Skip to content

chart: refuse a half-configured external PostgreSQL - #12

Merged
convee merged 1 commit into
mainfrom
feat/external-postgres
Sep 10, 2026
Merged

convee merged 1 commit into
mainfrom
feat/external-postgres

Conversation

@convee

@convee convee commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

postgresql.embedded.enabled: false already dropped the bundled PostgreSQL StatefulSet, its Service and its ingress NetworkPolicy, but three values kept defaults that only make sense while that server exists:

  • database.host still named sites-postgres;
  • database.runtimeHost still resolved that Service's in-cluster DNS name for the tenant-facing runtime Secret;
  • SITES_DB_SSLMODE was hardcoded disable.

Each one renders, applies and rolls out while the control plane dials a Service this render declined to create, so all three now fail at helm template in that mode.

database.sslmode joins the values surface as a stated choice. The bundled install keeps disable, because that image serves no certificate and the hop never leaves the cluster; an external deployment has to say require, verify-ca, verify-full or disable rather than inherit require from the code while the chart's comment still describes a hop that is gone.

Rebased on the current main (the newcomer/quickstart batch), so the README test count moves 1060 -> 1063 for the three new tests.

Verified

  • helm lint charts/site - ok
  • helm template in both modes: 35 -> 32 documents with the bundled server off, and no sites-postgres Service/StatefulSet/NetworkPolicy left in the release
  • tests/test_helm_package.py - three new tests (external replaces the bundled one; the default render is the negative control; all three half-configurations refuse); test_helm_package + test_readme_claims = 34 passing
  • 232 chart-related tests across test_exposure, test_monitoring, test_registry_proxy, test_scale_to_zero, test_cluster_network, test_static_runtime and test_builds - one error, environment-only: GatewayQuotaEnforcementTests.setUpClass needs the throwaway PostgreSQL on 127.0.0.1:55439 (make test-db; no Docker daemon was running on the machine that ran this)

`postgresql.embedded.enabled: false` already dropped the bundled StatefulSet,
its Service and its ingress NetworkPolicy, but three values kept defaults that
only make sense while that server exists:

- `database.host` still named `sites-postgres`;
- `database.runtimeHost` still resolved that Service's in-cluster DNS name for
  the tenant-facing runtime Secret;
- `SITES_DB_SSLMODE` was hardcoded `disable`.

Each one renders, applies and rolls out while the control plane dials a Service
this render declined to create, so all three now fail at `helm template` in that
mode.

`database.sslmode` joins the values surface as a stated choice. The bundled
install keeps `disable`, because that image serves no certificate and the hop
never leaves the cluster; an external deployment has to say `require`,
`verify-ca`, `verify-full` or `disable` rather than inherit "require" from the
code while the chart's comment still describes a hop that is gone.
@convee
convee merged commit 3adec9a into main Sep 10, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant