Examples#
例は、PostgreSQLクラスターをセットアップするための構成ファイルを示しています。
基本#
基本的なクラスター
クラスターの基本的な例。
EDB Postgres Advanced Serverクラスター
EPASクラスターの基本的な例。
EDB Postgres ExtendedPGEクラスター
PGEクラスターの基本的な例。
カスタムクラスター
デフォルトのストレージクラスとカスタムパラメーターを使用する基本的なクラスター
postgresql.conf およびpg_hba.conf ファイル。
動的pg_hbaアドレス解決を使用したクラスター
cluster-example-pod-selector-refs.yaml
podSelectorRefs を使用して、 ${podselector:NAME}
構文を介してpg_hba ルールのポッドIPを動的に解決するクラスター。
カスタマイズされたストレージクラスを使用したクラスター
cluster-storage-class.yaml standard
の指定されたストレージクラスを使用する基本クラスター。
永続的なボリューム要求PVCテンプレートが構成されたクラスター
cluster-pvc-template.yaml 明示的な永続ボリューム要求テンプレートを使用した基本クラスター。
拡張構成例
cluster-example-full.yaml 使用可能なオプションのほとんどを設定するクラスター。
SQLファイルを使用したブートストラップクラスター
cluster-example-initdb-sql-refs.yaml
データベースが作成された直後に、シークレットとConfigMap
で定義されたクエリーセットを実行するクラスター例。
カスタマイズされた``pg_hba`` 構成を使用したサンプルクラスター
cluster-example-pg-hba.yaml ユーザアプリが証明書を使用して認証できるようにする基本的なクラスター。
投影されたボリュームテンプレートを使用してマウントされたシークレットとConfigMapを含むサンプルクラスター
cluster-example-projected-volume.yaml
投影されたボリュームマウントを使用してPostgresポッドにマウントされた既存のSecret
およびConfigMap を含む基本的なクラスター。
TDEが有効になったクラスター
TDEを使用したEPAS 15クラスター。使用するイメージをダウンロードするには、アクセス資格情報が必要であることに注意してください。
セキュリティ#
カスタムセキュリティコンテキストを使用したサンプルクラスター
cluster-example-security-context.yaml
ポッドとコンテナの両方のセキュリティコンテキストをカスタマイズする方法を示すクラスター。これは、ポッドセキュリティ標準を使用する場合、または特定のセキュリティ要件を満たす場合に役立ちます。
バックアップ#
カスタマイズされたストレージクラスとバックアップ
前提条件 バケットストレージが利用できること。サンプル構成はAWS用です。セットアップに合わせて変更します。
cluster-storage-class-with-backup.yaml バックアップが構成されたクラスター。
バックアップ
前提条件 cluster-storage-class-with-backup.yaml
適用され正常に稼働。
backup-example.yaml 前のサンプルに対して実行されるバックアップの例。
minio用にバックアップが構成された単純なクラスター
前提条件
この構成では、minioが実行され動作していることを前提としています。
minioパラメーターまたはクラウドソリューションでbackup.barmanObjectStore
を更新します。
cluster-example-with-backup.yaml
バックアップが構成された基本的なクラスター。
Scaleway Object Storage用に構成されたバックアップを含む単純なクラスター
前提条件 この構成では、Scaleway Object
Storageバケットが存在することを前提としています。
backup.barmanObjectStore をScalewayパラメーターで更新します。
cluster-example-with-backup-scaleway.yaml
Scaleway Object Storageで動作するように構成されたバックアップを含む基本的なクラスター。
レプリカクラスター#
オブジェクトストアからのバックアップによるレプリカクラスター
前提条件 cluster-storage-class-with-backup.yaml
適用され、正常な、およびバックアップ cluster-example-trigger-backup.yaml
適用されて完了しました。
cluster-example-replica-from-backup-simple.yaml バックアップが構成されたクラスターに続くレプリカクラスター。
ボリュームスナップショットによるレプリカクラスター
前提条件 cluster-example-with-volume-snapshot.yaml
適用され、正常な、およびボリュームスナップショット backup-with-volume-snapshot.yaml
適用されて完了しました。
cluster-example-replica-from-volume-snapshot.yaml ボリュームスナップショットが構成されたクラスターに続くレプリカクラスター。
ストリーミングpg_basebackupを介したレプリカクラスター
前提条件 cluster-example.yaml
適用され正常に稼働。
cluster-example-replica-streaming.yaml ストリーミングレプリケーションを使用したcluster-example
に続くレプリカクラスター。
PostGIS#
画像ボリューム拡張機能を使用したPostGISの例
postgis-example.yaml イメージボリューム拡張を使用したPostGISクラスターの例。詳細は、 PostGIS を参照してください。
