolicy.ingressRules.readReplicasAccessOnlyFrom.enabled Enable ingress rule that makes PostgreSQL read-only nodes only accessible from a particular origin.
  1370. ## @param networkPolicy.ingressRules.readReplicasAccessOnlyFrom.namespaceSelector [object] Namespace selector label that is allowed to access the PostgreSQL read-only nodes. This label will be used to identified the allowed namespace(s).
  1371. ## @param networkPolicy.ingressRules.readReplicasAccessOnlyFrom.podSelector [object] Pods selector label that is allowed to access the PostgreSQL read-only nodes. This label will be used to identified the allowed pod(s).
  1372. ## @param networkPolicy.ingressRules.readReplicasAccessOnlyFrom.customRules Custom network policy for the PostgreSQL read-only nodes.
  1373. ##
  1374. readReplicasAccessOnlyFrom:
  1375. enabled: false
  1376. ## e.g:
  1377. ## namespaceSelector:
  1378. ## label: ingress
  1379. ##
  1380. namespaceSelector: {}
  1381. ## e.g:
  1382. ## podSelector:
  1383. ## label: access
  1384. ##
  1385. podSelector: {}
  1386. ## custom ingress rules
  1387. ## e.g:
  1388. ## CustomRules:
  1389. ## - from:
  1390. ## - namespaceSelector:
  1391. ## matchLabels:
  1392. ## label: example
  1393. ##
  1394. customRules: []
  1395. ## @param networkPolicy.egressRules.denyConnectionsToExternal Enable egress rule that denies outgoing traffic outside the cluster, except for DNS (port 53).
  1396. ## @param networkPolicy.egressRules.customRules Custom network policy rule
  1397. ##
  1398. egressRules:
  1399. # Deny connections to external. This is not compatible with an external database.
  1400. denyConnectionsToExternal: false
  1401. ## Additional custom egress rules
  1402. ## e.g:
  1403. ## customRules:
  1404. ## - to:
  1405. ## - namespaceSelector:
  1406. ## matchLabels:
  1407. ## label: example
  1408. ##
  1409. customRules: []
  1410. ## @section Volume Permissions parameters
  1411. ##
  1412. ## Init containers parameters:
  1413. ## volumePermissions: Change the owner and group of the persistent volume(s) mountpoint(s) to 'runAsUser:fsGroup' on each node
  1414. ##
  1415. volumePermissions:
  1416. ## @param volumePermissions.enabled Enable init container that changes the owner and group of the persistent volume
  1417. ##
  1418. enabled: false
  1419. ## @param volumePermissions.image.registry [default: REGISTRY_NAME] Init container volume-permissions image registry
  1420. ## @param volumePermissions.image.repository [default: REPOSITORY_NAME/os-shell] Init container volume-permissions image repository
  1421. ## @skip volumePermissions.image.tag Init container volume-permissions image tag (immutable tags are recommended)
  1422. ## @param volumePermissions.image.digest Init container volume-permissions image digest in the way sha256:aa.... Please note this parameter, if set, will override the tag
  1423. ## @param volumePermissions.image.pullPolicy Init container volume-permissions image pull policy
  1424. ## @param volumePermissions.image.pullSecrets Init container volume-permissions image pull secrets
  1425. ##
  1426. image:
  1427. registry: docker.io
  1428. repository: bitnami/os-shell
  1429. tag: 11-debian-11-r96
  1430. digest: ""
  1431. pullPolicy: IfNotPresent
  1432. ## Optionally specify an array of imagePullSecrets.
  1433. ## Secrets must be manually created in the namespace.
  1434. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
  1435. ## Example:
  1436. ## pullSecrets:
  1437. ## - myRegistryKeySecretName
  1438. ##
  1439. pullSecrets: []
  1440. ## Init container resource requests and limits
  1441. ## ref: https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/
  1442. ## @param volumePermissions.resources.limits Init container volume-permissions resource limits
  1443. ## @param volumePermissions.resources.requests Init container volume-permissions resource requests
  1444. ##
  1445. resources:
  1446. limits: {}
  1447. requests: {}
  1448. ## Init container' Security Context
  1449. ## Note: the chown of the data folder is done to containerSecurityContext.runAsUser
  1450. ## and not the below volumePermissions.containerSecurityContext.runAsUser
  1451. ## @param volumePermissions.containerSecurityContext.seLinuxOptions [object,nullable] Set SELinux options in container
  1452. ## @param volumePermissions.containerSecurityContext.runAsUser User ID for the init container
  1453. ## @param volumePermissions.containerSecurityContext.runAsGroup Group ID for the init container
  1454. ## @param volumePermissions.containerSecurityContext.runAsNonRoot runAsNonRoot for the init container
  1455. ## @param volumePermissions.containerSecurityContext.seccompProfile.type seccompProfile.type for the init container
  1456. ##
  1457. containerSecurityContext:
  1458. seLinuxOptions: null
  1459. runAsUser: 0
  1460. runAsGroup: 0
  1461. runAsNonRoot: false
  1462. seccompProfile:
  1463. type: RuntimeDefault
  1464. ## @section Other Parameters
  1465. ##
  1466. ## @param serviceBindings.enabled Create secret for service binding (Experimental)
  1467. ## Ref: https://servicebinding.io/service-provider/
  1468. ##
  1469. serviceBindings:
  1470. enabled: false
  1471. ## Service account for PostgreSQL to use.
  1472. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/
  1473. ##
  1474. serviceAccount:
  1475. ## @param serviceAccount.create Enable creation of ServiceAccount for PostgreSQL pod
  1476. ##
  1477. create: true
  1478. ## @param serviceAccount.name The name of the ServiceAccount to use.
  1479. ## If not set and create is true, a name is generated using the common.names.fullname template
  1480. ##
  1481. name: ""
  1482. ## @param serviceAccount.automountServiceAccountToken Allows auto mount of ServiceAccountToken on the serviceAccount created
  1483. ## Can be set to false if pods using this serviceAccount do not need to use K8s API
  1484. ##
  1485. automountServiceAccountToken: false
  1486. ## @param serviceAccount.annotations Additional custom annotations for the ServiceAccount
  1487. ##
  1488. annotations: {}
  1489. ## Creates role for ServiceAccount
  1490. ## @param rbac.create Create Role and RoleBinding (required for PSP to work)
  1491. ##
  1492. rbac:
  1493. create: false
  1494. ## @param rbac.rules Custom RBAC rules to set
  1495. ## e.g:
  1496. ## rules:
  1497. ## - apiGroups:
  1498. ## - ""
  1499. ## resources:
  1500. ## - pods
  1501. ## verbs:
  1502. ## - get
  1503. ## - list
  1504. ##
  1505. rules: []
  1506. ## Pod Security Policy
  1507. ## ref: https://kubernetes.io/docs/concepts/policy/pod-security-policy/
  1508. ## @param psp.create Whether to create a PodSecurityPolicy. WARNING: PodSecurityPolicy is deprecated in Kubernetes v1.21 or later, unavailable in v1.25 or later
  1509. ##
  1510. psp:
  1511. create: false
  1512. ## @section Metrics Parameters
  1513. ##
  1514. metrics:
  1515. ## @param metrics.enabled Start a prometheus exporter
  1516. ##
  1517. enabled: true
  1518. ## @param metrics.image.registry [default: REGISTRY_NAME] PostgreSQL Prometheus Exporter image registry
  1519. ## @param metrics.image.repository [default: REPOSITORY_NAME/postgres-exporter] PostgreSQL Prometheus Exporter image repository
  1520. ## @skip metrics.image.tag PostgreSQL Prometheus Exporter image tag (immutable tags are recommended)
  1521. ## @param metrics.image.digest PostgreSQL image digest in the way sha256:aa.... Please note this parameter, if set, will override the tag
  1522. ## @param metrics.image.pullPolicy PostgreSQL Prometheus Exporter image pull policy
  1523. ## @param metrics.image.pullSecrets Specify image pull secrets
  1524. ##
  1525. image:
  1526. registry: docker.io
  1527. repository: bitnami/postgres-exporter
  1528. tag: 0.15.0-debian-11-r8
  1529. digest: ""
  1530. pullPolicy: IfNotPresent
  1531. ## Optionally specify an array of imagePullSecrets.
