From 52e1f50a8061d85ddc663688655a2f149e4d085b Mon Sep 17 00:00:00 2001 From: mr-forust Date: Mon, 14 Sep 2026 10:25:45 +0200 Subject: [PATCH 1/6] feat(postgres): add shared database deployments --- postgres/.env.example | 5 ++ postgres/README.md | 35 ++++++++ postgres/initdb/01-create-databases.sh | 27 ++++++ postgres/k8s/active | 0 postgres/k8s/namespace.yaml | 6 ++ postgres/k8s/network-policy.yaml | 28 ++++++ postgres/k8s/postgres.yaml | 114 +++++++++++++++++++++++++ postgres/k8s/secrets.yaml.example | 12 +++ postgres/shared-compose.yaml | 28 ++++++ 9 files changed, 255 insertions(+) create mode 100644 postgres/.env.example create mode 100644 postgres/README.md create mode 100755 postgres/initdb/01-create-databases.sh create mode 100644 postgres/k8s/active create mode 100644 postgres/k8s/namespace.yaml create mode 100644 postgres/k8s/network-policy.yaml create mode 100644 postgres/k8s/postgres.yaml create mode 100644 postgres/k8s/secrets.yaml.example create mode 100644 postgres/shared-compose.yaml diff --git a/postgres/.env.example b/postgres/.env.example new file mode 100644 index 0000000..ae8600c --- /dev/null +++ b/postgres/.env.example @@ -0,0 +1,5 @@ +POSTGRES_ADMIN_PASSWORD= +AUTHENTIK_DB_PASSWORD= +GITEA_DB_PASSWORD= +NETRONOME_DB_PASSWORD= +PENPOT_DB_PASSWORD= diff --git a/postgres/README.md b/postgres/README.md new file mode 100644 index 0000000..abbc43f --- /dev/null +++ b/postgres/README.md @@ -0,0 +1,35 @@ +# Shared PostgreSQL + +This directory contains a PostgreSQL 15 deployment draft for Authentik, Gitea, +Netronome, and Penpot. It creates one database and one login role per service; +it does not migrate existing data or change application connection settings. + +## Compatibility baseline + +| Service | Current application | Current standalone PostgreSQL | Common PostgreSQL 15 | +| --- | --- | ---: | --- | +| Authentik | 2025.10.2 | 15 | Supported (Authentik requires 14+) | +| Gitea | 1.27.3 | 14 | Supported (Gitea requires 12+) | +| Netronome | 0.14.0 | 17 | Validate in staging; upstream's example uses 17 but no 17-only feature is documented | +| Penpot | 2.17.2 | 15 | Supported by the official deployment | + +PostgreSQL 15 is the conservative common major. A major-version downgrade or +change must use a logical dump/restore; changing only the image tag while +keeping a data directory is not supported. Back up and migrate one application +at a time, starting with Netronome because its current standalone deployment +uses PostgreSQL 17. + +For Compose, copy `.env.example` to `.env`, set all passwords, and start it with +`docker compose -f shared-compose.yaml up -d`. This file is intentionally not +named `compose.yaml`, so the repository deploy workflow does not start a second +database accidentally. +Applications that use this database must also join that external network and use +`homelab-postgres:5432`. + +For Kubernetes, create `k8s/secrets.yaml` from the example before applying the +manifests. The `k8s/active` marker makes the normal deploy workflow include the +namespace, StatefulSet, ConfigMap, and NetworkPolicy. Applications use +`postgres.database.svc.cluster.local:5432`. +Migrate each existing database with a tested logical dump/restore before +switching an application. Do not reuse a PostgreSQL 14 or 17 data directory +with PostgreSQL 15. diff --git a/postgres/initdb/01-create-databases.sh b/postgres/initdb/01-create-databases.sh new file mode 100755 index 0000000..ffdb01d --- /dev/null +++ b/postgres/initdb/01-create-databases.sh @@ -0,0 +1,27 @@ +#!