管理対象ロール#
宣言的ロール管理を使用したクラスター
cluster-example-with-roles.yaml managed スタンザを使用してロールを宣言します。
Kubernetesシークレットを使用したパスワード管理が含まれます。
管理対象サービス#
管理対象サービスを使用したクラスター
cluster-example-managed-services.yaml managed
スタンザを使用してサービスを宣言します。デフォルトサービスが無効になり、定義されたLoadBalancer
タイプの新しいrw サービステンプレートが含まれます。
宣言的テーブルスペース#
宣言的テーブルスペースを使用したクラスター
cluster-example-with-tablespaces.yaml
宣言的テーブルスペースとバックアップを使用したクラスター
前提条件
この構成では、minioが実行され動作していることを前提としています。
minioパラメーターまたはクラウドソリューションでbackup.barmanObjectStore
を更新します。
cluster-example-with-tablespaces-backup.yaml
オブジェクトストアからテーブルスペースを使用して復元されたクラスター
前提条件
以前のクラスターが適用され、ベースバックアップが完了しました。
bootstrap.recovery.backup.name
をバックアップ名で更新することを忘れないでください。
cluster-restore-with-tablespaces.yaml
使用可能なオプションのリストについては、 API Reference - v1.29.0 を参照してください。
プーラー構成#
カスタムサービス構成を使用したプーラー
宣言的なパブリケーションおよびサブスクリプションオブジェクトを介した論理レプリケーション#
2つのテストマニフェストには、論理レプリケーションのセットアップに必要なすべてが含まれています。
パブリケーションを含むソースクラスター
cluster-example-logical-source.yaml
app
データベースで作成されたいくつかのテーブルを使用してクラスターcluster-example
をセットアップし、重要なことに、
アプリユーザーにレプリケーションを追加します 。 app
データベースにクラスターのパブリケーションが作成されます。パブリケーションは、クラスターのプライマリが起動して実行された後にのみリコンサイルされることに注意してください。
サブスクリプションを使用した宛先クラスター
前提条件 上記のように定義された、パブリケーションを含むソースクラスター。
cluster-example-logical-destination.yaml
次を使用してクラスターcluster-example-dest を設定します。
externalClustersスタンザで定義されたソースクラスター。appロールを使用して接続することに注意してください。これは、ソースクラスターがreplication特権を付与していることを前提としています。schemaOnlyが有効になったマイクロサービスタイプのブートストラップインポート
サブスクリプションは宛先クラスターで作成されます。サブスクリプションは、宛先クラスターのプライマリが起動して実行された後にのみ調整されることに注意してください。
両方のクラスターがリコンサイルされた後、パブリケーションオブジェクトとサブスクリプションオブジェクトとともに、ソースクラスターのテーブルとそのデータが宛先クラスターでレプリケートされたことを確認できます。
さらに、いくつかのスタンドアロンのマニフェストの例があります。
すべてのテーブルをターゲットとしたプレーンなパブリケーション
前提条件 既存のクラスターcluster-example 。
制約されたパブリケーションターゲットを含むパブリケーション
前提条件 既存のクラスターcluster-example 。
publication-example-objects.yaml
プレーンなサブスクリプション
前提条件 パブリケーションpub-all
を使用して、ソースとして設定された既存のクラスターcluster-example
。宛先クラスターとして設定されたクラスターcluster-example-dest
。レプリケーション特権を持つロールを含む、ソースクラスターへの接続パラメーターを含むexternalClusters
スタンザを含みます。
上記のマニフェストはすべて、app
データベースにパブリケーションまたはサブスクリプションを作成します。
Database
CRDは、データベースを宣言的に作成する便利な方法を提供します。これを使用すると、任意のデータベースに論理レプリケーションを設定できます。次のセクションに進みます。
Postgresデータベースの宣言的管理#
プレーンなデータベース
前提条件 既存のクラスターcluster-example 。
ICUローカル仕様のデータベース
前提条件 Postgres
16以上を実行している既存のクラスターcluster-example 。
cluster-example.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example
spec:
instances: 3
storage:
size: 1Gi
cluster-example-epas.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: postgresql-advanced-cluster
spec:
instances: 3
imageName: docker.enterprisedb.com/k8s/edb-postgres-advanced:18-standard-ubi9
storage:
size: 1Gi
cluster-example-pge.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: postgresql-extended-cluster