  1532. ## Secrets must be manually created in the namespace.
  1533. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/
  1534. ## Example:
  1535. ## pullSecrets:
  1536. ## - myRegistryKeySecretName
  1537. ##
  1538. pullSecrets: []
  1539. ## @param metrics.collectors Control enabled collectors
  1540. ## ref: https://github.com/prometheus-community/postgres_exporter#flags
  1541. ## Example:
  1542. ## collectors:
  1543. ## wal: false
  1544. collectors: {}
  1545. ## @param metrics.customMetrics Define additional custom metrics
  1546. ## ref: https://github.com/prometheus-community/postgres_exporter#adding-new-metrics-via-a-config-file-deprecated
  1547. ## customMetrics:
  1548. ## pg_database:
  1549. ## query: "SELECT d.datname AS name, CASE WHEN pg_catalog.has_database_privilege(d.datname, 'CONNECT') THEN pg_catalog.pg_database_size(d.datname) ELSE 0 END AS size_bytes FROM pg_catalog.pg_database d where datname not in ('template0', 'template1', 'postgres')"
  1550. ## metrics:
  1551. ## - name:
  1552. ## usage: "LABEL"
  1553. ## description: "Name of the database"
  1554. ## - size_bytes:
  1555. ## usage: "GAUGE"
  1556. ## description: "Size of the database in bytes"
  1557. ##
  1558. customMetrics: {}
  1559. ## @param metrics.extraEnvVars Extra environment variables to add to PostgreSQL Prometheus exporter
  1560. ## see: https://github.com/prometheus-community/postgres_exporter#environment-variables
  1561. ## For example:
  1562. ## extraEnvVars:
  1563. ## - name: PG_EXPORTER_DISABLE_DEFAULT_METRICS
  1564. ## value: "true"
  1565. ##
  1566. extraEnvVars: []
  1567. ## PostgreSQL Prometheus exporter containers' Security Context
  1568. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/#set-the-security-context-for-a-container
  1569. ## @param metrics.containerSecurityContext.enabled Enabled containers' Security Context
  1570. ## @param metrics.containerSecurityContext.seLinuxOptions [object,nullable] Set SELinux options in container
  1571. ## @param metrics.containerSecurityContext.runAsUser Set containers' Security Context runAsUser
  1572. ## @param metrics.containerSecurityContext.runAsNonRoot Set container's Security Context runAsNonRoot
  1573. ## @param metrics.containerSecurityContext.privileged Set container's Security Context privileged
  1574. ## @param metrics.containerSecurityContext.readOnlyRootFilesystem Set container's Security Context readOnlyRootFilesystem
  1575. ## @param metrics.containerSecurityContext.allowPrivilegeEscalation Set container's Security Context allowPrivilegeEscalation
  1576. ## @param metrics.containerSecurityContext.capabilities.drop List of capabilities to be dropped
  1577. ## @param metrics.containerSecurityContext.seccompProfile.type Set container's Security Context seccomp profile
  1578. ##
  1579. containerSecurityContext:
  1580. enabled: true
  1581. seLinuxOptions: null
  1582. runAsUser: 1001
  1583. runAsNonRoot: true
  1584. privileged: false
  1585. readOnlyRootFilesystem: false
  1586. allowPrivilegeEscalation: false
  1587. capabilities:
  1588. drop: ["ALL"]
  1589. seccompProfile:
  1590. type: "RuntimeDefault"
  1591. ## Configure extra options for PostgreSQL Prometheus exporter containers' liveness, readiness and startup probes
  1592. ## ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-startup-probes/#configure-probes
  1593. ## @param metrics.livenessProbe.enabled Enable livenessProbe on PostgreSQL Prometheus exporter containers
  1594. ## @param metrics.livenessProbe.initialDelaySeconds Initial delay seconds for livenessProbe
  1595. ## @param metrics.livenessProbe.periodSeconds Period seconds for livenessProbe
  1596. ## @param metrics.livenessProbe.timeoutSeconds Timeout seconds for livenessProbe
  1597. ## @param metrics.livenessProbe.failureThreshold Failure threshold for livenessProbe
  1598. ## @param metrics.livenessProbe.successThreshold Success threshold for livenessProbe
  1599. ##
  1600. livenessProbe:
  1601. enabled: true
  1602. initialDelaySeconds: 5
  1603. periodSeconds: 10
  1604. timeoutSeconds: 5
  1605. failureThreshold: 6
