arrstack: gate apps on DB via initContainer instead of sync-waves
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful

Per review: drop the ArgoCD sync-wave annotations (their health-gating is
what deadlocked the first deploy) and instead add a wait-for-db init
container to each app that blocks until its own Postgres database+role is
reachable (libpq PG* env, password never in argv). ArgoCD applies
everything at once; the app container only starts once its DB is ready.
This commit is contained in:
2026-08-22 12:38:02 +10:00
parent df687e310b
commit 60309fc5c2
9 changed files with 114 additions and 22 deletions
@@ -7,9 +7,6 @@ kind: ObjectStoreUser
metadata:
name: cnpg-arrstack-backup
namespace: arrstack
annotations:
# S3 creds Secret must exist before the Cluster (wave -2) reconciles its backup.
argocd.argoproj.io/sync-wave: "-3"
spec:
displayName: "CNPG backup owner (arrstack)"
uid: cnpg-arrstack-backup
@@ -22,8 +19,6 @@ kind: Bucket
metadata:
name: cnpg-arrstack
namespace: arrstack
annotations:
argocd.argoproj.io/sync-wave: "-3"
spec:
placementTarget: ec
bucketName: cnpg-arrstack
@@ -11,11 +11,6 @@ kind: Cluster
metadata:
name: arrstack-postgres
namespace: arrstack
annotations:
# Wave 1: the per-app <app>-db Secrets (wave 0) must exist first — CNPG reads
# them as the managed roles' passwordSecret. ArgoCD gates dependents on the
# Cluster's health status.
argocd.argoproj.io/sync-wave: "-2"
spec:
inheritedMetadata:
annotations:
@@ -7,8 +7,6 @@ kind: Database
metadata:
name: prowlarr-main
namespace: arrstack
annotations:
argocd.argoproj.io/sync-wave: "-1"
spec:
cluster:
name: arrstack-postgres
@@ -7,8 +7,6 @@ kind: Database
metadata:
name: radarr-main
namespace: arrstack
annotations:
argocd.argoproj.io/sync-wave: "-1"
spec:
cluster:
name: arrstack-postgres
@@ -7,8 +7,6 @@ kind: Database
metadata:
name: sonarr-main
namespace: arrstack
annotations:
argocd.argoproj.io/sync-wave: "-1"
spec:
cluster:
name: arrstack-postgres
@@ -13,8 +13,6 @@ kind: VaultStaticSecret
metadata:
name: sonarr-db
namespace: arrstack
annotations:
argocd.argoproj.io/sync-wave: "-3"
spec:
destination:
create: true
@@ -32,8 +30,6 @@ kind: VaultStaticSecret
metadata:
name: radarr-db
namespace: arrstack
annotations:
argocd.argoproj.io/sync-wave: "-3"
spec:
destination:
create: true
@@ -51,8 +47,6 @@ kind: VaultStaticSecret
metadata:
name: prowlarr-db
namespace: arrstack
annotations:
argocd.argoproj.io/sync-wave: "-3"
spec:
destination:
create: true
@@ -28,6 +28,44 @@ spec:
runAsGroup: 1000
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
initContainers:
# Gate the app on its own Postgres database+role being reachable, instead
# of relying on ArgoCD sync-waves (which deadlock if apps aren't Healthy).
# libpq reads PG* from env, so the password never lands in argv.
- name: wait-for-db
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/postgres:17-alpine
command:
- sh
- -c
- |
until psql -tAc 'select 1' >/dev/null 2>&1; do
echo "waiting for $PGDATABASE on $PGHOST..."; sleep 3
done
echo "database ready"
env:
- name: PGHOST
value: arrstack-postgres-rw.arrstack.svc.cluster.local
- name: PGPORT
value: "5432"
- name: PGDATABASE
value: prowlarr-main
- name: PGUSER
valueFrom:
secretKeyRef:
name: prowlarr-db
key: username
- name: PGPASSWORD
valueFrom:
secretKeyRef:
name: prowlarr-db
key: password
resources:
requests:
cpu: 10m
memory: 32Mi
limits:
cpu: 100m
memory: 64Mi
containers:
- name: prowlarr
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/prowlarr:v2.6.2-unkin2
+38
View File
@@ -28,6 +28,44 @@ spec:
runAsGroup: 1000
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
initContainers:
# Gate the app on its own Postgres database+role being reachable, instead
# of relying on ArgoCD sync-waves (which deadlock if apps aren't Healthy).
# libpq reads PG* from env, so the password never lands in argv.
- name: wait-for-db
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/postgres:17-alpine
command:
- sh
- -c
- |
until psql -tAc 'select 1' >/dev/null 2>&1; do
echo "waiting for $PGDATABASE on $PGHOST..."; sleep 3
done
echo "database ready"
env:
- name: PGHOST
value: arrstack-postgres-rw.arrstack.svc.cluster.local
- name: PGPORT
value: "5432"
- name: PGDATABASE
value: radarr-main
- name: PGUSER
valueFrom:
secretKeyRef:
name: radarr-db
key: username
- name: PGPASSWORD
valueFrom:
secretKeyRef:
name: radarr-db
key: password
resources:
requests:
cpu: 10m
memory: 32Mi
limits:
cpu: 100m
memory: 64Mi
containers:
- name: radarr
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/radarr:v6.4.2-unkin2
+38
View File
@@ -28,6 +28,44 @@ spec:
runAsGroup: 1000
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
initContainers:
# Gate the app on its own Postgres database+role being reachable, instead
# of relying on ArgoCD sync-waves (which deadlock if apps aren't Healthy).
# libpq reads PG* from env, so the password never lands in argv.
- name: wait-for-db
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/postgres:17-alpine
command:
- sh
- -c
- |
until psql -tAc 'select 1' >/dev/null 2>&1; do
echo "waiting for $PGDATABASE on $PGHOST..."; sleep 3
done
echo "database ready"
env:
- name: PGHOST
value: arrstack-postgres-rw.arrstack.svc.cluster.local
- name: PGPORT
value: "5432"
- name: PGDATABASE
value: sonarr-main
- name: PGUSER
valueFrom:
secretKeyRef:
name: sonarr-db
key: username
- name: PGPASSWORD
valueFrom:
secretKeyRef:
name: sonarr-db
key: password
resources:
requests:
cpu: 10m
memory: 32Mi
limits:
cpu: 100m
memory: 64Mi
containers:
- name: sonarr
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/sonarr:v5.0.0-unkin2