9a7200636c
The 500m CPU limit is a 50ms CFS quota per 100ms period, so the postgres pods are throttled on every burst even at ~0.01 cores average and each query pays that latency. 128MB of `shared_buffers` and a 256MB cache estimate also under-serve the planner on the joins authentik issues on its hot read paths. - raise resources to requests `500m`/`1Gi`, limits `2`/`2Gi` - raise `shared_buffers` to 512MB and `effective_cache_size` to 1536MB - hold the post-incident memory headroom multiple over `shared_buffers` Rolling restart with switchover. Stacked on `benvin/authentik-hot-standby-feedback`. Reviewed-on: #474 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>