spec:
instances: 3
imageName: docker.enterprisedb.com/k8s/edb-postgres-extended:18-standard-ubi9
storage:
size: 1Gi
cluster-example-custom.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example-custom
spec:
instances: 3
# Parameters and pg_hba configuration will be append
# to the default ones to make the cluster work
postgresql:
parameters:
max_worker_processes: "60"
pg_hba:
# To access through TCP/IP you will need to get username
# and password from the secret cluster-example-custom-app
- host all all all md5
# Example of rolling update strategy:
# - unsupervised: automated update of the primary once all
# replicas have been upgraded (default)
# - supervised: requires manual supervision to perform
# the switchover of the primary
primaryUpdateStrategy: unsupervised
# Require 1Gi of space per instance using default storage class
storage:
size: 1Gi
cluster-example-pod-selector-refs.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example-pod-selector-refs
spec:
instances: 3
# Define named pod label selectors for dynamic pg_hba address resolution.
# The operator resolves matching pod IPs and expands ${podselector:NAME}
# references in pg_hba rules into one line per IP with /32 (IPv4) or /128 (IPv6) masks.
podSelectorRefs:
- name: app-pods
selector:
matchLabels:
app: myapp
- name: monitoring
selector:
matchLabels:
role: monitoring
postgresql:
pg_hba:
# These rules use ${podselector:NAME} syntax to reference podSelectorRefs.
# Each reference is expanded to one line per matching pod IP.
- "hostssl mydb myuser ${podselector:app-pods} scram-sha-256"
- "hostssl postgres monitor ${podselector:monitoring} scram-sha-256"
# Standard rules without expansion are passed through unchanged.
- host all all 10.244.0.0/16 md5
primaryUpdateStrategy: unsupervised
storage:
size: 1Gi
cluster-storage-class.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: postgresql-storage-class
spec:
instances: 3
# Example of rolling update strategy:
# - unsupervised: automated update of the primary once all
# replicas have been upgraded (default)
# - supervised: requires manual supervision to perform
# the switchover of the primary
primaryUpdateStrategy: unsupervised
# Persistent storage configuration
storage:
storageClass: standard
size: 1Gi
cluster-pvc-template.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: postgresql-pvc-template
spec:
instances: 3
# Example of rolling update strategy:
# - unsupervised: automated update of the primary once all
# replicas have been upgraded (default)
# - supervised: requires manual supervision to perform
# the switchover of the primary
primaryUpdateStrategy: unsupervised
# Persistent storage configuration
storage:
