mirror of
https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git
synced 2026-08-20 23:16:49 +00:00
Initial commit
This commit is contained in:
@@ -0,0 +1,114 @@
|
||||
# Job to initialize Guacamole database schema
|
||||
# This should run once after the PostgreSQL cluster is ready
|
||||
apiVersion: batch/v1
|
||||
kind: Job
|
||||
metadata:
|
||||
name: guacamole-init-schema
|
||||
namespace: guacamole
|
||||
spec:
|
||||
ttlSecondsAfterFinished: 300
|
||||
template:
|
||||
spec:
|
||||
restartPolicy: OnFailure
|
||||
initContainers:
|
||||
- name: wait-for-postgres
|
||||
image: postgres:16-alpine
|
||||
securityContext:
|
||||
runAsUser: 10000
|
||||
runAsGroup: 10000
|
||||
runAsNonRoot: true
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop: ["ALL"]
|
||||
volumeMounts:
|
||||
- name: tmp
|
||||
mountPath: /tmp
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
echo "Waiting for PostgreSQL to be ready..."
|
||||
until pg_isready -h pg-guacamole-rw -p 5432 -U guacamole; do
|
||||
echo "PostgreSQL not ready, waiting..."
|
||||
sleep 5
|
||||
done
|
||||
echo "PostgreSQL is ready!"
|
||||
env:
|
||||
- name: PGPASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: pg-guacamole-app
|
||||
key: password
|
||||
- name: generate-initdb
|
||||
image: guacamole/guacamole:1.6.0
|
||||
securityContext:
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
runAsNonRoot: true
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop: ["ALL"]
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
set -e
|
||||
/opt/guacamole/bin/initdb.sh --postgresql > /initdb/initdb.sql
|
||||
test -s /initdb/initdb.sql
|
||||
volumeMounts:
|
||||
- name: initdb
|
||||
mountPath: /initdb
|
||||
containers:
|
||||
- name: init-schema
|
||||
image: postgres:16-alpine
|
||||
securityContext:
|
||||
runAsUser: 10000
|
||||
runAsGroup: 10000
|
||||
runAsNonRoot: true
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop: ["ALL"]
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
set -e
|
||||
echo "Checking if schema already exists..."
|
||||
TABLES=$(PGPASSWORD="$PGPASSWORD" psql -h pg-guacamole-rw -U guacamole -d guacamole -tA -c "SELECT COUNT(*) FROM information_schema.tables WHERE table_name = 'guacamole_user';" 2>/dev/null | tr -d '[:space:]' || printf '0')
|
||||
TABLES=${TABLES:-0}
|
||||
|
||||
if [ "$TABLES" -gt "0" ]; then
|
||||
echo "Schema already exists."
|
||||
else
|
||||
echo "Initializing Guacamole database schema..."
|
||||
PGPASSWORD="$PGPASSWORD" psql -v ON_ERROR_STOP=1 -h pg-guacamole-rw -U guacamole -d guacamole -f /initdb/initdb.sql
|
||||
echo "Schema initialization complete!"
|
||||
fi
|
||||
|
||||
echo "Setting up Authentik Admins group permissions..."
|
||||
PGPASSWORD="$PGPASSWORD" psql -v ON_ERROR_STOP=1 -h pg-guacamole-rw -U guacamole -d guacamole -f /schema/permissions.sql
|
||||
echo "Authentik Admins group permissions configured!"
|
||||
env:
|
||||
- name: PGPASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: pg-guacamole-app
|
||||
key: password
|
||||
volumeMounts:
|
||||
- name: initdb
|
||||
mountPath: /initdb
|
||||
- name: schema
|
||||
mountPath: /schema
|
||||
- name: tmp
|
||||
mountPath: /tmp
|
||||
volumes:
|
||||
- name: tmp
|
||||
emptyDir: {}
|
||||
- name: initdb
|
||||
emptyDir: {}
|
||||
- name: schema
|
||||
configMap:
|
||||
name: guacamole-schema
|
||||
Reference in New Issue
Block a user