blob: e89e9db51263a7ae576bfbd1b5e907353465f354 [file] [log] [blame]
Sergiusz Bazanski5f2dc852019-04-02 02:36:22 +02001# PostgreSQL on Kubernetes.
2
3local kube = import "kube.libsonnet";
4
5{
6 local postgres = self,
7 local cfg = postgres.cfg,
8 cfg:: {
9 namespace: error "namespace must be set",
10 appName: error "app name must be set",
Sergiusz Bazanskid07861b2019-08-08 17:48:25 +020011 storageClassName: "waw-hdd-paranoid-2",
Sergiusz Bazanski5f2dc852019-04-02 02:36:22 +020012 prefix: "", # if set, should be 'foo-'
13
14 image: "postgres:10.4",
15 database: error "database must be set",
16 username: error "username must be set",
17 # not literal, instead ref for env (like { secretKeyRef: ... })
18 password: error "password must be set",
Serge Bazanskic0c037a2020-08-23 01:24:03 +000019
20 storageSize: "30Gi",
Sergiusz Bazanski5f2dc852019-04-02 02:36:22 +020021 },
22
23 makeName(suffix):: cfg.prefix + suffix,
24
25 metadata:: {
26 namespace: cfg.namespace,
27 labels: {
28 "app.kubernetes.io/name": cfg.appName,
29 "app.kubernetes.io/managed-by": "kubecfg",
30 "app.kubernetes.io/component": "postgres",
31 },
32 },
33
34 volumeClaim: kube.PersistentVolumeClaim(postgres.makeName("postgres")) {
35 metadata+: postgres.metadata,
36 spec+: {
37 storageClassName: cfg.storageClassName,
38 accessModes: [ "ReadWriteOnce" ],
39 resources: {
40 requests: {
Serge Bazanskic0c037a2020-08-23 01:24:03 +000041 storage: cfg.storageSize,
Sergiusz Bazanski5f2dc852019-04-02 02:36:22 +020042 },
43 },
44 },
45 },
46 deployment: kube.Deployment(postgres.makeName("postgres")) {
47 metadata+: postgres.metadata,
48 spec+: {
49 replicas: 1,
50 template+: {
51 spec+: {
52 volumes_: {
53 data: kube.PersistentVolumeClaimVolume(postgres.volumeClaim),
54 },
55 containers_: {
56 postgres: kube.Container(postgres.makeName("postgres")) {
57 image: cfg.image,
58 ports_: {
59 client: { containerPort: 5432 },
60 },
61 env_: {
62 POSTGRES_DB: cfg.database,
63 POSTGRES_USER: cfg.username,
64 POSTGRES_PASSWORD: cfg.password,
65 PGDATA: "/var/lib/postgresql/data/pgdata",
66 },
67 volumeMounts_: {
68 data: { mountPath: "/var/lib/postgresql/data" },
69 },
70 },
71 },
Sergiusz Bazanskia2ee8652020-01-22 21:48:48 +010072 securityContext: {
73 runAsUser: 999,
74 },
Sergiusz Bazanski5f2dc852019-04-02 02:36:22 +020075 },
76 },
77 },
78 },
Serge Bazanskic0c037a2020-08-23 01:24:03 +000079
Sergiusz Bazanski5f2dc852019-04-02 02:36:22 +020080 svc: kube.Service(postgres.makeName("postgres")) {
81 metadata+: postgres.metadata,
82 target_pod:: postgres.deployment.spec.template,
83 spec+: {
84 ports: [
85 { name: "client", port: 5432, targetPort: 5432, protocol: "TCP" },
86 ],
87 type: "ClusterIP",
88 },
89 },
Sergiusz Bazanskic622a192020-02-15 12:39:14 +010090
91 bouncer: {
92 deployment: kube.Deployment(postgres.makeName("bouncer")) {
93 metadata+: postgres.metadata {
94 labels+: {
95 "app.kubernetes.io/component": "bouncer",
96 }
97 },
98 spec+: {
99 replicas: 1,
100 template+: {
101 spec+: {
102 containers_: {
103 bouncer: kube.Container(postgres.makeName("bouncer")) {
104 image: "edoburu/pgbouncer:1.11.0",
105 ports_: {
106 client: { containerPort: 5432 },
107 },
108 env: [
109 { name: "POSTGRES_PASSWORD", valueFrom: cfg.password },
110 { name: "DATABASE_URL", value: "postgres://%s:$(POSTGRES_PASSWORD)@%s/%s" % [cfg.username, postgres.svc.host, cfg.database] },
111 ],
112 },
113 },
114 },
115 },
116 },
117 },
118 svc: kube.Service(postgres.makeName("bouncer")) {
119 metadata+: postgres.metadata {
120 labels+: {
121 "app.kubernetes.io/component": "bouncer",
122 }
123 },
124 target_pod:: postgres.bouncer.deployment.spec.template,
125 spec+: {
126 ports: [
127 { name: "client", port: 5432, targetPort: 5432, protocol: "TCP" },
128 ],
129 type: "ClusterIP",
130 },
131 },
132 },
Sergiusz Bazanski5f2dc852019-04-02 02:36:22 +0200133}