arrstack: fix sync-wave deadlock + config multi-attach #385
@@ -11,11 +11,6 @@ kind: Cluster
|
|||||||
metadata:
|
metadata:
|
||||||
name: arrstack-postgres
|
name: arrstack-postgres
|
||||||
namespace: arrstack
|
namespace: arrstack
|
||||||
annotations:
|
|
||||||
# Wave 1: the per-app <app>-db Secrets (wave 0) must exist first — CNPG reads
|
|
||||||
# them as the managed roles' passwordSecret. ArgoCD gates dependents on the
|
|
||||||
# Cluster's health status.
|
|
||||||
argocd.argoproj.io/sync-wave: "1"
|
|
||||||
spec:
|
spec:
|
||||||
inheritedMetadata:
|
inheritedMetadata:
|
||||||
annotations:
|
annotations:
|
||||||
|
|||||||
@@ -7,8 +7,6 @@ kind: Database
|
|||||||
metadata:
|
metadata:
|
||||||
name: prowlarr-main
|
name: prowlarr-main
|
||||||
namespace: arrstack
|
namespace: arrstack
|
||||||
annotations:
|
|
||||||
argocd.argoproj.io/sync-wave: "2"
|
|
||||||
spec:
|
spec:
|
||||||
cluster:
|
cluster:
|
||||||
name: arrstack-postgres
|
name: arrstack-postgres
|
||||||
|
|||||||
@@ -7,8 +7,6 @@ kind: Database
|
|||||||
metadata:
|
metadata:
|
||||||
name: radarr-main
|
name: radarr-main
|
||||||
namespace: arrstack
|
namespace: arrstack
|
||||||
annotations:
|
|
||||||
argocd.argoproj.io/sync-wave: "2"
|
|
||||||
spec:
|
spec:
|
||||||
cluster:
|
cluster:
|
||||||
name: arrstack-postgres
|
name: arrstack-postgres
|
||||||
|
|||||||
@@ -7,8 +7,6 @@ kind: Database
|
|||||||
metadata:
|
metadata:
|
||||||
name: sonarr-main
|
name: sonarr-main
|
||||||
namespace: arrstack
|
namespace: arrstack
|
||||||
annotations:
|
|
||||||
argocd.argoproj.io/sync-wave: "2"
|
|
||||||
spec:
|
spec:
|
||||||
cluster:
|
cluster:
|
||||||
name: arrstack-postgres
|
name: arrstack-postgres
|
||||||
|
|||||||
@@ -13,8 +13,6 @@ kind: VaultStaticSecret
|
|||||||
metadata:
|
metadata:
|
||||||
name: sonarr-db
|
name: sonarr-db
|
||||||
namespace: arrstack
|
namespace: arrstack
|
||||||
annotations:
|
|
||||||
argocd.argoproj.io/sync-wave: "0"
|
|
||||||
spec:
|
spec:
|
||||||
destination:
|
destination:
|
||||||
create: true
|
create: true
|
||||||
@@ -32,8 +30,6 @@ kind: VaultStaticSecret
|
|||||||
metadata:
|
metadata:
|
||||||
name: radarr-db
|
name: radarr-db
|
||||||
namespace: arrstack
|
namespace: arrstack
|
||||||
annotations:
|
|
||||||
argocd.argoproj.io/sync-wave: "0"
|
|
||||||
spec:
|
spec:
|
||||||
destination:
|
destination:
|
||||||
create: true
|
create: true
|
||||||
@@ -51,8 +47,6 @@ kind: VaultStaticSecret
|
|||||||
metadata:
|
metadata:
|
||||||
name: prowlarr-db
|
name: prowlarr-db
|
||||||
namespace: arrstack
|
namespace: arrstack
|
||||||
annotations:
|
|
||||||
argocd.argoproj.io/sync-wave: "0"
|
|
||||||
spec:
|
spec:
|
||||||
destination:
|
destination:
|
||||||
create: true
|
create: true
|
||||||
|
|||||||
@@ -28,6 +28,44 @@ spec:
|
|||||||
runAsGroup: 1000
|
runAsGroup: 1000
|
||||||
fsGroup: 1000
|
fsGroup: 1000
|
||||||
fsGroupChangePolicy: OnRootMismatch
|
fsGroupChangePolicy: OnRootMismatch
|
||||||
|
initContainers:
