d9315322fc
1. Renamed every object this demo creates (TerdutServer, Postgres
Secret/Deployment/Service) from terdut-demo[-postgres] to
terdut-operator-demo[-postgres]. The user applied this kit into the
already-live "terdut-demo" namespace -- the real operator exercise
from earlier in this repo's own history -- and this demo's own
TerdutServer/Postgres objects shared that exact name. The TerdutServer
apply was rejected outright (DatabaseSpec's own CEL rule: adding dsn
while the live object already had postgresClusterRef violates "exactly
one of" and the API server refused it), and the real Postgres Service
was never touched (confirmed live: still Zalando's own spilo selector,
endpoint still the real StatefulSet pod) -- but the Postgres Secret and
Deployment, having no such protection, were created as brand new,
extra, crash-looping objects sitting right next to the real ones.
Prefixing every name this demo creates means a repeat of this exact
mistake no longer collides with anything, documented directly in
README.md now.
2. The actual crash itself, independent of (1): capabilities.drop: ["ALL"]
(added responding to a PodSecurity "restricted" warning) took
CAP_CHOWN/CAP_FOWNER away from the root user postgres:17-alpine's own
entrypoint needs to chown/chmod the data directory before it drops
privileges itself -- confirmed in a real crashed pod's logs: `chmod:
/var/run/postgresql: Operation not permitted`. kubectl apply
--dry-run=server, which is as far as this got verified before, only
checks admission policy; it was never actually booted. Removed the
capability drop and verified for real this time: applied just
00-postgres.yaml alone into a disposable namespace, waited for the pod
to go Ready, read its logs ("database system is ready to accept
connections"), then deleted that namespace.
33 lines
1.1 KiB
YAML
33 lines
1.1 KiB
YAML
# The one TerdutServer this whole demo runs against. Everything else in
|
|
# this directory (teams, escalation rules, dead man's switches, alert
|
|
# sources) references it by name.
|
|
#
|
|
# networking.hostname is accepted but not yet acted on: creating the
|
|
# HTTPRoute for it isn't implemented yet (api/v1alpha1/terdutserver_types.go,
|
|
# NetworkingSpec's own doc comment) -- this TerdutServer is reachable from
|
|
# outside the cluster only by port-forwarding its Service, same name as
|
|
# this object (see README.md).
|
|
apiVersion: terdut.ryuvia.com/v1alpha1
|
|
kind: TerdutServer
|
|
metadata:
|
|
name: terdut-operator-demo
|
|
spec:
|
|
image:
|
|
repository: git.ryuvia.com/niklas/terdut-server
|
|
tag: v0.33.2
|
|
replicas: 1
|
|
networking:
|
|
hostname: terdut-operator-demo.example
|
|
servicePort: 8080
|
|
database:
|
|
dsn: "postgres://terdut@terdut-operator-demo-postgres:5432/terdut?sslmode=disable"
|
|
passwordSecretRef:
|
|
name: terdut-operator-demo-postgres
|
|
key: password
|
|
sweeper:
|
|
staleAfter: 6h
|
|
archiveAfter: 168h
|
|
# No oidc block: password login only, so there's nothing external to
|
|
# register a redirect URI with before this demo can sign in.
|
|
passwordLogin: true
|