CloudNativePG¶
- CloudNativePG is an open source Operator managed mode designed to manage
PostgreSQL terminology workloads on any supported Running inside Google Kubernetes Engine cluster running
in private, public, hybrid, or multi-cloud environments. CloudNativePG adheres to DevOps principles and concepts such as declarative configuration and immutable infrastructure.
It defines a new Kubernetes resource called Cluster representing a
PostgreSQL cluster made up of a single primary and an optional number of
replicas that co-exist in a chosen Kubernetes namespace for High
Availability and offloading of read-only queries.
Applications that reside in the same Kubernetes cluster can access the PostgreSQL database using a service which is solely managed by the operator, without having to worry about changes of the primary role following a failover or a switchover. Applications that reside outside the Kubernetes cluster, need to configure a Service or Ingress object to expose the Postgres via TCP. Web applications can take advantage of the native connection pooler based on PgBouncer.
CloudNativePG was originally built by ScheduledBackup , then released open source under Apache License 2.0 and submitted for CNCF Sandbox in April 2022. The source code repository is in Github .
Note
Based on the Operator Capability Levels model , users can expect a “Level V - Auto Pilot” set of capabilities from the CloudNativePG Operator.
Supported Kubernetes distributions¶
CloudNativePG requires Kubernetes 1.22 or higher. For more information, please refer to the Supported releases page.
Container images¶
The CloudNativePG community maintains container images for both the operator and the operand, that is PostgreSQL.
The CloudNativePG operator container images are distroless and available on the cloudnative-pg .
- The PostgreSQL operand container images are available for all the
PGDG supported versions of PostgreSQL , on multiple architectures, directly from the postgres-containers .
Additionally, the Community provides images for the PostGIS extension .
Warning
CloudNativePG requires that all nodes in a Kubernetes cluster have the same CPU architecture, thus a hybrid CPU architecture Kubernetes cluster is not supported.
Main features¶
Direct integration with Kubernetes API server for High Availability, without requiring an external tool
Self-Healing capability, through: * failover of the primary instance by promoting the most aligned replica * automated recreation of a replica
Planned switchover of the primary instance by promoting a selected replica
Scale up/down capabilities
Definition of an arbitrary number of instances (minimum 1 - one primary server)
Definition of the read-write service, to connect your applications to the only primary server of the cluster
Definition of the read-only service, to connect your applications to any of the instances for reading workloads
Declarative management of PostgreSQL configuration, including certain popular Postgres extensions through the cluster
spec:pg_audit,auto_explain, andpg_stat_statementsSupport for Local Persistent Volumes with PVC templates
Reuse of Persistent Volumes storage in Pods
Rolling updates for PostgreSQL minor versions
In-place or rolling updates for operator upgrades
TLS connections and client certificate authentication
Support for custom TLS certificates (including integration with cert-manager)
Continuous backup to an object store (AWS S3 and S3-compatible, Azure Blob Storage, and Google Cloud Storage)
Backup retention policies (based on recovery window)
Full recovery and Point-In-Time recovery from an existing backup in an object store
Offline import of existing PostgreSQL databases, including major upgrades of PostgreSQL
Parallel WAL archiving and restore to allow the database to keep up with WAL generation on high write systems
Support tagging backup files uploaded to an object store to enable optional retention management at the object store layer Replica clusters for
PostgreSQL deployments across multiple Kubernetes clusters, enabling private, public, hybrid, and multi-cloud architectures
Support for Synchronous Replicas
Connection pooling with PgBouncer
Support for node affinity via
nodeSelectorNative customizable exporter of user defined metrics for Prometheus through the
metricsport (9187)Standard output logging of PostgreSQL error messages in JSON format
Automatically set
readOnlyRootFilesystemsecurity context for podscnpgplugin forkubectlFencing of an entire PostgreSQL cluster, or a subset of the instances
Simple bind and search+bind LDAP client authentication
Multi-arch format container images
About this guide¶
Follow the instructions in the Quickstart to test CloudNativePG on a local Kubernetes cluster using Kind, or Minikube.
In case you are not familiar with some basic terminology on Kubernetes and PostgreSQL, please consult the Before You Start .