|
||||||
|
# Gate the app on its own Postgres database+role being reachable, instead
|
||||||
|
# of relying on ArgoCD sync-waves (which deadlock if apps aren't Healthy).
|
||||||
|
# libpq reads PG* from env, so the password never lands in argv.
|
||||||
|
- name: wait-for-db
|
||||||
|
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/postgres:17-alpine
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
until psql -tAc 'select 1' >/dev/null 2>&1; do
|
||||||
|
echo "waiting for $PGDATABASE on $PGHOST..."; sleep 3
|
||||||
|
done
|
||||||
|
echo "database ready"
|
||||||
|
env:
|
||||||
|
- name: PGHOST
|
||||||
|
value: arrstack-postgres-rw.arrstack.svc.cluster.local
|
||||||
|
- name: PGPORT
|
||||||
|
value: "5432"
|
||||||
|
- name: PGDATABASE
|
||||||
|
value: prowlarr-main
|
||||||
|
- name: PGUSER
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: prowlarr-db
|
||||||
|
key: username
|
||||||
|
- name: PGPASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: prowlarr-db
|
||||||
|
key: password
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 10m
|
||||||
|
memory: 32Mi
|
||||||
|
limits:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 64Mi
|
||||||
containers:
|
containers:
|
||||||
- name: prowlarr
|
- name: prowlarr
|
||||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/prowlarr:v2.6.2-unkin2
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/prowlarr:v2.6.2-unkin2
|
||||||
@@ -92,5 +130,4 @@ spec:
|
|||||||
mountPath: /config
|
mountPath: /config
|
||||||
volumes:
|
volumes:
|
||||||
- name: config
|
- name: config
|
||||||
persistentVolumeClaim:
|
emptyDir: {}
|
||||||
claimName: prowlarr-config
|
|
||||||
|
|||||||
@@ -3,7 +3,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
|||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
|
|
||||||
resources:
|
resources:
|
||||||
- pvc-config.yaml
|
|
||||||
- vaultstaticsecret.yaml
|
- vaultstaticsecret.yaml
|
||||||
- configmap.yaml
|
- configmap.yaml
|
||||||
- deployment.yaml
|
- deployment.yaml
|
||||||
|
|||||||
@@ -28,6 +28,44 @@ spec:
|
|||||||
runAsGroup: 1000
|
runAsGroup: 1000
|
||||||
fsGroup: 1000
|
fsGroup: 1000
|
||||||
fsGroupChangePolicy: OnRootMismatch
|
fsGroupChangePolicy: OnRootMismatch
|
||||||
|
initContainers:
