hardened-containers 레포의 published.json(게이트 PASS + push 확인된 발행 기록)을 반영한다. 상세는 이 실행의 Job Summary 참고. Co-Authored-By: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
cloudnative-pg
CloudNativePG Operator Helm Chart
Homepage: https://cloudnative-pg.io
About this chart
Helm chart to install the CloudNativePG operator, originally created and sponsored by EDB to manage PostgreSQL workloads on any supported Kubernetes cluster running in private, public, or hybrid cloud environments.
NOTE: this chart supports only the latest point release of the CloudNativePG operator.
The chart installs only the operator (controller manager, webhooks, RBAC and CRDs). To provision a PostgreSQL
Cluster resource, use the companion cluster chart
(see the Cluster chart README for details)
or apply your own Cluster manifest.
Getting Started
Add the chart repository
helm repo add cnpg https://cloudnative-pg.github.io/charts
helm repo update
Install the operator
helm upgrade --install cnpg \
--namespace cnpg-system \
--create-namespace \
cnpg/cloudnative-pg
Install with custom parameters
You can override individual chart values from the command line with --set.
For example, to enable the Prometheus PodMonitor:
helm upgrade --install cnpg \
--namespace cnpg-system \
--create-namespace \
--set monitoring.podMonitorEnabled=true \
cnpg/cloudnative-pg
Note
Enabling the
PodMonitorrequires the Prometheus Operator CRDs to be installed in the cluster. Without them the install fails withno matches for kind "PodMonitor".
See the Values section below for the full list of configurable parameters.
Verify the installation
kubectl -n cnpg-system get deploy
kubectl -n cnpg-system rollout status deploy/cnpg-cloudnative-pg
Single namespace installation
It is possible to limit the operator's capabilities to solely the namespace in which it has been installed. With this restriction, the cluster-level permissions required by the operator will be substantially reduced, and the security profile of the installation will be enhanced.
You can install the operator in single-namespace mode by setting the config.clusterWide flag to false,
as in the following example:
helm upgrade --install cnpg \
--namespace cnpg-system \
--create-namespace \
--set config.clusterWide=false \
cnpg/cloudnative-pg
IMPORTANT: the single-namespace installation mode can't coexist with the cluster-wide operator. Otherwise there would be collisions when managing the resources in the namespace watched by the single-namespace operator. It is up to the user to ensure there is no collision between operators.
Uninstalling
helm uninstall cnpg --namespace cnpg-system
Warning
Uninstalling the chart does not remove the CRDs. Deleting them cascade-deletes every
Cluster(and other CloudNativePG) resource across the whole cluster, together with the PostgreSQL data stored in their PVCs. This is irreversible, so only delete the CRDs if you intend to permanently remove all managed databases.
Source Code
Requirements
Kubernetes: >=1.29.0-0
| Repository | Name | Version |
|---|---|---|
| https://cloudnative-pg.github.io/grafana-dashboards | monitoring(cluster) | 0.0 |
Values
| Key | Type | Default | Description |
|---|---|---|---|
| additionalArgs | list | [] |
Additional arguments to be added to the operator's args list. |
| additionalEnv | list | [] |
Array containing extra environment variables which can be templated. |
| affinity | object | {} |
Affinity for the operator to be installed. |
| commonAnnotations | object | {} |
Annotations to be added to all other resources. |
| config.clusterWide | bool | true |
This option determines if the operator is responsible for observing events across the entire Kubernetes cluster or if its focus should be narrowed down to the specific namespace within which it has been deployed. |
| config.create | bool | true |
Specifies whether the secret should be created. |
| config.data | object | {} |
The content of the configmap/secret, see https://cloudnative-pg.io/documentation/current/operator_conf/#available-options for all the available options. |
| config.maxConcurrentReconciles | int | 10 |
The maximum number of concurrent reconciles. Defaults to 10. |
| config.name | string | "cnpg-controller-manager-config" |
The name of the configmap/secret to use. |
| config.secret | bool | false |
Specifies whether it should be stored in a secret, instead of a configmap. |
| containerSecurityContext | object | {"allowPrivilegeEscalation":false,"capabilities":{"drop":["ALL"]},"readOnlyRootFilesystem":true,"runAsGroup":10001,"runAsUser":10001,"seccompProfile":{"type":"RuntimeDefault"}} |
Container Security Context. |
| crds.create | bool | true |
Specifies whether the CRDs should be created when installing the chart. |
| dnsPolicy | string | "" |
|
| fullnameOverride | string | "" |
|
| hostNetwork | bool | false |
|
| image.pullPolicy | string | "IfNotPresent" |
|
| image.repository | string | "ghcr.io/cloudnative-pg/cloudnative-pg" |
|
| image.tag | string | "" |
Overrides the image tag whose default is the chart appVersion. |
| imagePullSecrets | list | [] |
|
| monitoring.grafanaDashboard.annotations | object | {} |
Annotations that ConfigMaps can have to get configured in Grafana. |
