TerdutServer: trim spec.pod passthroughs, harden the Zalando DSN, make the init image configurable #11

Open
opened 2026-10-09 12:43:03 +00:00 by niklas · 0 comments
Owner

Items on the TerdutServer Deployment builder (internal/controller/terdutserver_*.go) left from the Oct 2026 review:

  • The wait-for-postgres init container hard-codes postgres:17-alpine (the chart makes it configurable). The server's own db.Open now retries the ping, so decide whether the init container is still needed; if it stays, make the image a field.
  • The Deployment sets no security context of its own (the server chart sets runAsNonRoot, runAsUser: 65532, readOnlyRootFilesystem, drop ALL); only spec.pod passthroughs apply. Give it the same safe defaults.
  • PUBLIC_URL is always https://<hostname>; the chart allows notify.publicUrl. Add the override if needed.
  • Zalando path (terdutserver_database.go): role and database are hard-coded to terdut, port 5432 and sslmode=require, rather than derived from the postgresql CR; classifyClusterGetError maps real errors (RBAC) to PostgresClusterNotFound; no Secret watch, so a rotated password waits for the 5-minute resync. Either derive properly (CNPG-style connectionSecretRef) or drop postgresClusterRef and require dsn plus a Secret reference.
  • replicas, servicePort defaults are repeated in the Go builder and the CRD defaults; keep only the CRD ones.
  • Unused spec.pod knobs: prune any nobody sets.
  • Duration strings in spec.sweeper and spec.notify have no pattern validation; the server silently falls back to defaults on a typo (config.duration).
  • The chart's terdutServer block duplicates the CRD spec and is overwritten by kubebuilder edit ... --force (see CLAUDE.md). Hand-maintain the chart or generate the block.
  • Any new server setting must be added in config.go, the server chart, buildEnv and the CRD: add a test that every env var buildEnv sets is read by config.go.
Items on the `TerdutServer` Deployment builder (`internal/controller/terdutserver_*.go`) left from the Oct 2026 review: - The `wait-for-postgres` init container hard-codes `postgres:17-alpine` (the chart makes it configurable). The server's own `db.Open` now retries the ping, so decide whether the init container is still needed; if it stays, make the image a field. - The Deployment sets no security context of its own (the server chart sets `runAsNonRoot`, `runAsUser: 65532`, `readOnlyRootFilesystem`, `drop ALL`); only `spec.pod` passthroughs apply. Give it the same safe defaults. - `PUBLIC_URL` is always `https://<hostname>`; the chart allows `notify.publicUrl`. Add the override if needed. - Zalando path (`terdutserver_database.go`): role and database are hard-coded to `terdut`, port 5432 and `sslmode=require`, rather than derived from the `postgresql` CR; `classifyClusterGetError` maps real errors (RBAC) to `PostgresClusterNotFound`; no Secret watch, so a rotated password waits for the 5-minute resync. Either derive properly (CNPG-style `connectionSecretRef`) or drop `postgresClusterRef` and require `dsn` plus a Secret reference. - `replicas`, `servicePort` defaults are repeated in the Go builder and the CRD defaults; keep only the CRD ones. - Unused `spec.pod` knobs: prune any nobody sets. - Duration strings in `spec.sweeper` and `spec.notify` have no pattern validation; the server silently falls back to defaults on a typo (`config.duration`). - The chart's `terdutServer` block duplicates the CRD spec and is overwritten by `kubebuilder edit ... --force` (see CLAUDE.md). Hand-maintain the chart or generate the block. - Any new server setting must be added in `config.go`, the server chart, `buildEnv` and the CRD: add a test that every env var `buildEnv` sets is read by `config.go`.
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: niklas/terdut-operator#11