|
||||||
|
# Gate the app on its own Postgres database+role being reachable, instead
|
||||||
|
# of relying on ArgoCD sync-waves (which deadlock if apps aren't Healthy).
|
||||||
|
# libpq reads PG* from env, so the password never lands in argv.
|
||||||
|
- name: wait-for-db
|
||||||
|
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/postgres:17-alpine
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
until psql -tAc 'select 1' >/dev/null 2>&1; do
|
||||||
|
echo "waiting for $PGDATABASE on $PGHOST..."; sleep 3
|
||||||
|
done
|
||||||
|
echo "database ready"
|
||||||
|
env:
|
||||||
|
- name: PGHOST
|
||||||
|
value: arrstack-postgres-rw.arrstack.svc.cluster.local
|
||||||
|
- name: PGPORT
|
||||||
|
value: "5432"
|
||||||
|
- name: PGDATABASE
|
||||||
|
value: radarr-main
|
||||||
|
- name: PGUSER
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: radarr-db
|
||||||
|
key: username
|
||||||
|
- name: PGPASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: radarr-db
|
||||||
|
key: password
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 10m
|
||||||
|
memory: 32Mi
|
||||||
|
limits:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 64Mi
|
||||||
containers:
|
containers:
|
||||||
- name: radarr
|
- name: radarr
|
||||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/radarr:v6.4.2-unkin2
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/radarr:v6.4.2-unkin2
|
||||||
@@ -94,8 +132,7 @@ spec:
|
|||||||
mountPath: /media/movies
|
mountPath: /media/movies
|
||||||
volumes:
|
volumes:
|
||||||
- name: config
|
- name: config
|
||||||
persistentVolumeClaim:
|
emptyDir: {}
|
||||||
claimName: radarr-config
|
|
||||||
- name: media-movies
|
- name: media-movies
|
||||||
persistentVolumeClaim:
|
persistentVolumeClaim:
|
||||||
claimName: media-movies
|
claimName: media-movies
|
||||||
|
|||||||
@@ -3,7 +3,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
|||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
|
|
||||||
resources:
|
resources:
|
||||||
- pvc-config.yaml
|
|
||||||
- vaultstaticsecret.yaml
|
- vaultstaticsecret.yaml
|
||||||
- configmap.yaml
|
- configmap.yaml
|
||||||
- deployment.yaml
|
- deployment.yaml
|
||||||
|
|||||||
@@ -28,6 +28,44 @@ spec:
|
|||||||
runAsGroup: 1000
|
runAsGroup: 1000
|
||||||
fsGroup: 1000
|
fsGroup: 1000
|
||||||
fsGroupChangePolicy: OnRootMismatch
|
fsGroupChangePolicy: OnRootMismatch
|
||||||
|
initContainers:
|
||||||
|
# Gate the app on its own Postgres database+role being reachable, instead
|
||||||
|
# of relying on ArgoCD sync-waves (which deadlock if apps aren't Healthy).
|
||||||
|
# libpq reads PG* from env, so the password never lands in argv.
|
||||||
|
- name: wait-for-db
|
||||||
|
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/postgres:17-alpine
|
||||||
|
command:
|
||||||
|
- sh
|
||||||
|
- -c
|
||||||
|
- |
|
||||||
|
until psql -tAc 'select 1' >/dev/null 2>&1; do
|
||||||
|
echo "waiting for $PGDATABASE on $PGHOST..."; sleep 3
|
||||||
|
done
|
||||||
|
echo "database ready"
|
||||||
|
env:
|
||||||
|
- name: PGHOST
|
||||||
|
value: arrstack-postgres-rw.arrstack.svc.cluster.local
|
||||||
|
- name: PGPORT
|
||||||
|
value: "5432"
|
||||||
|
- name: PGDATABASE
|
||||||
|
value: sonarr-main
|
||||||
|
- name: PGUSER
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: sonarr-db
|
||||||
|
key: username
|
||||||
|
- name: PGPASSWORD
|
||||||
|
valueFrom:
|
||||||
|
secretKeyRef:
|
||||||
|
name: sonarr-db
|
||||||
|
key: password
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu: 10m
|
||||||
|
memory: 32Mi
|
||||||
|
limits:
|
||||||
|
cpu: 100m
|
||||||
|
memory: 64Mi
|
||||||
containers:
|
containers:
|
||||||
- name: sonarr
|
- name: sonarr
|
||||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/sonarr:v5.0.0-unkin2
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/sonarr:v5.0.0-unkin2
|
||||||
@@ -94,8 +132,7 @@ spec:
|
|||||||
mountPath: /media/tv
|
mountPath: /media/tv
|
||||||
volumes:
|
volumes:
|
||||||
- name: config
|
- name: config
|
||||||
persistentVolumeClaim:
|
emptyDir: {}
|
||||||
claimName: sonarr-config
|
|
||||||
- name: media-tv
|
- name: media-tv
|
||||||
persistentVolumeClaim:
|
persistentVolumeClaim:
|
||||||
claimName: media-tv
|
claimName: media-tv
|
||||||
|
|||||||
@@ -3,7 +3,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
|||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
|
|
||||||
resources:
|
resources:
|
||||||
- pvc-config.yaml
|
|
||||||
- vaultstaticsecret.yaml
|
- vaultstaticsecret.yaml
|
||||||
- configmap.yaml
|
- configmap.yaml
|
||||||
- deployment.yaml
|
- deployment.yaml
|
||||||
|
|||||||
Reference in New Issue
Block a user