Add valkey/redis driver with operator-secret auto-configuration
ci/woodpecker/push/test Pipeline was successful
ci/woodpecker/push/build Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/push/pre-commit Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

Apps fronted by valkey-operator instances need the same wait-for-ready
initContainer postgres workloads already get, and wiring per-field
secretKeyRefs for operator-generated secrets is boilerplate. waitfordb
now speaks enough RESP to AUTH and PING, and natively understands the
secret shapes CNPG and valkey-operator generate so an initContainer is
just envFrom plus a mode variable.

- valkey driver (alias: redis): fresh TCP connection per attempt,
  optional AUTH (ACL user or default), PING, reusing the existing
  retry/backoff wait loop; redis:///valkey:// DSNs; default port 6379
- WAITFORDB_SECRET_FORMAT=cnpg|valkey for envFrom-injected operator
  secrets: CNPG <cluster>-app host/port/dbname/user/password keys, and
  valkey-operator key-per-username secrets (_operator preferred, or
  WAITFORDB_USER's same-named key)
- autodetection from injected keys (CNPG keys -> postgres, valkey keys
  -> valkey); explicit WAITFORDB_DRIVER/WAITFORDB_* always win, PG*
  fallback and all existing flags unchanged
- valkey needs no user/database to be valid (unauthenticated PING)
- tests: secret shape parsing/autodetect/mismatch, fake RESP server
  covering NOAUTH/WRONGPASS/ACL auth/DSN, retry-until-up wait
- README: envFrom initContainer snippets for CNPG and valkey-operator
This commit is contained in:
unkin-agent
2026-08-23 16:36:52 +10:00
parent 8654dab582
commit a466b3e07f
7 changed files with 720 additions and 46 deletions
+10 -6
View File
@@ -1,6 +1,7 @@
// waitfordb blocks until a target database answers SELECT 1 under the given
// credentials, then exits 0. It is designed to run as a Kubernetes
// initContainer, configured entirely by environment variables.
// waitfordb blocks until a target database answers a liveness query (SELECT 1,
// or PING for valkey/redis) under the given credentials, then exits 0. It is
// designed to run as a Kubernetes initContainer, configured entirely by
// environment variables.
//
// Exit codes: 0 ready, 1 timeout, 2 configuration error.
package main
@@ -145,7 +146,7 @@ func plural(n int) string {
}
func usage() {
fmt.Fprint(os.Stderr, `waitfordb — block until a database is ready (SELECT 1 succeeds).
fmt.Fprint(os.Stderr, `waitfordb — block until a database is ready (SELECT 1 / PING succeeds).
Usage:
waitfordb wait using the WAITFORDB_*/PG* environment variables
@@ -153,7 +154,7 @@ Usage:
waitfordb help print this help
Environment:
WAITFORDB_DRIVER postgres (default) or mysql
WAITFORDB_DRIVER postgres (default), mysql, or valkey (alias: redis)
WAITFORDB_HOST database host (PGHOST fallback)
WAITFORDB_PORT database port (PGPORT fallback)
WAITFORDB_USER username (PGUSER fallback)
@@ -161,11 +162,14 @@ Environment:
WAITFORDB_DATABASE database name (PGDATABASE fallback)
WAITFORDB_SSLMODE postgres sslmode (PGSSLMODE fallback)
WAITFORDB_DSN full connection string (overrides the fields above)
WAITFORDB_SECRET_FORMAT operator secret shape injected via envFrom:
cnpg (CNPG <cluster>-app) or valkey (valkey-operator);
autodetected when unset
WAITFORDB_TIMEOUT total wait budget, Go duration; 0 = forever (default 0)
WAITFORDB_INTERVAL gap between retries (default 2s)
WAITFORDB_CONNECT_TIMEOUT per-attempt connect timeout (default 5s)
Precedence for connection parameters: WAITFORDB_DSN > WAITFORDB_* > PG*.
Precedence: WAITFORDB_DSN > WAITFORDB_* > PG* > operator-secret keys.
Exit codes: 0 ready, 1 timeout/interrupted, 2 configuration error.
`)
}