  1606. successThreshold: 1
  1607. ## @param metrics.readinessProbe.enabled Enable readinessProbe on PostgreSQL Prometheus exporter containers
  1608. ## @param metrics.readinessProbe.initialDelaySeconds Initial delay seconds for readinessProbe
  1609. ## @param metrics.readinessProbe.periodSeconds Period seconds for readinessProbe
  1610. ## @param metrics.readinessProbe.timeoutSeconds Timeout seconds for readinessProbe
  1611. ## @param metrics.readinessProbe.failureThreshold Failure threshold for readinessProbe
  1612. ## @param metrics.readinessProbe.successThreshold Success threshold for readinessProbe
  1613. ##
  1614. readinessProbe:
  1615. enabled: true
  1616. initialDelaySeconds: 5
  1617. periodSeconds: 10
  1618. timeoutSeconds: 5
  1619. failureThreshold: 6
  1620. successThreshold: 1
  1621. ## @param metrics.startupProbe.enabled Enable startupProbe on PostgreSQL Prometheus exporter containers
  1622. ## @param metrics.startupProbe.initialDelaySeconds Initial delay seconds for startupProbe
  1623. ## @param metrics.startupProbe.periodSeconds Period seconds for startupProbe
  1624. ## @param metrics.startupProbe.timeoutSeconds Timeout seconds for startupProbe
  1625. ## @param metrics.startupProbe.failureThreshold Failure threshold for startupProbe
  1626. ## @param metrics.startupProbe.successThreshold Success threshold for startupProbe
  1627. ##
  1628. startupProbe:
  1629. enabled: false
  1630. initialDelaySeconds: 10
  1631. periodSeconds: 10
  1632. timeoutSeconds: 1
  1633. failureThreshold: 15
  1634. successThreshold: 1
  1635. ## @param metrics.customLivenessProbe Custom livenessProbe that overrides the default one
  1636. ##
  1637. customLivenessProbe: {}
  1638. ## @param metrics.customReadinessProbe Custom readinessProbe that overrides the default one
  1639. ##
  1640. customReadinessProbe: {}
  1641. ## @param metrics.customStartupProbe Custom startupProbe that overrides the default one
  1642. ##
  1643. customStartupProbe: {}
  1644. ## @param metrics.containerPorts.metrics PostgreSQL Prometheus exporter metrics container port
  1645. ##
  1646. containerPorts:
  1647. metrics: 9187
  1648. ## PostgreSQL Prometheus exporter resource requests and limits
  1649. ## ref: https://kubernetes.io/docs/concepts/configuration/manage-compute-resources-container/
  1650. ## @param metrics.resources.limits The resources limits for the PostgreSQL Prometheus exporter container
  1651. ## @param metrics.resources.requests The requested resources for the PostgreSQL Prometheus exporter container
  1652. ##
  1653. resources:
  1654. limits: {}
  1655. requests: {}
  1656. ## Service configuration
  1657. ##
  1658. service:
  1659. ## @param metrics.service.ports.metrics PostgreSQL Prometheus Exporter service port
  1660. ##
  1661. ports:
  1662. metrics: 9187
  1663. ## @param metrics.service.clusterIP Static clusterIP or None for headless services
  1664. ## ref: https://kubernetes.io/docs/concepts/services-networking/service/#choosing-your-own-ip-address
  1665. ##
  1666. clusterIP: ""
  1667. ## @param metrics.service.sessionAffinity Control where client requests go, to the same pod or round-robin
  1668. ## Values: ClientIP or None
  1669. ## ref: https://kubernetes.io/docs/concepts/services-networking/service/
  1670. ##
  1671. sessionAffinity: None
  1672. ## @param metrics.service.annotations [object] Annotations for Prometheus to auto-discover the metrics endpoint
  1673. ##
  1674. annotations:
  1675. prometheus.io/scrape: "true"
  1676. prometheus.io/port: "{{ .Values.metrics.service.ports.metrics }}"
  1677. ## Prometheus Operator ServiceMonitor configuration
  1678. ##
  1679. serviceMonitor:
  1680. ## @param metrics.serviceMonitor.enabled Create ServiceMonitor Resource for scraping metrics using Prometheus Operator
  1681. ##
  1682. enabled: false
  1683. ## @param metrics.serviceMonitor.namespace Namespace for the ServiceMonitor Resource (defaults to the Release Namespace)
  1684. ##
  1685. namespace: ""
  1686. ## @param metrics.serviceMonitor.interval Interval at which metrics should be scraped.
