helm: let the chart use an external PostgreSQL - #25
Merged
Merged
Conversation
`postgresql.embedded.enabled: false` already dropped the bundled StatefulSet, its Service and its ingress NetworkPolicy, but the Control Plane kept a hardcoded in-cluster host and had no port of its own, so the release dialled a Service the same render had declined to create. `postgresql.external.host` and `postgresql.external.port` now supply SANDBOX_DB_HOST and SANDBOX_DB_PORT. The credential contract is unchanged - `postgresql.authSecret` is mounted in either mode, so an external server only needs a Secret carrying its own values, and the database and role must already exist there. An empty host fails `helm template`. The Control Plane's own default is `sandbox-postgres`, so a silent fallback would ship a release that starts, reports ready, and answers every request from a Service that does not exist.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
postgresql.embedded.enabled: falsealready dropped the bundled StatefulSet, its Service and its ingress NetworkPolicy, but the Control Plane kept a hardcoded in-cluster host (SANDBOX_DB_HOST: sandbox-postgres) and had no port of its own. A release built for an external server therefore dialled a Service the same render had declined to create.postgresql.external.hostandpostgresql.external.portnow supplySANDBOX_DB_HOSTandSANDBOX_DB_PORT. The credential contract is unchanged -postgresql.authSecretis mounted in either mode - so an external server only needs a Secret carrying its owndatabase,usernameandpassword, and the database and role must already exist there.An empty
postgresql.external.hostfailshelm templaterather than falling back tosandbox-postgres, which is the process default: a silent fallback would ship a release that starts, reports ready, and answers every request from a Service that does not exist.Rebased on the current
main; the README test count moves 878 -> 880 for the two new tests.Verified
helm lint charts/sandbox- okhelm templatein both modes: 30 -> 27 documents with the bundled server off, and nosandbox-postgresService, StatefulSet or NetworkPolicy lefttests/test_helm_package.py- two new tests (external replaces the bundled one; an empty host refuses), 11 passing therepip install -e '.[test]'):unittest discover -s tests -p 'test_*.py'- OK (skipped=2), 880 tests