# Demo-only Postgres: a bare Deployment+Service+Secret, not the Zalando # postgres-operator path (DatabaseSpec.postgresClusterRef, DESIGN.md ยง8). # Bring-your-own DSN is the simpler of the two paths to stand up from # nothing (ROADMAP.md Stage 1's own note), which is all this needs to be. # # emptyDir, one replica, a password sitting in a plaintext Secret below -- # none of that is how you'd run Postgres for real. It exists only so # 01-server.yaml has something to talk to. Throw the whole demo namespace # away when you're done; nothing here is meant to survive that. apiVersion: v1 kind: Secret metadata: name: terdut-operator-demo-postgres type: Opaque stringData: password: demo-not-a-real-password --- apiVersion: apps/v1 kind: Deployment metadata: name: terdut-operator-demo-postgres labels: app: terdut-operator-demo-postgres spec: replicas: 1 # Recreate, not RollingUpdate: emptyDir means a new pod starts with an # empty database anyway, and two Postgres pods would never agree on one # emptyDir each. strategy: type: Recreate selector: matchLabels: app: terdut-operator-demo-postgres template: metadata: labels: app: terdut-operator-demo-postgres spec: containers: - name: postgres image: postgres:17-alpine # Partial, deliberately: the official image's entrypoint needs to # start as root to chown/chmod the data directory before it drops # privileges itself (gosu, to the postgres user) -- forcing # runAsNonRoot would just refuse to start the container, and # dropping all capabilities (an earlier version of this file did) # takes CAP_CHOWN/CAP_FOWNER away from that same root user, which # is a different way of breaking the identical startup step: # confirmed the hard way, as `chmod: /var/run/postgresql: # Operation not permitted` in a real pod's logs, not caught by # `kubectl apply --dry-run=server` -- that only checks admission # policy, never whether the container actually boots. A # "restricted" PodSecurity namespace warns on the remaining gap # (no runAsNonRoot) rather than blocking, which is an acceptable # tradeoff for Postgres that exists only to be thrown away with # the rest of this demo. securityContext: allowPrivilegeEscalation: false seccompProfile: type: RuntimeDefault ports: - name: postgres containerPort: 5432 env: - name: POSTGRES_USER value: terdut - name: POSTGRES_DB value: terdut - name: POSTGRES_PASSWORD valueFrom: secretKeyRef: name: terdut-operator-demo-postgres key: password volumeMounts: - name: data mountPath: /var/lib/postgresql/data subPath: pgdata readinessProbe: exec: command: ["pg_isready", "-U", "terdut"] initialDelaySeconds: 5 volumes: - name: data emptyDir: {} --- apiVersion: v1 kind: Service metadata: name: terdut-operator-demo-postgres spec: selector: app: terdut-operator-demo-postgres ports: - name: postgres port: 5432 targetPort: postgres