/usr/bin/env bash +set -euo pipefail + +: "${AUTHENTIK_DB_PASSWORD:?AUTHENTIK_DB_PASSWORD is required}" +: "${GITEA_DB_PASSWORD:?GITEA_DB_PASSWORD is required}" +: "${NETRONOME_DB_PASSWORD:?NETRONOME_DB_PASSWORD is required}" +: "${PENPOT_DB_PASSWORD:?PENPOT_DB_PASSWORD is required}" + +create_role_and_database() { + local role="$1" + local database="$2" + local password="$3" + + psql --username "$POSTGRES_USER" --dbname postgres \ + -v role="$role" -v database="$database" -v password="$password" \ + <<'SQL' +SELECT format('CREATE ROLE %I LOGIN PASSWORD %L', :'role', :'password') +WHERE NOT EXISTS (SELECT FROM pg_roles WHERE rolname = :'role')\gexec +SELECT format('CREATE DATABASE %I OWNER %I', :'database', :'role') +WHERE NOT EXISTS (SELECT FROM pg_database WHERE datname = :'database')\gexec +SQL +} + +create_role_and_database authentik authentik "$AUTHENTIK_DB_PASSWORD" +create_role_and_database gitea gitea "$GITEA_DB_PASSWORD" +create_role_and_database netronome netronome "$NETRONOME_DB_PASSWORD" +create_role_and_database penpot penpot "$PENPOT_DB_PASSWORD" diff --git a/postgres/k8s/active b/postgres/k8s/active new file mode 100644 index 0000000..e69de29 diff --git a/postgres/k8s/namespace.yaml b/postgres/k8s/namespace.yaml new file mode 100644 index 0000000..2b540ae --- /dev/null +++ b/postgres/k8s/namespace.yaml @@ -0,0 +1,6 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: database + labels: + app.kubernetes.io/part-of: homelab-database diff --git a/postgres/k8s/network-policy.yaml b/postgres/k8s/network-policy.yaml new file mode 100644 index 0000000..3877836 --- /dev/null +++ b/postgres/k8s/network-policy.yaml @@ -0,0 +1,28 @@ +apiVersion: networking.k8s.io/v1 +kind: NetworkPolicy +metadata: + name: postgres-ingress + namespace: database +spec: + podSelector: + matchLabels: + app.kubernetes.io/name: postgres + policyTypes: + - Ingress + ingress: + - from: + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: authentik + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: gitea + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: netronome + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: penpot + ports: + - protocol: TCP + port: 5432 diff --git a/postgres/k8s/postgres.yaml b/postgres/k8s/postgres.yaml new file mode 100644 index 0000000..6a605ba --- /dev/null +++ b/postgres/k8s/postgres.yaml @@ -0,0 +1,114 @@ +apiVersion: v1 +kind: Service +metadata: + name: postgres + namespace: database + labels: + app.kubernetes.io/name: postgres + app.kubernetes.io/part-of: homelab-database +spec: + selector: + app.kubernetes.io/name: postgres + ports: + - name: postgres + port: 5432 + targetPort: postgres +--- +apiVersion: apps/v1 +kind: StatefulSet +metadata: + name: postgres + namespace: database +spec: + serviceName: postgres + replicas: 1 + selector: + matchLabels: + app.kubernetes.io/name: postgres + template: + metadata: + labels: + app.kubernetes.io/name: postgres + spec: + containers: + - name: postgres + image: postgres:15.19-alpine + ports: + - name: postgres + containerPort: 5432 + env: + - name: POSTGRES_DB + value: postgres + - name: POSTGRES_USER + value: postgres + - name: POSTGRES_PASSWORD + valueFrom: + secretKeyRef: + name: postgres-shared-secrets + key: POSTGRES_ADMIN_PASSWORD + envFrom: + - secretRef: + name: postgres-shared-secrets + volumeMounts: + - name: postgres-data + mountPath: /var/lib/postgresql/data + - name: initdb + mountPath: /docker-entrypoint-initdb.d/01-create-databases.sh + subPath: 01-create-databases.sh + readinessProbe: + exec: + command: ["pg_isready", "-U", "postgres", "-d", "postgres"] + initialDelaySeconds: 10 + periodSeconds: 10 + livenessProbe: + exec: + command: ["pg_isready", "-U", "postgres", "-d", "postgres"] + initialDelaySeconds: 30 + periodSeconds: 20 + volumes: + - name: initdb + configMap: + name: postgres-initdb + defaultMode: 0755 + volumeClaimTemplates: + - metadata: + name: postgres-data + spec: + accessModes: ["ReadWriteOnce"] + resources: + requests: + storage: 20Gi +--- +apiVersion: v1 +kind: ConfigMap +metadata: + name: postgres-initdb + namespace: database +data: + 01-create-databases.sh: | + #!/usr/bin/env bash + set -euo pipefail + + : "${AUTHENTIK_DB_PASSWORD:?AUTHENTIK_DB_PASSWORD is required}" + : "${GITEA_DB_PASSWORD:?GITEA_DB_PASSWORD is required}" + : "${NETRONOME_DB_PASSWORD:?NETRONOME_DB_PASSWORD is required}" + : "${PENPOT_DB_PASSWORD:?PENPOT_DB_PASSWORD is required}" + + create_role_and_database() { + local role="$1" + local database="$2" + local password="$3" + psql --username "$POSTGRES_USER" --dbname postgres \ + -v role="$role" -v database="$database" -v password="$password" \ + <<'SQL' + SELECT format('CREATE ROLE %I LOGIN PASSWORD %L', :'role', :'password') + WHERE NOT EXISTS (SELECT FROM pg_roles WHERE rolname = :'role')\gexec + SELECT format('CREATE DATABASE %I OWNER %I', :'database', :'role') + WHERE NOT EXISTS (SELECT FROM pg_database WHERE datname = :'database')\gexec + SQL + } + + create_role_and_database authentik authentik "$AUTHENTIK_DB_PASSWORD" + create_role_and_database gitea gitea "$GITEA_DB_PASSWORD" + create_role_and_database netronome netronome "$NETRONOME_DB_PASSWORD" + create_role_and_database penpot penpot "$PENPOT_DB_PASSWORD" diff --git a/postgres/k8s/secrets.yaml.example b/postgres/k8s/secrets.yaml.example new file mode 100644 index 0000000..d905da1 --- /dev/null +++ b/postgres/k8s/secrets.yaml.example @@ -0,0 +1,12 @@ +apiVersion: v1 +kind: Secret +metadata: + name: postgres-shared-secrets + namespace: database +type: Opaque +stringData: + POSTGRES_ADMIN_PASSWORD: "" + AUTHENTIK_DB_PASSWORD: "" + GITEA_DB_PASSWORD: "" + NETRONOME_DB_PASSWORD: "" + PENPOT_DB_PASSWORD: "" diff --git a/postgres/shared-compose.yaml b/postgres/shared-compose.yaml new file mode 100644 index 0000000..872078d --- /dev/null +++ b/postgres/shared-compose.yaml @@ -0,0 +1,28 @@ +services: + postgres: + image: postgres:15.19-alpine + container_name: homelab-postgres + restart: unless-stopped + env_file: + - .env + environment: + POSTGRES_DB: postgres + POSTGRES_USER: postgres + POSTGRES_PASSWORD: ${POSTGRES_ADMIN_PASSWORD:?set POSTGRES_ADMIN_PASSWORD} + volumes: + - postgres-data:/var/lib/postgresql/data + - ./initdb:/docker-entrypoint-initdb.d:ro + healthcheck: + test: ["CMD-SHELL", "pg_isready -U postgres -d postgres"] + interval: 10s + timeout: 5s + retries: 5 + networks: + - database + +volumes: + postgres-data: + +networks: + database: + name: homelab-database From b3463705c31371c47b8b41394fdbd2fd4f0495a1 Mon Sep 17 00:00:00 2001 From: mr-forust Date: Mon, 14 Sep 2026 10:41:46 +0200 Subject: [PATCH 2/6] feat(postgres): migrate apps to shared database Move Authentik and Netronome to the shared PostgreSQL service after logical dump and restore. