--- apiVersion: postgresql.cnpg.io/v1 kind: Cluster metadata: name: puppet-postgres namespace: puppet spec: affinity: podAntiAffinityType: preferred backup: # 30-day retention (DEFAULT — adjust per cluster if needed). Enforced by CNPG # against the object store on each successful base backup. retentionPolicy: 30d barmanObjectStore: # Dedicated per-cluster Ceph RGW bucket (cephrgw-operator provisions it). destinationPath: s3://cnpg-puppet endpointURL: https://s3.ceph.unkin.net # radosgw serves a Vault-PKI cert; trust the internal CA (reflected into # every namespace as the vault-ca-cert Secret). endpointCA: name: vault-ca-cert key: ca.crt # Keys minted by the ObjectStoreUser in cnpg_backup.yaml; never hardcoded. s3Credentials: accessKeyId: name: cnpg-puppet-backup-s3 key: AWS_ACCESS_KEY_ID secretAccessKey: name: cnpg-puppet-backup-s3 key: AWS_SECRET_ACCESS_KEY # Path prefix within the bucket; keep stable across restores (see docs). serverName: puppet data: compression: bzip2 jobs: 2 wal: compression: zstd maxParallel: 2 bootstrap: initdb: database: puppetdb encoding: UTF8 localeCType: C localeCollate: C owner: puppetdb secret: name: postgres-credentials postInitApplicationSQL: - CREATE EXTENSION IF NOT EXISTS pg_trgm; - CREATE EXTENSION IF NOT EXISTS pgcrypto; - GRANT CONNECT ON DATABASE puppetdb TO puppetdb_read; - GRANT USAGE ON SCHEMA public TO puppetdb_read; - GRANT SELECT ON ALL TABLES IN SCHEMA public TO puppetdb_read; - ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT SELECT ON TABLES TO puppetdb_read; managed: roles: - name: puppetdb_read ensure: present comment: PuppetDB read-only database user login: true superuser: false createdb: false createrole: false inherit: true replication: false connectionLimit: -1 passwordSecret: name: postgres-read-credentials enablePDB: true enableSuperuserAccess: false failoverDelay: 0 imageName: ghcr.io/cloudnative-pg/postgresql:17-minimal-trixie instances: 3 logLevel: info maxSyncReplicas: 0 minSyncReplicas: 0 monitoring: customQueriesConfigMap: - key: queries name: cnpg-default-monitoring disableDefaultQueries: false enablePodMonitor: false postgresql: parameters: archive_mode: "on" archive_timeout: 5min dynamic_shared_memory_type: posix effective_cache_size: 256MB full_page_writes: "on" log_destination: csvlog log_directory: /controller/log log_filename: postgres log_rotation_age: "0" log_rotation_size: "0" log_truncate_on_rotation: "false" logging_collector: "on" max_connections: "200" max_parallel_workers: "16" max_replication_slots: "16" max_worker_processes: "16" shared_buffers: 128MB shared_memory_type: mmap ssl_max_protocol_version: TLSv1.3 ssl_min_protocol_version: TLSv1.3 wal_keep_size: 256MB wal_level: logical wal_log_hints: "on" wal_receiver_timeout: 5s wal_sender_timeout: 5s syncReplicaElectionConstraint: enabled: false primaryUpdateMethod: restart primaryUpdateStrategy: unsupervised probes: liveness: isolationCheck: connectionTimeout: 1000 enabled: true requestTimeout: 1000 replicationSlots: highAvailability: enabled: true slotPrefix: _cnpg_ synchronizeReplicas: enabled: true updateInterval: 30 resources: limits: cpu: 500m memory: 512Mi requests: cpu: 50m memory: 256Mi smartShutdownTimeout: 180 startDelay: 3600 stopDelay: 1800 storage: resizeInUseVolumes: true size: 10Gi storageClass: cephrbd-fast-delete switchoverDelay: 3600