# Demo-only Postgres: a bare Deployment+Service+Secret, not the Zalando # postgres-operator path (DatabaseSpec.postgresClusterRef, DESIGN.md ยง8). # Bring-your-own DSN is the simpler of the two paths to stand up from # nothing (ROADMAP.md Stage 1's own note), which is all this needs to be. # # emptyDir, one replica, a password sitting in a plaintext Secret below -- # none of that is how you'd run Postgres for real. It exists only so # 01-server.yaml has something to talk to. Throw the whole demo namespace # away when you're done; nothing here is meant to survive that. apiVersion: v1 kind: Secret metadata: name: terdut-demo-postgres type: Opaque stringData: password: demo-not-a-real-password --- apiVersion: apps/v1 kind: Deployment metadata: name: terdut-demo-postgres labels: app: terdut-demo-postgres spec: replicas: 1 # Recreate, not RollingUpdate: emptyDir means a new pod starts with an # empty database anyway, and two Postgres pods would never agree on one # emptyDir each. strategy: type: Recreate selector: matchLabels: app: terdut-demo-postgres template: metadata: labels: app: terdut-demo-postgres spec: containers: - name: postgres image: postgres:17-alpine # Partial, deliberately: the official image's entrypoint needs to # start as root to chown the data directory before it drops # privileges itself (gosu, to the postgres user) -- forcing # runAsNonRoot here would just refuse to start the container. A # "restricted" PodSecurity namespace warns on that gap rather # than blocking (confirmed server-side against this operator's # own dev cluster), which is an acceptable tradeoff for Postgres # that exists only to be thrown away with the rest of this demo. securityContext: allowPrivilegeEscalation: false capabilities: drop: ["ALL"] seccompProfile: type: RuntimeDefault ports: - name: postgres containerPort: 5432 env: - name: POSTGRES_USER value: terdut - name: POSTGRES_DB value: terdut - name: POSTGRES_PASSWORD valueFrom: secretKeyRef: name: terdut-demo-postgres key: password volumeMounts: - name: data mountPath: /var/lib/postgresql/data subPath: pgdata readinessProbe: exec: command: ["pg_isready", "-U", "terdut"] initialDelaySeconds: 5 volumes: - name: data emptyDir: {} --- apiVersion: v1 kind: Service metadata: name: terdut-demo-postgres spec: selector: app: terdut-demo-postgres ports: - name: postgres port: 5432 targetPort: postgres