# n8n warm standby on the VPS - Phase 2. Same discipline as # infrastructure/vps-standby/authentik/values.yaml: the CNPG replica # cluster keeps the DB continuously warm in the background, and the app # runs continuously too (replicaCount: 1, reachable at # n8n.vps.huskypup.net - see manifests/ingress.yaml) - workflow # saves/executions will error against the read-only DB until a # deliberate manual promotion (flip pg-n8n's spec.replica.enabled to # false), but the UI and existing workflow definitions are browsable. # # N8N_ENCRYPTION_KEY must be byte-identical to home's - it decrypts # stored credentials (API keys, OAuth tokens, etc.) that live encrypted # in the DB being replicated. Unlike Authentik's chart-deterministic # secret_key, n8n's isn't derived from anything reproducible - it's # copied for real (kubectl, not git, same as Vault's unseal key / # root token): # kubectl -n n8n create secret generic n8n-config-secret \ # --from-literal=encryption-key= image: repository: n8nio/n8n tag: "2.0.3" config: database: type: postgresdb postgresdb: host: pg-n8n-rw port: 5432 database: n8n user: n8n schema: public generic: timezone: America/New_York path: / host: n8n.vps.huskypup.net port: 5678 protocol: https executions: mode: regular saveDataOnError: all saveDataOnSuccess: all saveDataManualExecutions: true pruneData: true pruneDataMaxAge: 3760 secret: {} replicaCount: 1 service: type: ClusterIP port: 80 securityContext: allowPrivilegeEscalation: false capabilities: drop: - ALL seccompProfile: type: RuntimeDefault ingress: enabled: false persistence: enabled: true type: existing existingClaim: n8n-main-persistence storageClass: local-path accessModes: - ReadWriteOnce size: 10Gi resources: requests: cpu: 50m memory: 256Mi limits: cpu: "500m" memory: 512Mi # Chart defaults are more aggressive than n8n needs to actually finish # starting - without this the liveness probe kills the container before # it ever binds :5678 (confirmed live: exitCode 143/SIGTERM, crashloop). # Matches home's apps/n8n/values.yaml timings. startupProbe: httpGet: path: /healthz port: http initialDelaySeconds: 10 periodSeconds: 5 timeoutSeconds: 3 failureThreshold: 12 readinessProbe: httpGet: path: /healthz port: http initialDelaySeconds: 5 periodSeconds: 5 timeoutSeconds: 3 failureThreshold: 2 livenessProbe: httpGet: path: /healthz port: http initialDelaySeconds: 10 periodSeconds: 10 timeoutSeconds: 5 failureThreshold: 3 extraEnvSecrets: DB_POSTGRESDB_PASSWORD: name: pg-n8n-app key: password N8N_ENCRYPTION_KEY: name: n8n-config-secret key: encryption-key extraEnv: WEBHOOK_URL: https://n8n.vps.huskypup.net/ N8N_EDITOR_BASE_URL: https://n8n.vps.huskypup.net N8N_LOG_LEVEL: error postgresql: enabled: false redis: enabled: false scaling: enabled: false extraVolumes: [] extraVolumeMounts: [] nodeSelector: {} tolerations: [] affinity: {}