| monitoring.grafanaDashboard.configMapName | string | "cnpg-grafana-dashboard" |
The name of the ConfigMap containing the dashboard. |
| monitoring.grafanaDashboard.create | bool | false |
|
| monitoring.grafanaDashboard.labels | object | {} |
Labels that ConfigMaps should have to get configured in Grafana. |
| monitoring.grafanaDashboard.namespace | string | "" |
Allows overriding the namespace where the ConfigMap will be created, defaulting to the same one as the Release. |
| monitoring.grafanaDashboard.sidecarLabel | string | "grafana_dashboard" |
Label that ConfigMaps should have to be loaded as dashboards. DEPRECATED: Use labels instead. |
| monitoring.grafanaDashboard.sidecarLabelValue | string | "1" |
Label value that ConfigMaps should have to be loaded as dashboards. DEPRECATED: Use labels instead. |
| monitoring.podMonitorAdditionalLabels | object | {} |
Additional labels for the podMonitor |
| monitoring.podMonitorEnabled | bool | false |
Specifies whether the monitoring should be enabled. Requires Prometheus Operator CRDs. |
| monitoring.podMonitorMetricRelabelings | list | [] |
Metrics relabel configurations to apply to samples before ingestion. |
| monitoring.podMonitorRelabelings | list | [] |
Relabel configurations to apply to samples before scraping. |
| monitoringQueriesConfigMap.name | string | "cnpg-default-monitoring" |
The name of the default monitoring configmap. |
| monitoringQueriesConfigMap.queries | string | `"backends:\n query: | \n SELECT sa.datname\n , sa.usename\n , sa.application_name\n , states.state\n , COALESCE(sa.count, 0) AS total\n , COALESCE(sa.max_tx_secs, 0) AS max_tx_duration_seconds\n FROM ( VALUES ('active')\n , ('idle')\n , ('idle in transaction')\n , ('idle in transaction (aborted)')\n , ('fastpath function call')\n , ('disabled')\n ) AS states(state)\n LEFT JOIN (\n SELECT datname\n , state\n , usename\n , COALESCE(application_name, '') AS application_name\n , pg_catalog.count(*)\n , COALESCE(EXTRACT (EPOCH FROM (pg_catalog.max(pg_catalog.now() OPERATOR(pg_catalog.-) xact_start))), 0) AS max_tx_secs\n FROM pg_catalog.pg_stat_activity\n GROUP BY datname, state, usename, application_name\n ) sa ON states.state OPERATOR(pg_catalog.=) sa.state\n WHERE sa.usename IS NOT NULL\n metrics:\n - datname:\n usage: "LABEL"\n description: "Name of the database"\n - usename:\n usage: "LABEL"\n description: "Name of the user"\n - application_name:\n usage: "LABEL"\n description: "Name of the application"\n - state:\n usage: "LABEL"\n description: "State of the backend"\n - total:\n usage: "GAUGE"\n description: "Number of backends"\n - max_tx_duration_seconds:\n usage: "GAUGE"\n description: "Maximum duration of a transaction in seconds"\n\nbackends_waiting:\n query: |
| nameOverride | string | "" |
|
| namespaceOverride | string | "" |
|
| nodeSelector | object | {} |
Nodeselector for the operator to be installed. |
| podAnnotations | object | {} |
Annotations to be added to the pod. |
| podLabels | object | {} |
Labels to be added to the pod. |
| podSecurityContext | object | {"runAsNonRoot":true,"seccompProfile":{"type":"RuntimeDefault"}} |
Security Context for the whole pod. |
| priorityClassName | string | "" |
Priority indicates the importance of a Pod relative to other Pods. |
| rbac.aggregateClusterRoles | bool | false |
Aggregate ClusterRoles to Kubernetes default user-facing roles. Ref: https://kubernetes.io/docs/reference/access-authn-authz/rbac/#user-facing-roles |
| rbac.create | bool | true |
Specifies whether ClusterRole and ClusterRoleBinding should be created. |
| replicaCount | int | 1 |
|
| resources | object | {} |
|
| service.ipFamilies | list | [] |
Sets the families that should be supported and the order in which they should be applied to ClusterIP as well. Can be IPv4 and/or IPv6. |
| service.ipFamilyPolicy | string | "" |
Set the ip family policy to configure dual-stack see Configure dual-stack |
| service.name | string | "cnpg-webhook-service" |
The name of the Webhook Service. |
| service.port | int | 443 |
|
| service.type | string | "ClusterIP" |
|
| serviceAccount.create | bool | true |
Specifies whether the service account should be created. |
| serviceAccount.name | string | "" |
The name of the service account to use. If not set and create is true, a name is generated using the fullname template. |
| tolerations | list | [] |
Tolerations for the operator to be installed. |
| topologySpreadConstraints | list | [] |
Topology Spread Constraints for the operator to be installed. |
| updateStrategy | object | {} |
Update strategy for the operator. ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy |
| webhook | object | {"livenessProbe":{"initialDelaySeconds":3},"mutating":{"create":true,"failurePolicy":"Fail"},"port":9443,"readinessProbe":{"initialDelaySeconds":3},"startupProbe":{"failureThreshold":6,"periodSeconds":5},"validating":{"create":true,"failurePolicy":"Fail"}} |
The webhook configuration. |
Maintainers
| Name | Url | |
|---|---|---|
| phisco | p.scorsolini@gmail.com |
Contributing
Please read the code of conduct and the guidelines to contribute to the project.
Copyright
Helm charts for CloudNativePG are distributed under Apache License 2.0.