d9315322fc
1. Renamed every object this demo creates (TerdutServer, Postgres
Secret/Deployment/Service) from terdut-demo[-postgres] to
terdut-operator-demo[-postgres]. The user applied this kit into the
already-live "terdut-demo" namespace -- the real operator exercise
from earlier in this repo's own history -- and this demo's own
TerdutServer/Postgres objects shared that exact name. The TerdutServer
apply was rejected outright (DatabaseSpec's own CEL rule: adding dsn
while the live object already had postgresClusterRef violates "exactly
one of" and the API server refused it), and the real Postgres Service
was never touched (confirmed live: still Zalando's own spilo selector,
endpoint still the real StatefulSet pod) -- but the Postgres Secret and
Deployment, having no such protection, were created as brand new,
extra, crash-looping objects sitting right next to the real ones.
Prefixing every name this demo creates means a repeat of this exact
mistake no longer collides with anything, documented directly in
README.md now.
2. The actual crash itself, independent of (1): capabilities.drop: ["ALL"]
(added responding to a PodSecurity "restricted" warning) took
CAP_CHOWN/CAP_FOWNER away from the root user postgres:17-alpine's own
entrypoint needs to chown/chmod the data directory before it drops
privileges itself -- confirmed in a real crashed pod's logs: `chmod:
/var/run/postgresql: Operation not permitted`. kubectl apply
--dry-run=server, which is as far as this got verified before, only
checks admission policy; it was never actually booted. Removed the
capability drop and verified for real this time: applied just
00-postgres.yaml alone into a disposable namespace, waited for the pod
to go Ready, read its logs ("database system is ready to accept
connections"), then deleted that namespace.
18 lines
727 B
YAML
18 lines
727 B
YAML
# Two teams (this one and 03-team-payments.yaml) so the demo shows
|
|
# per-team isolation -- separate incident lists, separate escalation
|
|
# ladders, separate alert sources -- rather than one team standing in for
|
|
# everything.
|
|
apiVersion: terdut.ryuvia.com/v1alpha1
|
|
kind: TerdutTeam
|
|
metadata:
|
|
name: terdutteam-platform
|
|
spec:
|
|
# serverRef.namespace omitted: both this and terdut-operator-demo (01-server.yaml)
|
|
# live in whatever namespace you apply this directory into, which is the
|
|
# common case and needs no allowedTeams consent on the TerdutServer side
|
|
# (DESIGN.md §4.1, §4.6).
|
|
serverRef:
|
|
name: terdut-operator-demo
|
|
displayName: Platform
|
|
# No oidc block: this demo is password-login only (01-server.yaml).
|