--- # Main Jellyfin database. The cheeztv-ha fork's experimental EF Core provider # moves the entire Jellyfin DB (incl. library items) off SQLite into PostgreSQL, # which is what makes a shared-nothing multi-replica deployment possible. No # bootstrap secret is given, so CNPG generates the cheeztv-postgres-app secret # (username/password/dbname) that the StatefulSet composes its DSN from. apiVersion: postgresql.cnpg.io/v1 kind: Cluster metadata: name: cheeztv-postgres namespace: cheeztv spec: # Exclude the operator-managed data PVCs (cheeztv-postgres-N) from the # cheeztv-config k8up Schedule (skipWithoutAnnotation is false cluster-wide, # so unannotated PVCs are swept in). Postgres has its own barmanObjectStore # backup below; restic must not touch the raw RWO data volumes. inheritedMetadata: annotations: k8up.io/backup: "false" affinity: podAntiAffinityType: preferred backup: retentionPolicy: 30d barmanObjectStore: # Dedicated per-cluster Ceph RGW bucket (cephrgw-operator provisions it). destinationPath: s3://cnpg-cheeztv endpointURL: https://s3.ceph.unkin.net endpointCA: name: vault-ca-cert key: ca.crt s3Credentials: accessKeyId: name: cnpg-cheeztv-backup-s3 key: AWS_ACCESS_KEY_ID secretAccessKey: name: cnpg-cheeztv-backup-s3 key: AWS_SECRET_ACCESS_KEY serverName: cheeztv data: compression: bzip2 jobs: 2 wal: compression: zstd maxParallel: 2 bootstrap: initdb: database: cheeztv encoding: UTF8 localeCType: C localeCollate: C owner: cheeztv enablePDB: true enableSuperuserAccess: false failoverDelay: 0 # PG 17 — accepted by the fork's Npgsql/EF Core provider (needs PG14+); the # provider generates its own migrations on first start. imageName: ghcr.io/cloudnative-pg/postgresql:17-system-trixie instances: 3 logLevel: info maxSyncReplicas: 0 minSyncReplicas: 0 monitoring: customQueriesConfigMap: - key: queries name: cnpg-default-monitoring disableDefaultQueries: false enablePodMonitor: false postgresql: parameters: archive_mode: "on" archive_timeout: 5min dynamic_shared_memory_type: posix effective_cache_size: 256MB full_page_writes: "on" log_destination: csvlog log_directory: /controller/log log_filename: postgres log_rotation_age: "0" log_rotation_size: "0" log_truncate_on_rotation: "false" logging_collector: "on" max_connections: "200" max_parallel_workers: "16" max_replication_slots: "16" max_worker_processes: "16" shared_buffers: 128MB shared_memory_type: mmap ssl_max_protocol_version: TLSv1.3 ssl_min_protocol_version: TLSv1.3 wal_keep_size: 256MB wal_level: logical wal_log_hints: "on" wal_receiver_timeout: 5s wal_sender_timeout: 5s syncReplicaElectionConstraint: enabled: false primaryUpdateMethod: restart primaryUpdateStrategy: unsupervised probes: liveness: isolationCheck: connectionTimeout: 1000 enabled: true requestTimeout: 1000 replicationSlots: highAvailability: enabled: true slotPrefix: _cnpg_ synchronizeReplicas: enabled: true updateInterval: 30 resources: limits: cpu: "1" memory: 1Gi requests: cpu: 50m memory: 512Mi smartShutdownTimeout: 180 startDelay: 3600 stopDelay: 1800 storage: resizeInUseVolumes: true size: 10Gi storageClass: cephrbd-fast-delete switchoverDelay: 3600