From 162eff41d5901c2abc85eb9b8b769b0ecfcc1e57 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sat, 19 Sep 2026 13:58:27 +1000 Subject: [PATCH] Enable pg_stat_statements on the authentik postgres cluster The cluster preloads no statement-statistics library, so there is no per-query cost attribution and slow paths have to be inferred from application-side metrics. - preload pg_stat_statements - set pg_stat_statements.max and .track so CNPG manages the extension and creates it in every database Requires a postgres restart. --- apps/base/authentik/cnpg_cluster.yaml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/apps/base/authentik/cnpg_cluster.yaml b/apps/base/authentik/cnpg_cluster.yaml index 5dd813d..67ea13b 100644 --- a/apps/base/authentik/cnpg_cluster.yaml +++ b/apps/base/authentik/cnpg_cluster.yaml @@ -81,6 +81,11 @@ spec: max_parallel_workers: "16" max_replication_slots: "16" max_worker_processes: "16" + # A pg_stat_statements.* parameter is what makes CNPG treat the extension as + # managed and run CREATE EXTENSION in every database; preloading alone does + # not create it. + pg_stat_statements.max: "10000" + pg_stat_statements.track: top shared_buffers: 512MB shared_memory_type: mmap ssl_max_protocol_version: TLSv1.3 @@ -90,6 +95,9 @@ spec: wal_log_hints: "on" wal_receiver_timeout: 5s wal_sender_timeout: 5s + # CNPG merges this with the libraries it manages itself. + shared_preload_libraries: + - pg_stat_statements syncReplicaElectionConstraint: enabled: false primaryUpdateMethod: restart -- 2.47.3