Files
Homelabv4/infrastructure/vps-standby/authentik/manifests/cnpg-cluster.yaml
T
Scooby Husky a1d6091122 Fix VPS replica clusters: match home's max_connections (recovery abort)
Postgres refuses to replay WAL past a checkpoint recorded with higher
max_connections/max_wal_senders/etc than the recovering instance's own
settings: 'recovery aborted because of insufficient parameter settings:
max_connections = 100 is a lower setting than on the primary server,
where its value was 200' - confirmed live on all 3 VPS clusters (they
had no postgresql.parameters block at all, defaulting to CNPG's 100).
Copied home's full postgresql.parameters block to remove any other
potential mismatch (max_wal_senders, max_worker_processes are subject
to the same check). Bumped memory requests/limits to match home too -
shared_buffers: 512MB needs headroom the previous 256Mi/1Gi didn't have.
2026-08-17 23:15:02 -05:00

101 lines
3.7 KiB
YAML

---
# CNPG "replica cluster" - continuously replays WAL shipped from home's
# pg-authentik cluster (infrastructure/authentik/manifests/cnpg-cluster.yaml)
# via VPS MinIO's cnpg-backups/pg-authentik bucket path. Unlike Vault's
# raft-restore CronJob (Vault has no native continuous-replication-into-
# object-store feature), CNPG's replica-cluster mode is a first-class
# built-in mechanism - no custom restore scripting needed, matches the
# plan's intent directly.
#
# While spec.replica.enabled is true, this cluster is a read-only standby
# in continuous recovery - the -rw service exists but is NOT writable
# (same "nothing accepts writes in normal operation" discipline as Vault/
# Gitea). Promoting it to a real writable primary during an actual
# incident is a deliberate manual step:
# kubectl -n authentik patch cluster pg-authentik --type merge \
# -p '{"spec":{"replica":{"enabled":false}}}'
# then scale the authentik Deployment(s) up from 0.
#
# vps-minio-secret is a plain Secret copied here manually (kubectl, not
# git) from the vps-minio-root-secret in the minio namespace - this
# cluster has no Vault/ESO of its own:
# kubectl -n authentik create secret generic vps-minio-secret \
# --from-literal=accesskey=<vps minio root user> \
# --from-literal=secretkey=<vps minio root password>
apiVersion: postgresql.cnpg.io/v1
kind: Cluster
metadata:
name: pg-authentik
namespace: authentik
spec:
imageName: ghcr.io/cloudnative-pg/postgresql:16
instances: 1
# shared_buffers: 512MB above needs headroom - matches home's requests/limits.
resources:
requests:
memory: "512Mi"
cpu: "25m"
limits:
memory: "2Gi"
cpu: "250m"
storage:
size: 5Gi
storageClass: local-path
# Must match (or exceed) home's max_connections/max_wal_senders/etc -
# Postgres refuses to replay WAL past a checkpoint recorded with higher
# values than the recovering instance's own settings ("recovery aborted
# because of insufficient parameter settings: max_connections = 100 is
# a lower setting than on the primary server, where its value was 200",
# confirmed live 2026-08-18). Copied from
# infrastructure/authentik/manifests/cnpg-cluster.yaml.
postgresql:
parameters:
max_connections: "200"
shared_buffers: "512MB"
effective_cache_size: "1536MB"
maintenance_work_mem: "128MB"
checkpoint_completion_target: "0.9"
wal_buffers: "16MB"
default_statistics_target: "100"
random_page_cost: "1.1"
effective_io_concurrency: "200"
work_mem: "2621kB"
min_wal_size: "1GB"
max_wal_size: "4GB"
bootstrap:
recovery:
source: home-backup
externalClusters:
- name: home-backup
barmanObjectStore:
# serverName defaults to the externalClusters[].name ("home-backup")
# here, NOT the source Postgres cluster's actual name - but home's
# barmanObjectStore backup: block (on the pg-authentik Cluster
# itself) defaults serverName to its own metadata.name
# ("pg-authentik"). Without this override, recovery looks for
# backups under the wrong server-name prefix and finds none -
# "no target backup found" despite the backup genuinely existing
# (confirmed live 2026-08-18).
serverName: pg-authentik
destinationPath: s3://cnpg-backups/pg-authentik
endpointURL: http://vps-minio.minio.svc.cluster.local:9000
s3Credentials:
accessKeyId:
name: vps-minio-secret
key: accesskey
secretAccessKey:
name: vps-minio-secret
key: secretkey
replica:
enabled: true
source: home-backup
monitoring:
enablePodMonitor: false # no Prometheus on the VPS cluster