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- authentik/k8s/config.yaml | 2 +- netronome/k8s/config.yaml | 2 +- postgres/k8s/postgres.yaml | 1 + 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/authentik/k8s/config.yaml b/authentik/k8s/config.yaml index f888be8..0d3c4e5 100644 --- a/authentik/k8s/config.yaml +++ b/authentik/k8s/config.yaml @@ -6,6 +6,6 @@ metadata: data: AUTHENTIK_IMAGE: ghcr.io/goauthentik/server AUTHENTIK_TAG: "2025.10.2" - AUTHENTIK_POSTGRESQL__HOST: authentik-postgres-service + AUTHENTIK_POSTGRESQL__HOST: postgres.database.svc.cluster.local AUTHENTIK_POSTGRESQL__NAME: authentik AUTHENTIK_ERROR_REPORTING__ENABLED: "true" diff --git a/netronome/k8s/config.yaml b/netronome/k8s/config.yaml index fa4f125..23ac87a 100644 --- a/netronome/k8s/config.yaml +++ b/netronome/k8s/config.yaml @@ -5,7 +5,7 @@ metadata: namespace: netronome data: NETRONOME__DB_TYPE: "postgres" - NETRONOME__DB_HOST: "netronome-postgres-service" + NETRONOME__DB_HOST: "postgres.database.svc.cluster.local" NETRONOME__DB_PORT: "5432" NETRONOME__DB_NAME: "netronome" NETRONOME__DB_SSLMODE: "disable" diff --git a/postgres/k8s/postgres.yaml b/postgres/k8s/postgres.yaml index 6a605ba..531ff3b 100644 --- a/postgres/k8s/postgres.yaml +++ b/postgres/k8s/postgres.yaml @@ -75,6 +75,7 @@ spec: name: postgres-data spec: accessModes: ["ReadWriteOnce"] + storageClassName: local-path-retain resources: requests: storage: 20Gi From 003b1e5dca0d74953f00abf6adf26a3782ceb0b9 Mon Sep 17 00:00:00 2001 From: mr-forust Date: Mon, 14 Sep 2026 11:54:28 +0200 Subject: [PATCH 3/6] feat(postgres): upgrade shared database to PostgreSQL 17 Move the shared postgres service from 15.19 to 17.6 as the postgres17 StatefulSet with its own PVC, extend the initdb and ingress policy with the statuspage database, and drop the now-unused per-app postgres manifests for authentik, gitea and netronome. --- authentik/k8s/postgresql.yaml | 66 ---------------------------- gitea/k8s/postgres.yaml | 62 --------------------------- netronome/k8s/postgres.yaml | 71 ------------------------------- postgres/k8s/network-policy.yaml | 5 ++- postgres/k8s/postgres.yaml | 43 ++++++++++++------- postgres/k8s/secrets.yaml.example | 1 + 6 files changed, 32 insertions(+), 216 deletions(-) delete mode 100644 authentik/k8s/postgresql.yaml delete mode 100644 gitea/k8s/postgres.yaml delete mode 100644 netronome/k8s/postgres.yaml diff --git a/authentik/k8s/postgresql.yaml b/authentik/k8s/postgresql.yaml deleted file mode 100644 index 9199cb3..0000000 --- a/authentik/k8s/postgresql.yaml +++ /dev/null @@ -1,66 +0,0 @@ -apiVersion: v1 -kind: Service -metadata: - name: authentik-postgres-service - namespace: authentik -spec: - clusterIP: None - selector: - app: authentik-postgres - ports: - - port: 5432 - targetPort: 5432 ---- -apiVersion: apps/v1 -kind: StatefulSet -metadata: - name: authentik-postgres-statefulset - namespace: authentik -spec: - selector: - matchLabels: - app: authentik-postgres - serviceName: authentik-postgres-service - replicas: 1 - template: - metadata: - labels: - app: authentik-postgres - spec: - containers: - - name: postgres - image: docker.io/library/postgres:15.19-alpine - env: - - name: POSTGRES_DB - value: authentik - - name: POSTGRES_USER - valueFrom: - secretKeyRef: - name: authentik-secrets - key: AUTHENTIK_POSTGRESQL__USER - - name: POSTGRES_PASSWORD - valueFrom: - secretKeyRef: - name: authentik-secrets - key: AUTHENTIK_POSTGRESQL__PASSWORD - ports: - - containerPort: 5432 - name: postgres - volumeMounts: - - name: postgres-data - mountPath: /var/lib/postgresql/data - resources: - requests: - memory: "256Mi" - cpu: "200m" - limits: - memory: "1Gi" - cpu: "500m" - volumeClaimTemplates: - - metadata: - name: postgres-data - spec: - accessModes: ["ReadWriteOnce"] - resources: - requests: - storage: 5Gi diff --git a/gitea/k8s/postgres.yaml b/gitea/k8s/postgres.yaml deleted file mode 100644 index 90a1cc6..0000000 --- a/gitea/k8s/postgres.yaml +++ /dev/null @@ -1,62 +0,0 @@ -apiVersion: v1 -kind: Service -metadata: - name: gitea-postgres-service - namespace: gitea -spec: - clusterIP: None - selector: - app: gitea-postgres - ports: - - port: 5432 - targetPort: 5432 ---- -apiVersion: apps/v1 -kind: StatefulSet -metadata: - name: gitea-postgres-statefulset - namespace: gitea -spec: - selector: - matchLabels: - app: gitea-postgres - serviceName: gitea-postgres-service - replicas: 1 - template: - metadata: - labels: - app: gitea-postgres - spec: - containers: - - name: gitea-postgres - image: postgres:14.24-alpine - env: - - name: POSTGRES_USER - valueFrom: - secretKeyRef: - name: gitea-secrets - key: GITEA__database__USER - - name: POSTGRES_PASSWORD - valueFrom: - secretKeyRef: - name: gitea-secrets - key: GITEA__database__PASSWD - - name: POSTGRES_DB - valueFrom: - secretKeyRef: - name: gitea-secrets - key: GITEA__database__NAME - ports: - - containerPort: 5432 - name: postgres - volumeMounts: - - name: postgres-data - mountPath: /var/lib/postgresql/data - volumeClaimTemplates: - - metadata: - name: postgres-data - spec: - accessModes: ["ReadWriteOnce"] - resources: - requests: - storage: 1Gi diff --git a/netronome/k8s/postgres.yaml b/netronome/k8s/postgres.yaml deleted file mode 100644 index 1c3a2e8..0000000 --- a/netronome/k8s/postgres.yaml +++ /dev/null @@ -1,71 +0,0 @@ -apiVersion: v1 -kind: Service -metadata: - name: netronome-postgres-service - namespace: netronome -spec: - selector: - app: netronome-postgres - ports: - - protocol: TCP - port: 5432 - targetPort: 5432 ---- -apiVersion: apps/v1 -kind: StatefulSet -metadata: - name: netronome-postgres - namespace: netronome -spec: - serviceName: "netronome-postgres-service" - replicas: 1 - selector: - matchLabels: - app: netronome-postgres - template: - metadata: - labels: - app: netronome-postgres - spec: - containers: - - name: netronome-postgres - image: postgres:17.11-alpine - ports: - - name: postgres-port - protocol: TCP - containerPort: 5432 - env: - - name: POSTGRES_USER - valueFrom: - secretKeyRef: - name: netronome-secrets - key: NETRONOME__DB_USER - - name: POSTGRES_PASSWORD - valueFrom: - secretKeyRef: - name: netronome-secrets - key: NETRONOME__DB_PASSWORD - - name: POSTGRES_DB - valueFrom: - configMapKeyRef: - name: netronome-config - key: NETRONOME__DB_NAME - resources: - requests: - memory: "512Mi" - cpu: "500m" - limits: - memory: "1Gi" - cpu: "1000m" - volumeMounts: - - name: netronome-pg-data - mountPath: /var/lib/postgresql/data - volumeClaimTemplates: - - metadata: - name: netronome-pg-data - spec: - accessModes: - - ReadWriteOnce - resources: - requests: - storage: 1Gi diff --git a/postgres/k8s/network-policy.yaml b/postgres/k8s/network-policy.yaml index 3877836..b4ec4dd 100644 --- a/postgres/k8s/network-policy.yaml +++ b/postgres/k8s/network-policy.yaml @@ -6,7 +6,7 @@ metadata: spec: podSelector: matchLabels: - app.kubernetes.io/name: postgres + app.kubernetes.io/name: postgres17 policyTypes: - Ingress ingress: @@ -23,6 +23,9 @@ spec: - namespaceSelector: matchLabels: kubernetes.io/metadata.name: penpot + - namespaceSelector: + matchLabels: + kubernetes.io/metadata.name: statuspage ports: - protocol: TCP port: 5432 diff --git a/postgres/k8s/postgres.yaml b/postgres/k8s/postgres.yaml index 531ff3b..e4707f5 100644 --- a/postgres/k8s/postgres.yaml +++ b/postgres/k8s/postgres.yaml @@ -4,11 +4,11 @@ metadata: name: postgres namespace: database labels: - app.kubernetes.io/name: postgres + app.kubernetes.io/name: postgres17 app.kubernetes.io/part-of: homelab-database spec: selector: - app.kubernetes.io/name: postgres + app.kubernetes.io/name: postgres17 ports: - name: postgres port: 5432 @@ -17,22 +17,22 @@ spec: apiVersion: apps/v1 kind: StatefulSet metadata: - name: postgres + name: postgres17 namespace: database spec: - serviceName: postgres + serviceName: postgres17 replicas: 1 selector: matchLabels: - app.kubernetes.io/name: postgres + app.kubernetes.io/name: postgres17 template: metadata: labels: - app.kubernetes.io/name: postgres + app.kubernetes.io/name: postgres17 spec: containers: - name: postgres - image: postgres:15.19-alpine + image: postgres:17.6-alpine ports: - name: postgres containerPort: 5432 @@ -66,19 +66,28 @@ spec: initialDelaySeconds: 30 periodSeconds: 20 volumes: + - name: postgres-data + persistentVolumeClaim: + claimName: postgres17-data - name: initdb configMap: name: postgres-initdb defaultMode: 0755 - volumeClaimTemplates: - - metadata: - name: postgres-data - spec: - accessModes: ["ReadWriteOnce"] - storageClassName: local-path-retain - resources: - requests: - storage: 20Gi +--- +apiVersion: v1 +kind: PersistentVolumeClaim +metadata: + name: postgres17-data + namespace: database + labels: + app.kubernetes.io/name: postgres17 + app.kubernetes.io/part-of: homelab-database +spec: + accessModes: ["ReadWriteOnce"] + storageClassName: local-path-retain + resources: + requests: + storage: 20Gi --- apiVersion: v1 kind: ConfigMap @@ -94,6 +103,7 @@ data: : "${GITEA_DB_PASSWORD:?GITEA_DB_PASSWORD is required}" : "${NETRONOME_DB_PASSWORD:?NETRONOME_DB_PASSWORD is required}" : "${PENPOT_DB_PASSWORD:?PENPOT_DB_PASSWORD is required}" + : "${STATUSPAGE_DB_PASSWORD:?STATUSPAGE_DB_PASSWORD is required}" create_role_and_database() { local role="$1" @@ -113,3 +123,4 @@ data: create_role_and_database gitea gitea "$GITEA_DB_PASSWORD" create_role_and_database netronome netronome "$NETRONOME_DB_PASSWORD" create_role_and_database penpot penpot "$PENPOT_DB_PASSWORD" + create_role_and_database statuspage statuspage "$STATUSPAGE_DB_PASSWORD" \ No newline at end of file diff --git a/postgres/k8s/secrets.yaml.example b/postgres/k8s/secrets.yaml.example index d905da1..4768d78 100644 --- a/postgres/k8s/secrets.yaml.example +++ b/postgres/k8s/secrets.yaml.example @@ -10,3 +10,4 @@ stringData: GITEA_DB_PASSWORD: "" NETRONOME_DB_PASSWORD: "" PENPOT_DB_PASSWORD: "" + STATUSPAGE_DB_PASSWORD: "" From c7d42fb90a5e09d6eb3394f739b1faa9efb9ad6c Mon Sep 17 00:00:00 2001 From: mr-forust Date: Mon, 14 Sep 2026 13:52:20 +0200 Subject: [PATCH 4/6] feat(postgres): migrate gitea to shared postgres database --- gitea/k8s/config.