176 lines
3.4 KiB
YAML
176 lines
3.4 KiB
YAML
fullname: pgadmin
|
|
|
|
image:
|
|
registry: docker.io
|
|
repository: dpage/pgadmin4
|
|
tag: "9.16"
|
|
pullPolicy: IfNotPresent
|
|
|
|
commonLabels:
|
|
app: pgadmin4
|
|
app.kubernetes.io/name: pgadmin4
|
|
app.kubernetes.io/instance: pgadmin
|
|
app.kubernetes.io/component: database-admin
|
|
app.kubernetes.io/part-of: platform
|
|
|
|
replicas: 1
|
|
strategy:
|
|
type: Recreate
|
|
|
|
containerPort: 5050
|
|
disablePostfix: true
|
|
enableServiceLinks: false
|
|
|
|
auth:
|
|
email: platform-admin@hyeonworks.com
|
|
existingSecret: pgadmin-bootstrap
|
|
passwordKey: password
|
|
|
|
extraEnvVars:
|
|
- name: PGADMIN_OIDC_CLIENT_ID
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: pgadmin-keycloak-oidc
|
|
key: client-id
|
|
- name: PGADMIN_OIDC_CLIENT_SECRET
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: pgadmin-keycloak-oidc
|
|
key: client-secret
|
|
- name: PGADMIN_REPLACE_SERVERS_ON_STARTUP
|
|
value: "True"
|
|
|
|
config_local:
|
|
enabled: false
|
|
|
|
extraVolumes:
|
|
- name: config-local
|
|
configMap:
|
|
name: pgadmin-config
|
|
defaultMode: 292
|
|
items:
|
|
- key: config_local.py
|
|
path: config_local.py
|
|
|
|
extraVolumeMounts:
|
|
- name: config-local
|
|
mountPath: /pgadmin4/config_local.py
|
|
subPath: config_local.py
|
|
readOnly: true
|
|
|
|
serverDefinitions:
|
|
enabled: true
|
|
data:
|
|
"1":
|
|
Name: Hyeonworks Gitea
|
|
Group: Platform
|
|
Host: platform-postgres-rw.platform-data.svc.cluster.local
|
|
Port: 5432
|
|
MaintenanceDB: gitea
|
|
Username: gitea
|
|
Shared: true
|
|
SharedUsername: gitea
|
|
ConnectionParameters:
|
|
sslmode: require
|
|
connect_timeout: 10
|
|
"2":
|
|
Name: Hyeonworks Keycloak
|
|
Group: Platform
|
|
Host: platform-postgres-rw.platform-data.svc.cluster.local
|
|
Port: 5432
|
|
MaintenanceDB: keycloak
|
|
Username: keycloak
|
|
Shared: true
|
|
SharedUsername: keycloak
|
|
ConnectionParameters:
|
|
sslmode: require
|
|
connect_timeout: 10
|
|
|
|
resources:
|
|
requests:
|
|
cpu: 250m
|
|
memory: 512Mi
|
|
limits:
|
|
cpu: "1"
|
|
memory: 1Gi
|
|
|
|
persistence:
|
|
enabled: true
|
|
size: 2Gi
|
|
storageClass: ssd-local-pgadmin-retain
|
|
accessModes:
|
|
- ReadWriteOnce
|
|
|
|
service:
|
|
type: ClusterIP
|
|
port: 80
|
|
|
|
serviceAccount:
|
|
create: true
|
|
automountServiceAccountToken: false
|
|
|
|
ingress:
|
|
enabled: true
|
|
hostname: db-admin.learn.hyeonworks.com
|
|
annotations:
|
|
kubernetes.io/ingress.class: traefik
|
|
traefik.ingress.kubernetes.io/router.entrypoints: web
|
|
tlsSecret: ""
|
|
|
|
startupProbe:
|
|
enabled: true
|
|
httpGet:
|
|
path: /misc/ping
|
|
port: http
|
|
httpHeaders:
|
|
- name: Host
|
|
value: db-admin.learn.hyeonworks.com
|
|
periodSeconds: 10
|
|
timeoutSeconds: 3
|
|
failureThreshold: 30
|
|
|
|
readinessProbe:
|
|
enabled: true
|
|
httpGet:
|
|
path: /misc/ping
|
|
port: http
|
|
httpHeaders:
|
|
- name: Host
|
|
value: db-admin.learn.hyeonworks.com
|
|
periodSeconds: 10
|
|
timeoutSeconds: 3
|
|
failureThreshold: 6
|
|
|
|
livenessProbe:
|
|
enabled: true
|
|
httpGet:
|
|
path: /misc/ping
|
|
port: http
|
|
httpHeaders:
|
|
- name: Host
|
|
value: db-admin.learn.hyeonworks.com
|
|
periodSeconds: 20
|
|
timeoutSeconds: 3
|
|
failureThreshold: 6
|
|
|
|
podSecurityContext:
|
|
enabled: true
|
|
fsGroupChangePolicy: OnRootMismatch
|
|
fsGroup: 1001
|
|
|
|
containerSecurityContext:
|
|
enabled: true
|
|
runAsUser: 1001
|
|
runAsGroup: 1001
|
|
runAsNonRoot: true
|
|
privileged: false
|
|
readOnlyRootFilesystem: true
|
|
allowPrivilegeEscalation: false
|
|
capabilities:
|
|
drop:
|
|
- ALL
|
|
seccompProfile:
|
|
type: RuntimeDefault
|
|
appArmorProfile:
|
|
type: RuntimeDefault
|