a9d788cc83
A Deployment created before Postgres has finished its very first boot -- initdb plus Patroni leader election, on a from-scratch postgres-operator cluster -- crash-looped a few times. db.Open()'s own ping-retry budget (pingAttempts/pingRetryDelay, internal/db/db.go) is sized for a much shorter, different race -- NetworkPolicy propagation, a few seconds -- not for genuine first-time cluster creation, which routinely takes longer, so it exhausted and the process exited before ever binding its HTTP port. A startupProbe cannot fix that: the crash happens before there is anything to probe. Added a wait-for-postgres init container instead: it loops pg_isready against database.dsn until Postgres actually answers, before the main container's own, unchanged retry budget gets a chance to run out. pg_isready needs no credentials -- it reports PQPING_OK on anything that amounts to a Postgres backend answering, including an auth challenge -- so no PGPASSWORD is wired into it. Chart-only; no Go code changed. database.waitForPostgres.enabled defaults to true and can be turned off if something else already guarantees Postgres is reachable before this Deployment is created.