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/gitea/k8s/config.yaml b/gitea/k8s/config.yaml index 20b4706..39eef13 100644 --- a/gitea/k8s/config.yaml +++ b/gitea/k8s/config.yaml @@ -10,7 +10,7 @@ data: GITEA__server__SSH_PORT: "2221" GITEA__database__DB_TYPE: "postgres" - GITEA__database__HOST: "gitea-postgres-service:5432" + GITEA__database__HOST: "postgres.database.svc.cluster.local:5432" GITEA__database__NAME: "gitea" GITEA__security__REVERSE_PROXY_LIMIT: "1" GITEA__security__REVERSE_PROXY_TRUSTED_PROXIES: "*" From 8f2e9d66c88b104cef5992d6ffcd2e315983e3db Mon Sep 17 00:00:00 2001 From: mr-forust Date: Mon, 14 Sep 2026 13:53:09 +0200 Subject: [PATCH 5/6] chore(gite): updated deprecated access log config --- gitea/k8s/config.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/gitea/k8s/config.yaml b/gitea/k8s/config.yaml index 39eef13..9eb7297 100644 --- a/gitea/k8s/config.yaml +++ b/gitea/k8s/config.yaml @@ -17,6 +17,6 @@ data: GITEA__mailer__ENABLED: "false" - GITEA__log__logger__access__MODE: "console, file" + GITEA__log__logger.access.MODE: "console, file" USER_UID: "1000" USER_GID: "1000" From 4ac65f743c26b4acf4f57378f32d56411e9bf9bb Mon Sep 17 00:00:00 2001 From: mr-forust Date: Mon, 14 Sep 2026 13:56:06 +0200 Subject: [PATCH 6/6] lint(postgres): 126:77 error no new line character at the end of file (new-line-at-end-of-file) --- postgres/README.md | 12 ++++++------ postgres/k8s/postgres.yaml | 2 +- 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/postgres/README.md b/postgres/README.md index abbc43f..8e2fa7e 100644 --- a/postgres/README.md +++ b/postgres/README.md @@ -6,12 +6,12 @@ it does not migrate existing data or change application connection settings. ## Compatibility baseline -| Service | Current application | Current standalone PostgreSQL | Common PostgreSQL 15 | -| --- | --- | ---: | --- | -| Authentik | 2025.10.2 | 15 | Supported (Authentik requires 14+) | -| Gitea | 1.27.3 | 14 | Supported (Gitea requires 12+) | -| Netronome | 0.14.0 | 17 | Validate in staging; upstream's example uses 17 but no 17-only feature is documented | -| Penpot | 2.17.2 | 15 | Supported by the official deployment | +| Service | Current application | Current standalone PostgreSQL | Common PostgreSQL 15 | +| --------- | ------------------- | ----------------------------: | ------------------------------------------------------------------------------------ | +| Authentik | 2025.10.2 | 15 | Supported (Authentik requires 14+) | +| Gitea | 1.27.3 | 14 | Supported (Gitea requires 12+) | +| Netronome | 0.14.0 | 17 | Validate in staging; upstream's example uses 17 but no 17-only feature is documented | +| Penpot | 2.17.2 | 15 | Supported by the official deployment | PostgreSQL 15 is the conservative common major. A major-version downgrade or change must use a logical dump/restore; changing only the image tag while diff --git a/postgres/k8s/postgres.yaml b/postgres/k8s/postgres.yaml index e4707f5..886fad4 100644 --- a/postgres/k8s/postgres.yaml +++ b/postgres/k8s/postgres.yaml @@ -123,4 +123,4 @@ data: create_role_and_database gitea gitea "$GITEA_DB_PASSWORD" create_role_and_database netronome netronome "$NETRONOME_DB_PASSWORD" create_role_and_database penpot penpot "$PENPOT_DB_PASSWORD" - create_role_and_database statuspage statuspage "$STATUSPAGE_DB_PASSWORD" \ No newline at end of file + create_role_and_database statuspage statuspage "$STATUSPAGE_DB_PASSWORD"