size: 1Gi
pvcTemplate:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi
storageClassName: standard
volumeMode: Filesystem
cluster-example-full.yaml#
# Example of definition of a test cluster using all the elements available
# in the CRD. Please change values appropriately for your environment.
# Remember that you can take advantage of convention over configuration
# and normally you dont need to use all these definitions.
apiVersion: v1
data:
password: VHhWZVE0bk44MlNTaVlIb3N3cU9VUlp2UURhTDRLcE5FbHNDRUVlOWJ3RHhNZDczS2NrSWVYelM1Y1U2TGlDMg==
username: YXBw
kind: Secret
metadata:
name: cluster-example-app-user
type: kubernetes.io/basic-auth
- --
apiVersion: v1
data:
password: dU4zaTFIaDBiWWJDYzRUeVZBYWNCaG1TemdxdHpxeG1PVmpBbjBRSUNoc0pyU211OVBZMmZ3MnE4RUtLTHBaOQ==
username: cG9zdGdyZXM=
kind: Secret
metadata:
name: cluster-example-superuser
type: kubernetes.io/basic-auth
- --
apiVersion: v1
kind: Secret
metadata:
name: backup-creds
data:
ACCESS_KEY_ID: a2V5X2lk
ACCESS_SECRET_KEY: c2VjcmV0X2tleQ==
- --
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example-full
spec:
description: "Example of cluster"
imageName: docker.enterprisedb.com/k8s/postgresql:18.3-standard-ubi9
# imagePullSecret is only required if the images are located in a private registry
# imagePullSecrets:
# - name: private_registry_access
instances: 3
startDelay: 300
stopDelay: 300
primaryUpdateStrategy: unsupervised
postgresql:
parameters:
shared_buffers: 256MB
pg_stat_statements.max: 10000
pg_stat_statements.track: all
auto_explain.log_min_duration: 10s
pg_hba:
- host all all 10.244.0.0/16 md5
bootstrap:
initdb:
database: app
owner: app
secret:
name: cluster-example-app-user
# Alternative bootstrap method: start from a backup
#recovery:
# backup:
# name: backup-example
enableSuperuserAccess: true
superuserSecret:
name: cluster-example-superuser
storage:
storageClass: standard
size: 1Gi
backup:
barmanObjectStore:
destinationPath: s3://cluster-example-full-backup/
endpointURL: http://custom-endpoint:1234
s3Credentials:
accessKeyId:
name: backup-creds
key: ACCESS_KEY_ID
secretAccessKey:
name: backup-creds
key: ACCESS_SECRET_KEY
wal:
compression: gzip
encryption: AES256
data:
compression: gzip
encryption: AES256
immediateCheckpoint: false
jobs: 2
retentionPolicy: "30d"
resources:
requests:
memory: "512Mi"
cpu: "1"
limits:
memory: "1Gi"
cpu: "2"
affinity:
enablePodAntiAffinity: true
topologyKey: failure-domain.beta.kubernetes.io/zone
nodeMaintenanceWindow:
inProgress: false
reusePVC: false
cluster-example-initdb-sql-refs.yaml#
apiVersion: v1
kind: ConfigMap
metadata:
name: post-init-sql-configmap
data:
configmap.sql: |
create table configmaps (i integer);
insert into configmaps (select generate_series(1,10000));
- --
apiVersion: v1
kind: Secret
metadata:
name: post-init-sql-secret
stringData:
secret.sql: |
create table secrets (i integer);
insert into secrets (select generate_series(1,10000));
- --
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example-initdb
spec:
instances: 3
bootstrap:
initdb:
database: appdb
owner: appuser
postInitSQL:
- create table numbers (i integer)
- insert into numbers (select generate_series(1,10000))
postInitTemplateSQL:
- create extension intarray
postInitApplicationSQL:
- create table application_numbers (i integer)
- insert into application_numbers (select generate_series(1,10000))
postInitApplicationSQLRefs:
configMapRefs:
- name: post-init-sql-configmap
key: configmap.sql
secretRefs:
- name: post-init-sql-secret
key: secret.sql
storage:
size: 1Gi
cluster-example-pg-hba.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example
spec:
instances: 3
postgresql:
pg_hba:
- hostssl app all all cert
storage:
size: 1Gi
cluster-example-projected-volume.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example-projected-volume
spec:
instances: 3
projectedVolumeTemplate:
sources:
- secret:
name: sample-secret
items:
- key: tls.crt
path: certificate/tls.crt
- key: tls.key
path: certificate/tls.key
- configMap:
name: sample-configmap
items:
- key: key1
path: config/key1
- key: key2
path: config/key2
storage:
size: 1Gi
- --
apiVersion: v1
data:
tls.crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNQekNDQWVXZ0F3SUJBZ0lRSHVDY2lKcDVkZis0dHZBcDBrTk9rekFLQmdncWhrak9QUVFEQWpCTk1TTXcKSVFZRFZRUUxFeHB3YjNOMFozSmxjM0ZzTFc5d1pYSmhkRzl5TFhONWMzUmxiVEVtTUNRR0ExVUVBeE1kY0c5egpkR2R5WlhOeGJDMXZjR1Z5WVhSdmNpMWpZUzF6WldOeVpYUXdIaGNOTWpJd09USTVNRGMxTVRBNVdoY05Nakl4Ck1qSTRNRGMxTVRBNVdqQk5NVXN3U1FZRFZRUURFMEp3YjNOMFozSmxjM0ZzTFc5d1pYSmhkRzl5TFhkbFltaHYKYjJzdGMyVnlkbWxqWlM1d2IzTjBaM0psYzNGc0xXOXdaWEpoZEc5eUxYTjVjM1JsYlM1emRtTXdXVEFUQmdjcQpoa2pPUFFJQkJnZ3Foa2pPUFFNQkJ3TkNBQVJRd2lhUm0wSmN4TzlBVlE0MVlqVlRqNUhDSVVFblFQOXNZRXFKCmYvNE1mVm53NkdDOThjNDNmQTVuS2UwSnQ5ZEV3QXREYktkdkRoeDlUTmIzdVY0K280R21NSUdqTUE0R0ExVWQKRHdFQi93UUVBd0lEcURBVEJnTlZIU1VFRERBS0JnZ3JCZ0VGQlFjREFUQU1CZ05WSFJNQkFmOEVBakFBTUI4RwpBMVVkSXdRWU1CYUFGQjN6cUVKbWFORENoRDdkWGptSWRlNEhUY0pFTUUwR0ExVWRFUVJHTUVTQ1FuQnZjM1JuCmNtVnpjV3d0YjNCbGNtRjBiM0l0ZDJWaWFHOXZheTF6WlhKMmFXTmxMbkJ2YzNSbmNtVnpjV3d0YjNCbGNtRjAKYjNJdGMzbHpkR1Z0TG5OMll6QUtCZ2dxaGtqT1BRUURBZ05JQURCRkFpQkMwS2M5WWxYelBpL0lhTkRnWHkwawpYTDJpNlZzSHRORTFxN3MzWXh6Mm53SWhBS2IxUW5EVTlqRnNVK0l5a292TitVU1ZpVm5vU2MvZ2RXWkxmMnhoCjZ2WUsKLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo=
tls.key: LS0tLS1CRUdJTiBFQyBQUklWQVRFIEtFWS0tLS0tCk1IY0NBUUVFSUtucWxVQjFqU2sxWW5VZzAyb0tGbXlRdDJLUEZwaFc0K1lmQUFmUFdRenVvQW9HQ0NxR1NNNDkKQXdFSG9VUURRZ0FFVU1JbWtadENYTVR2UUZVT05XSTFVNCtSd2lGQkowRC9iR0JLaVgvK0RIMVo4T2hndmZITwpOM3dPWnludENiZlhSTUFMUTJ5bmJ3NGNmVXpXOTdsZVBnPT0KLS0tLS1FTkQgRUMgUFJJVkFURSBLRVktLS0tLQo=
kind: Secret
metadata:
name: sample-secret
type: kubernetes.io/tls
- --
apiVersion: v1
data:
key1: value1
key2: value2
key3: value3
kind: ConfigMap
metadata:
name: sample-configmap
cluster-example-tde.yaml#
- --
apiVersion: v1
kind: Secret
metadata:
name: tde-key
data:
key: bG9zcG9sbGl0b3NkaWNlbnBpb3Bpb3Bpb2N1YW5kb3RpZW5lbmhhbWJyZWN1YW5kb3RpZW5lbmZyaW8=
- --
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example
spec:
instances: 3
imageName: docker.enterprisedb.com/k8s/edb-postgres-advanced:18-standard-ubi9
postgresql:
epas:
tde:
enabled: true
secretKeyRef:
name: tde-key
key: key
storage:
size: 1Gi
cluster-example-security-context.yaml#
# Example of PostgreSQL cluster with custom security contexts
#
# This example demonstrates how to customize both PodSecurityContext and
# Container SecurityContext for a PostgreSQL cluster. This is particularly
# useful when working with Pod Security Standards (PSS) or when you need
# to meet specific security requirements.
#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-security-context
spec:
instances: 3
# Storage configuration
storage:
size: 1Gi
# Custom PodSecurityContext
# This will be applied to all pods in the cluster and merged with operator defaults.
# Only RunAsUser, RunAsGroup, and SeccompProfile are merged from defaults if not specified.
podSecurityContext:
runAsUser: 26
runAsGroup: 26
fsGroup: 26
runAsNonRoot: true
supplementalGroups: [1000, 2000]
fsGroupChangePolicy: "OnRootMismatch"
# Custom Container SecurityContext
# This will be applied to all containers in the cluster pods and merged with operator defaults.
# The operator provides secure defaults for all fields, which will be used if not explicitly set.
securityContext:
allowPrivilegeEscalation: false
# Note: capabilities are not merged with operator defaults.
# If specified, they fully replace any defaults.
capabilities:
drop:
- ALL
add:
- NET_BIND_SERVICE
privileged: false
readOnlyRootFilesystem: true
runAsNonRoot: true
cluster-storage-class-with-backup.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: pg-backup
spec:
instances: 3
# Example of rolling update strategy:
# - unsupervised: automated update of the primary once all
# replicas have been upgraded (default)
# - supervised: requires manual supervision to perform
# the switchover of the primary
primaryUpdateStrategy: unsupervised
# Persistent storage configuration
storage:
storageClass: standard
size: 1Gi
# Backup properties
backup:
barmanObjectStore:
destinationPath: s3://BUCKET_NAME/path/to/folder
s3Credentials:
accessKeyId:
name: aws-creds
key: ACCESS_KEY_ID
secretAccessKey:
name: aws-creds
key: ACCESS_SECRET_KEY
wal:
compression: gzip
backup-example.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Backup
metadata:
name: pg-backup-example
spec:
cluster:
name: pg-backup
cluster-example-with-backup.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example-with-backup
spec:
instances: 3
primaryUpdateStrategy: unsupervised
# Persistent storage configuration
storage:
storageClass: csi-hostpath-sc
size: 1Gi
# Backup properties
# This assumes a local minio setup
backup:
barmanObjectStore:
destinationPath: s3://backups/
endpointURL: http://minio:9000
s3Credentials:
accessKeyId:
name: minio
key: ACCESS_KEY_ID
secretAccessKey:
name: minio
key: ACCESS_SECRET_KEY
wal:
compression: gzip
data:
additionalCommandArgs:
- "--min-chunk-size=5MB"
- "--read-timeout=60"
- "-vv"
cluster-example-with-backup-scaleway.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: pg-backup-scaleway
spec:
instances: 3
storage:
storageClass: standard
size: 1Gi
backup:
barmanObjectStore:
destinationPath: "s3://<bucket>/backups/" # change <bucket> with your buckets name.
endpointURL: "https://s3.<region>.scw.cloud" # change <region> with your buckets location/region.
s3Credentials:
accessKeyId:
name: scaleway
key: ACCESS_KEY_ID
secretAccessKey:
name: scaleway
key: ACCESS_SECRET_KEY
region:
name: scaleway
key: ACCESS_REGION
cluster-example-trigger-backup.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Backup
metadata:
name: cluster-example-trigger-backup
spec:
cluster:
name: cluster-example-with-backup
cluster-example-replica-from-backup-simple.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example-replica-from-backup-simple
spec:
instances: 1
bootstrap:
recovery:
source: cluster-example-backup
replica:
enabled: true
source: cluster-example-backup
storage:
size: 1Gi
externalClusters:
- name: cluster-example-backup
barmanObjectStore:
destinationPath: s3://backups/
endpointURL: http://minio:9000
s3Credentials:
accessKeyId:
name: minio
key: ACCESS_KEY_ID
secretAccessKey:
name: minio
key: ACCESS_SECRET_KEY
cluster-example-with-volume-snapshot.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example-with-volume-snapshot
spec:
instances: 3
primaryUpdateStrategy: unsupervised
# Persistent storage configuration
storage:
storageClass: csi-hostpath-sc
size: 1Gi
walStorage:
storageClass: csi-hostpath-sc
size: 1Gi
# Backup properties
backup:
volumeSnapshot:
className: csi-hostpath-snapclass
barmanObjectStore:
destinationPath: s3://backups/
endpointURL: http://minio:9000
s3Credentials:
accessKeyId:
name: minio
key: ACCESS_KEY_ID
secretAccessKey:
name: minio
key: ACCESS_SECRET_KEY
wal:
compression: gzip
backup-with-volume-snapshot.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Backup
metadata:
name: backup-with-volume-snapshot
spec:
method: volumeSnapshot
cluster:
name: cluster-example-with-volume-snapshot
cluster-example-replica-from-volume-snapshot.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example-replica-from-snapshot
spec:
instances: 1
storage:
storageClass: csi-hostpath-sc
size: 1Gi
walStorage:
storageClass: csi-hostpath-sc
size: 1Gi
bootstrap:
recovery:
source: cluster-example-with-volume-snapshot
volumeSnapshots:
storage:
name: cluster-example-with-volume-snapshot-2-1692618163
kind: VolumeSnapshot
apiGroup: snapshot.storage.k8s.io
walStorage:
name: cluster-example-with-volume-snapshot-2-wal-1692618163
kind: VolumeSnapshot
apiGroup: snapshot.storage.k8s.io
replica:
enabled: true
source: cluster-example-with-volume-snapshot
externalClusters:
- name: cluster-example-with-volume-snapshot
connectionParameters:
host: cluster-example-with-volume-snapshot-rw.default.svc
user: postgres
dbname: postgres
password:
name: cluster-example-with-volume-snapshot-superuser
key: password
barmanObjectStore:
destinationPath: s3://backups/
endpointURL: http://minio:9000
s3Credentials:
accessKeyId:
name: minio
key: ACCESS_KEY_ID
secretAccessKey:
name: minio
key: ACCESS_SECRET_KEY
wal:
maxParallel: 8
cluster-example-replica-streaming.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-replica-example
spec:
instances: 1
bootstrap:
pg_basebackup:
source: cluster-example
replica:
enabled: true
source: cluster-example
storage:
size: 1Gi
# note the namespace default in the host name `cluster-example-rw.default.svc`
# remember to change accordingly with the namespace of the main cluster
externalClusters:
- name: cluster-example
connectionParameters:
host: cluster-example-rw.default.svc
user: streaming_replica
sslmode: verify-full
dbname: postgres
# NOTE: if this cluster is created in a different namespace than the main cluster
# remember to create the `-replication` and `-ca` secrets in the follower namespace
# before creating the follower cluster
sslKey:
name: cluster-example-replication
key: tls.key
sslCert:
name: cluster-example-replication
key: tls.crt
sslRootCert:
name: cluster-example-ca
key: ca.crt
postgis-example.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: postgis-example
spec:
imageName: docker.enterprisedb.com/k8s_enterprise/postgresql:18.3-minimal-ubi9
instances: 1
storage:
size: 1Gi
postgresql:
extensions:
- name: postgis
image:
reference: ghcr.io/cloudnative-pg/postgis-extension:3.6.1-18-trixie
ld_library_path:
- system
- --
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Database
metadata:
name: postgis-example-app
spec:
name: app
owner: app
cluster:
name: postgis-example
extensions:
- name: postgis
version: 3.6.1
- name: postgis_raster
- name: postgis_sfcgal
- name: fuzzystrmatch
- name: address_standardizer
- name: address_standardizer_data_us
- name: postgis_tiger_geocoder
- name: postgis_topology
cluster-example-with-roles.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example-with-roles
spec:
instances: 3
storage:
size: 1Gi
managed:
roles:
- name: app
createdb: true
login: true
- name: dante
ensure: present
comment: my database-side comment
login: true
superuser: false
createdb: true
createrole: false
inherit: false
replication: false
bypassrls: false
connectionLimit: 4
validUntil: "2053-04-12T15:04:05Z"
inRoles:
- pg_monitor
- pg_signal_backend
passwordSecret:
name: cluster-example-dante
- --
apiVersion: v1
data:
username: ZGFudGU=
password: ZGFudGU=
kind: Secret
metadata:
name: cluster-example-dante
type: kubernetes.io/basic-auth
cluster-example-managed-services.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example-managed-services
spec:
instances: 1
storage:
size: 1Gi
managed:
services:
## disable the default services
disabledDefaultServices: ["ro", "r"]
additional:
- selectorType: rw
serviceTemplate:
metadata:
name: "test-rw"
labels:
test-label: "true"
annotations:
test-annotation: "true"
spec:
type: LoadBalancer
cluster-example-with-tablespaces.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example-with-tablespaces
spec:
instances: 3
storage:
size: 1Gi
tablespaces:
- name: atablespace
storage:
size: 1Gi
storageClass: standard
temporary: true
- name: another_tablespace
storage:
size: 2Gi
storageClass: standard
temporary: true
- name: tablespacea1
storage:
size: 2Gi
storageClass: standard
cluster-example-with-tablespaces-backup.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example-with-tablespaces
spec:
instances: 3
storage:
size: 1Gi
backup:
barmanObjectStore:
destinationPath: s3://backups/
endpointURL: http://minio:9000
s3Credentials:
accessKeyId:
name: minio
key: ACCESS_KEY_ID
secretAccessKey:
name: minio
key: ACCESS_SECRET_KEY
wal:
compression: gzip
tablespaces:
- name: atablespace
storage:
size: 1Gi
storageClass: standard
- name: another_tablespace
storage:
size: 2Gi
storageClass: standard
- name: tablespacea1
storage:
size: 2Gi
storageClass: standard
cluster-restore-with-tablespaces.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-restore-with-tablespaces
spec:
instances: 3
storage:
size: 1Gi
bootstrap:
recovery:
backup:
name: cluster-example-with-tablespaces-20231128093940
tablespaces:
atablespace:
storage:
size: 1Gi
storageClass: standard
another_tablespace:
storage:
size: 2Gi
storageClass: standard
tablespacea1:
storage:
size: 2Gi
storageClass: standard
pooler-external.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Pooler
metadata:
name: pooler-example-rw
spec:
cluster:
name: cluster-example
instances: 3
type: rw
serviceTemplate:
metadata:
labels:
app: pooler
spec:
type: LoadBalancer
pgbouncer:
poolMode: session
parameters:
max_client_conn: "1000"
default_pool_size: "10"
cluster-example-logical-source.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example
spec:
instances: 3
imageName: docker.enterprisedb.com/k8s/postgresql:18-standard-ubi9
storage:
size: 1Gi
bootstrap:
initdb:
postInitApplicationSQL:
- CREATE TABLE numbers (i SERIAL PRIMARY KEY, m INTEGER)
- INSERT INTO numbers (m) (SELECT generate_series(1,10000))
- ALTER TABLE numbers OWNER TO app
- CREATE TABLE numbers_two (i SERIAL PRIMARY KEY, m INTEGER)
- INSERT INTO numbers_two (m) (SELECT generate_series(1,10000))
- ALTER TABLE numbers_two OWNER TO app
- CREATE SCHEMA another_schema
- ALTER SCHEMA another_schema OWNER TO app
- CREATE TABLE another_schema.numbers_three (i SERIAL PRIMARY KEY, m INTEGER)
- INSERT INTO another_schema.numbers_three (m) (SELECT generate_series(1,10000))
- ALTER TABLE another_schema.numbers_three OWNER TO app
replicationSlots:
highAvailability:
synchronizeLogicalDecoding: true
managed:
roles:
- name: app
login: true
replication: true
postgresql:
parameters:
hot_standby_feedback: on
sync_replication_slots: on
- --
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Publication
metadata:
name: cluster-example-pub
spec:
name: pub
dbname: app
cluster:
name: cluster-example
target:
allTables: true
cluster-example-logical-destination.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Cluster
metadata:
name: cluster-example-dest
spec:
instances: 1
storage:
size: 1Gi
bootstrap:
initdb:
import:
type: microservice
schemaOnly: true
databases:
- app
source:
externalCluster: cluster-example
externalClusters:
- name: cluster-example
connectionParameters:
host: cluster-example-rw.default.svc
user: app
dbname: app
password:
name: cluster-example-app
key: password
- --
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Subscription
metadata:
name: cluster-example-dest-sub
spec:
cluster:
name: cluster-example-dest
name: sub
dbname: app
publicationName: pub
externalClusterName: cluster-example
parameters:
failover: true
Publication-example.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Publication
metadata:
name: publication-example
spec:
cluster:
name: cluster-example
name: pub-all
dbname: app
target:
allTables: true
Publication-example-objects.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Publication
metadata:
name: publication-example-objects
spec:
cluster:
name: cluster-example
name: pub-objects
dbname: app
target:
objects:
- tablesInSchema: public
- table:
schema: another_schema
name: numbers_three
only: true
subscription-example.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Subscription
metadata:
name: subscription-sample
spec:
name: sub
dbname: app
publicationName: pub-all
cluster:
name: cluster-example-dest
externalClusterName: cluster-example
Database-example.yaml#
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Database
metadata:
name: db-one
spec:
name: one
owner: app
cluster:
name: cluster-example
Database-example-icu.yaml#
# NOTE: this manifest will only work properly if the Postgres version supports
# ICU locales and rules (version 16 and newer)
apiVersion: postgresql.k8s.enterprisedb.io/v1
kind: Database
metadata:
name: db-icu
spec:
name: declarative-icu
owner: app
encoding: UTF8
localeProvider: icu
icuLocale: en
icuRules: fr
template: template0
cluster:
name: cluster-example