  1687. ## ref: https://github.com/coreos/prometheus-operator/blob/master/Documentation/api.md#endpoint
  1688. ##
  1689. interval: ""
  1690. ## @param metrics.serviceMonitor.scrapeTimeout Timeout after which the scrape is ended
  1691. ## ref: https://github.com/coreos/prometheus-operator/blob/master/Documentation/api.md#endpoint
  1692. ##
  1693. scrapeTimeout: ""
  1694. ## @param metrics.serviceMonitor.labels Additional labels that can be used so ServiceMonitor will be discovered by Prometheus
  1695. ##
  1696. labels: {}
  1697. ## @param metrics.serviceMonitor.selector Prometheus instance selector labels
  1698. ## ref: https://github.com/bitnami/charts/tree/main/bitnami/prometheus-operator#prometheus-configuration
  1699. ##
  1700. selector: {}
  1701. ## @param metrics.serviceMonitor.relabelings RelabelConfigs to apply to samples before scraping
  1702. ##
  1703. relabelings: []
  1704. ## @param metrics.serviceMonitor.metricRelabelings MetricRelabelConfigs to apply to samples before ingestion
  1705. ##
  1706. metricRelabelings: []
  1707. ## @param metrics.serviceMonitor.honorLabels Specify honorLabels parameter to add the scrape endpoint
  1708. ##
  1709. honorLabels: false
  1710. ## @param metrics.serviceMonitor.jobLabel The name of the label on the target service to use as the job name in prometheus.
  1711. ##
  1712. jobLabel: ""
  1713. ## Custom PrometheusRule to be defined
  1714. ## The value is evaluated as a template, so, for example, the value can depend on .Release or .Chart
  1715. ## ref: https://github.com/coreos/prometheus-operator#customresourcedefinitions
  1716. ##
  1717. prometheusRule:
  1718. ## @param metrics.prometheusRule.enabled Create a PrometheusRule for Prometheus Operator
  1719. ##
  1720. enabled: false
  1721. ## @param metrics.prometheusRule.namespace Namespace for the PrometheusRule Resource (defaults to the Release Namespace)
  1722. ##
  1723. namespace: ""
  1724. ## @param metrics.prometheusRule.labels Additional labels that can be used so PrometheusRule will be discovered by Prometheus
  1725. ##
  1726. labels: {}
  1727. ## @param metrics.prometheusRule.rules PrometheusRule definitions
  1728. ## Make sure to constraint the rules to the current postgresql service.
  1729. ## rules:
  1730. ## - alert: HugeReplicationLag
  1731. ## expr: pg_replication_lag{service="{{ printf "%s-metrics" (include "common.names.fullname" .) }}"} / 3600 > 1
  1732. ## for: 1m
  1733. ## labels:
  1734. ## severity: critical
  1735. ## annotations:
  1736. ## description: replication for {{ include "common.names.fullname" . }} PostgreSQL is lagging by {{ "{{ $value }}" }} hour(s).
  1737. ## summary: PostgreSQL replication is lagging by {{ "{{ $value }}" }} hour(s).
  1738. ##
  1739. rules: []