Skip to content

helm: let the chart use an external PostgreSQL - #25

Merged
convee merged 1 commit into
mainfrom
feat/external-postgres
Sep 10, 2026
Merged

convee merged 1 commit into
mainfrom
feat/external-postgres

Conversation

@convee

@convee convee commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

postgresql.embedded.enabled: false already dropped the bundled StatefulSet, its Service and its ingress NetworkPolicy, but the Control Plane kept a hardcoded in-cluster host (SANDBOX_DB_HOST: sandbox-postgres) and had no port of its own. A release built for an external server therefore dialled a Service the same render had declined to create.

postgresql.external.host and postgresql.external.port now supply SANDBOX_DB_HOST and SANDBOX_DB_PORT. The credential contract is unchanged - postgresql.authSecret is mounted in either mode - so an external server only needs a Secret carrying its own database, username and password, and the database and role must already exist there.

An empty postgresql.external.host fails helm template rather than falling back to sandbox-postgres, which is the process default: a silent fallback would ship a release that starts, reports ready, and answers every request from a Service that does not exist.

Rebased on the current main; the README test count moves 878 -> 880 for the two new tests.

Verified

  • helm lint charts/sandbox - ok
  • helm template in both modes: 30 -> 27 documents with the bundled server off, and no sandbox-postgres Service, StatefulSet or NetworkPolicy left
  • tests/test_helm_package.py - two new tests (external replaces the bundled one; an empty host refuses), 11 passing there
  • Full suite with the documented dependencies installed (pip install -e '.[test]'): unittest discover -s tests -p 'test_*.py' - OK (skipped=2), 880 tests

`postgresql.embedded.enabled: false` already dropped the bundled StatefulSet,
its Service and its ingress NetworkPolicy, but the Control Plane kept a
hardcoded in-cluster host and had no port of its own, so the release dialled a
Service the same render had declined to create.

`postgresql.external.host` and `postgresql.external.port` now supply
SANDBOX_DB_HOST and SANDBOX_DB_PORT. The credential contract is unchanged -
`postgresql.authSecret` is mounted in either mode, so an external server only
needs a Secret carrying its own values, and the database and role must already
exist there.

An empty host fails `helm template`. The Control Plane's own default is
`sandbox-postgres`, so a silent fallback would ship a release that starts,
reports ready, and answers every request from a Service that does not exist.
@convee
convee merged commit beb163f into main Sep 10, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant