arrstack: gate apps on DB via initContainer instead of sync-waves
Per review: drop the ArgoCD sync-wave annotations (their health-gating is what deadlocked the first deploy) and instead add a wait-for-db init container to each app that blocks until its own Postgres database+role is reachable (libpq PG* env, password never in argv). ArgoCD applies everything at once; the app container only starts once its DB is ready.
This commit is contained in:
@@ -7,9 +7,6 @@ kind: ObjectStoreUser
|
||||
metadata:
|
||||
name: cnpg-arrstack-backup
|
||||
namespace: arrstack
|
||||
annotations:
|
||||
# S3 creds Secret must exist before the Cluster (wave -2) reconciles its backup.
|
||||
argocd.argoproj.io/sync-wave: "-3"
|
||||
spec:
|
||||
displayName: "CNPG backup owner (arrstack)"
|
||||
uid: cnpg-arrstack-backup
|
||||
@@ -22,8 +19,6 @@ kind: Bucket
|
||||
metadata:
|
||||
name: cnpg-arrstack
|
||||
namespace: arrstack
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "-3"
|
||||
spec:
|
||||
placementTarget: ec
|
||||
bucketName: cnpg-arrstack
|
||||
|
||||
@@ -11,11 +11,6 @@ kind: Cluster
|
||||
metadata:
|
||||
name: arrstack-postgres
|
||||
namespace: arrstack
|
||||
annotations:
|
||||
# Wave 1: the per-app <app>-db Secrets (wave 0) must exist first — CNPG reads
|
||||
# them as the managed roles' passwordSecret. ArgoCD gates dependents on the
|
||||
# Cluster's health status.
|
||||
argocd.argoproj.io/sync-wave: "-2"
|
||||
spec:
|
||||
inheritedMetadata:
|
||||
annotations:
|
||||
|
||||
@@ -7,8 +7,6 @@ kind: Database
|
||||
metadata:
|
||||
name: prowlarr-main
|
||||
namespace: arrstack
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "-1"
|
||||
spec:
|
||||
cluster:
|
||||
name: arrstack-postgres
|
||||
|
||||
@@ -7,8 +7,6 @@ kind: Database
|
||||
metadata:
|
||||
name: radarr-main
|
||||
namespace: arrstack
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "-1"
|
||||
spec:
|
||||
cluster:
|
||||
name: arrstack-postgres
|
||||
|
||||
@@ -7,8 +7,6 @@ kind: Database
|
||||
metadata:
|
||||
name: sonarr-main
|
||||
namespace: arrstack
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "-1"
|
||||
spec:
|
||||
cluster:
|
||||
name: arrstack-postgres
|
||||
|
||||
@@ -13,8 +13,6 @@ kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: sonarr-db
|
||||
namespace: arrstack
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "-3"
|
||||
spec:
|
||||
destination:
|
||||
create: true
|
||||
@@ -32,8 +30,6 @@ kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: radarr-db
|
||||
namespace: arrstack
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "-3"
|
||||
spec:
|
||||
destination:
|
||||
create: true
|
||||
@@ -51,8 +47,6 @@ kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: prowlarr-db
|
||||
namespace: arrstack
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "-3"
|
||||
spec:
|
||||
destination:
|
||||
create: true
|
||||
|
||||
@@ -28,6 +28,44 @@ spec:
|
||||
runAsGroup: 1000
|
||||
fsGroup: 1000
|
||||
fsGroupChangePolicy: OnRootMismatch
|
||||
initContainers:
|
||||
# Gate the app on its own Postgres database+role being reachable, instead
|
||||
# of relying on ArgoCD sync-waves (which deadlock if apps aren't Healthy).
|
||||
# libpq reads PG* from env, so the password never lands in argv.
|
||||
- name: wait-for-db
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/postgres:17-alpine
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
until psql -tAc 'select 1' >/dev/null 2>&1; do
|
||||
echo "waiting for $PGDATABASE on $PGHOST..."; sleep 3
|
||||
done
|
||||
echo "database ready"
|
||||
env:
|
||||
- name: PGHOST
|
||||
value: arrstack-postgres-rw.arrstack.svc.cluster.local
|
||||
- name: PGPORT
|
||||
value: "5432"
|
||||
- name: PGDATABASE
|
||||
value: prowlarr-main
|
||||
- name: PGUSER
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: prowlarr-db
|
||||
key: username
|
||||
- name: PGPASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: prowlarr-db
|
||||
key: password
|
||||
resources:
|
||||
requests:
|
||||
cpu: 10m
|
||||
memory: 32Mi
|
||||
limits:
|
||||
cpu: 100m
|
||||
memory: 64Mi
|
||||
containers:
|
||||
- name: prowlarr
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/prowlarr:v2.6.2-unkin2
|
||||
|
||||
@@ -28,6 +28,44 @@ spec:
|
||||
runAsGroup: 1000
|
||||
fsGroup: 1000
|
||||
fsGroupChangePolicy: OnRootMismatch
|
||||
initContainers:
|
||||
# Gate the app on its own Postgres database+role being reachable, instead
|
||||
# of relying on ArgoCD sync-waves (which deadlock if apps aren't Healthy).
|
||||
# libpq reads PG* from env, so the password never lands in argv.
|
||||
- name: wait-for-db
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/postgres:17-alpine
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
until psql -tAc 'select 1' >/dev/null 2>&1; do
|
||||
echo "waiting for $PGDATABASE on $PGHOST..."; sleep 3
|
||||
done
|
||||
echo "database ready"
|
||||
env:
|
||||
- name: PGHOST
|
||||
value: arrstack-postgres-rw.arrstack.svc.cluster.local
|
||||
- name: PGPORT
|
||||
value: "5432"
|
||||
- name: PGDATABASE
|
||||
value: radarr-main
|
||||
- name: PGUSER
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: radarr-db
|
||||
key: username
|
||||
- name: PGPASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: radarr-db
|
||||
key: password
|
||||
resources:
|
||||
requests:
|
||||
cpu: 10m
|
||||
memory: 32Mi
|
||||
limits:
|
||||
cpu: 100m
|
||||
memory: 64Mi
|
||||
containers:
|
||||
- name: radarr
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/radarr:v6.4.2-unkin2
|
||||
|
||||
@@ -28,6 +28,44 @@ spec:
|
||||
runAsGroup: 1000
|
||||
fsGroup: 1000
|
||||
fsGroupChangePolicy: OnRootMismatch
|
||||
initContainers:
|
||||
# Gate the app on its own Postgres database+role being reachable, instead
|
||||
# of relying on ArgoCD sync-waves (which deadlock if apps aren't Healthy).
|
||||
# libpq reads PG* from env, so the password never lands in argv.
|
||||
- name: wait-for-db
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/postgres:17-alpine
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
until psql -tAc 'select 1' >/dev/null 2>&1; do
|
||||
echo "waiting for $PGDATABASE on $PGHOST..."; sleep 3
|
||||
done
|
||||
echo "database ready"
|
||||
env:
|
||||
- name: PGHOST
|
||||
value: arrstack-postgres-rw.arrstack.svc.cluster.local
|
||||
- name: PGPORT
|
||||
value: "5432"
|
||||
- name: PGDATABASE
|
||||
value: sonarr-main
|
||||
- name: PGUSER
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: sonarr-db
|
||||
key: username
|
||||
- name: PGPASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: sonarr-db
|
||||
key: password
|
||||
resources:
|
||||
requests:
|
||||
cpu: 10m
|
||||
memory: 32Mi
|
||||
limits:
|
||||
cpu: 100m
|
||||
memory: 64Mi
|
||||
containers:
|
||||
- name: sonarr
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/sonarr:v5.0.0-unkin2
|
||||
|
||||
Reference in New Issue
Block a user