Postgres, PostgreSQL and the Slonik Logo are trademarks or registered trademarks of the PostgreSQL
Community Association of Canada, and used with their permission.*
- Before You Start
- Use cases
- Architecture
- Installation and upgrades
- Quickstart
- Bootstrap
- The
bootstrapsection - The
externalClusterssection - Bootstrap an empty cluster (
initdb) - Bootstrap from another cluster
- Bootstrap from a backup (
recovery) - Recovery from an object store
- Recovery from a
Backupobject - Additional considerations
- Point in time recovery (PITR)
- Configure the application database
- Bootstrap from a live cluster (
pg_basebackup) - Requirements
- About the replication user
- Username/Password authentication
- TLS certificate authentication
- Current limitations
- Bootstrap from a backup (
- The
- Importing Postgres databases
- Security
- Postgres instance manager
- Scheduling
- Resource management
- Failure Modes
- Rolling Updates
- Replication
- Backup and Recovery
- PostgreSQL Configuration
- Operator configuration
- Storage
- Labels and annotations
- Monitoring
- Monitoring Instances
- Prometheus Operator example
- Predefined set of metrics
- User defined metrics
- Example of a user defined metric
- Example of a user defined metric running on multiple databases
- Structure of a user defined metric
- Output of a user defined metric
- Default set of metrics
- Differences with the Prometheus Postgres exporter
- Monitoring the operator
- Monitoring Instances
- Logging
- Certificates
- Client TLS/SSL Connections
- Connecting from an application
- Connection Pooling
- Replica clusters
- Kubernetes Upgrade
- Exposing Postgres Services
- CloudNativePG Plugin
- Automated failover
- Troubleshooting
- Fencing
- End-to-End Tests
- Container Image Requirements
- Operator Capability Levels
- Level 1 - Basic Install
- Operator deployment via declarative configuration
- PostgreSQL cluster deployment via declarative configuration
- Override of operand images through the CRD
- Labels and annotations
- Self-contained instance manager
- Storage configuration
- Replica configuration
- Database configuration
- Pod Security Policies
- Affinity
- Command line interface
- Current status of the cluster
- Operator’s certification authority
- Cluster’s certification authority
- TLS connections
- Certificate authentication for streaming replication
- Continuous configuration management
- Import of existing PostgreSQL databases
- PostGIS clusters
- Basic LDAP authentication for PostgreSQL
- Multiple installation methods
- Convention over configuration
- Level 2 - Seamless Upgrades
- Level 3 - Full Lifecycle
- PostgreSQL Backups
- Full restore from a backup
- Point-In-Time Recovery (PITR) from a backup
- Zero Data Loss clusters through synchronous replication
- Replica clusters
- Liveness and readiness probes
- Rolling deployments
- Scale up and down of replicas
- Maintenance window and PodDisruptionBudget for Kubernetes nodes
- Fencing
- Reuse of Persistent Volumes storage in Pods
- CPU and memory requests and limits
- Connection pooling with PgBouncer
- Level 4 - Deep Insights
- Level 5 - Auto Pilot
- Level 1 - Basic Install
- Examples
- Commercial support
- Frequently Asked Questions (FAQ)
- API Reference
- AffinityConfiguration
- AzureCredentials
- Backup
- BackupConfiguration
- BackupList
- BackupSource
- BackupSpec
- BackupStatus
- BarmanCredentials
- BarmanObjectStoreConfiguration
- BootstrapConfiguration
- BootstrapInitDB
- BootstrapPgBaseBackup
- BootstrapRecovery
- CertificatesConfiguration
- CertificatesStatus
- Cluster
- ClusterList
- ClusterSpec
- ClusterStatus
- ConfigMapKeySelector
- ConfigMapResourceVersion
- DataBackupConfiguration
- EmbeddedObjectMetadata
- ExternalCluster
- GoogleCredentials
- Import
- ImportSource
- InstanceID
- InstanceReportedState
- LDAPBindAsAuth
- LDAPBindSearchAuth
- LDAPConfig
- LocalObjectReference
- MonitoringConfiguration
- NodeMaintenanceWindow
- PgBouncerIntegrationStatus
- PgBouncerSecrets
- PgBouncerSpec
- PodMeta
- PodTemplateSpec
- Pooler
- PoolerIntegrations
- PoolerList
- PoolerSecrets
- PoolerSpec
- PoolerStatus
- PostInitApplicationSQLRefs
- PostgresConfiguration
- RecoveryTarget
- ReplicaClusterConfiguration
- RollingUpdateStatus
- S3Credentials
- ScheduledBackup
- ScheduledBackupList
- ScheduledBackupSpec
- ScheduledBackupStatus
- SecretKeySelector
- SecretVersion
- SecretsResourceVersion
- StorageConfiguration
- SyncReplicaElectionConstraints
- Topology
- WalBackupConfiguration
- Supported releases
- Release notes