fix: legacy container needs pg_hba.conf replication rule for pg_basebackup — added initdb.d hook script. Disposable test only, uses 'trust' since this container is not auth-representative.
ci/woodpecker/push/deploy Pipeline was successful
ci/woodpecker/push/deploy Pipeline was successful
This commit is contained in:
@@ -16,7 +16,8 @@
|
|||||||
# NOTE: command: blocks use $$(...) not $(...) — Compose's own variable
|
# NOTE: command: blocks use $$(...) not $(...) — Compose's own variable
|
||||||
# interpolation parses $( as an attempted ${VAR} reference and fails with
|
# interpolation parses $( as an attempted ${VAR} reference and fails with
|
||||||
# "invalid interpolation format" / "you may need to escape any $ with
|
# "invalid interpolation format" / "you may need to escape any $ with
|
||||||
# another $". $$ escapes to a literal $ for the shell at runtime.
|
# another $". $$ escapes to a literal $ for the shell at runtime. Same
|
||||||
|
# reasoning applies to $$PGDATA below.
|
||||||
#
|
#
|
||||||
# NOTE: ETCD3_HOSTS not ETCD_HOSTS — confirmed against zalando/spilo
|
# NOTE: ETCD3_HOSTS not ETCD_HOSTS — confirmed against zalando/spilo
|
||||||
# configure_spilo.py: PATRONI_DCS includes both "etcd" (legacy v2 API,
|
# configure_spilo.py: PATRONI_DCS includes both "etcd" (legacy v2 API,
|
||||||
@@ -25,6 +26,20 @@
|
|||||||
# (v3.5.9) have the v2 API disabled by default, so ETCD_HOSTS causes
|
# (v3.5.9) have the v2 API disabled by default, so ETCD_HOSTS causes
|
||||||
# Patroni to hit /v2 endpoints that 404. ETCD3_HOSTS selects the correct
|
# Patroni to hit /v2 endpoints that 404. ETCD3_HOSTS selects the correct
|
||||||
# v3-API client.
|
# v3-API client.
|
||||||
|
#
|
||||||
|
# NOTE: "legacy" needs a pg_hba.conf rule permitting REPLICATION-type
|
||||||
|
# connections, which is a distinct connection class from normal client
|
||||||
|
# connections in Postgres. The vanilla postgres:17 image's default
|
||||||
|
# pg_hba.conf allows normal client connections (pg_dumpall worked earlier)
|
||||||
|
# but NOT replication connections, which pg_basebackup (used by Patroni's
|
||||||
|
# CLONE_WITH_BASEBACKUP) requires. Fixed via a /docker-entrypoint-initdb.d/
|
||||||
|
# hook script (the officially supported extension point, runs once right
|
||||||
|
# after initdb, before the server's final restart) that appends a
|
||||||
|
# permissive "trust" rule for replication connections. "trust" is
|
||||||
|
# acceptable ONLY because this container is fully disposable and exists
|
||||||
|
# solely to validate cutover mechanics, not auth. See the note
|
||||||
|
# "ADR-0001 Addendum — pg_hba.conf replication prerequisite discovered in
|
||||||
|
# dry run" for the real production prerequisite this exposes.
|
||||||
# ─────────────────────────────────────────────────────────────────────────
|
# ─────────────────────────────────────────────────────────────────────────
|
||||||
version: "3.6"
|
version: "3.6"
|
||||||
|
|
||||||
@@ -34,7 +49,16 @@ services:
|
|||||||
legacy:
|
legacy:
|
||||||
image: public.ecr.aws/docker/library/postgres:17
|
image: public.ecr.aws/docker/library/postgres:17
|
||||||
hostname: db
|
hostname: db
|
||||||
command: [postgres]
|
entrypoint: ["/bin/sh", "-c"]
|
||||||
|
command:
|
||||||
|
- |
|
||||||
|
mkdir -p /docker-entrypoint-initdb.d
|
||||||
|
cat > /docker-entrypoint-initdb.d/zz-enable-replication.sh <<'EOF'
|
||||||
|
#!/bin/sh
|
||||||
|
echo "host replication all all trust" >> "$$PGDATA/pg_hba.conf"
|
||||||
|
EOF
|
||||||
|
chmod +x /docker-entrypoint-initdb.d/zz-enable-replication.sh
|
||||||
|
exec docker-entrypoint.sh postgres
|
||||||
environment:
|
environment:
|
||||||
POSTGRES_USER: PGadmin
|
POSTGRES_USER: PGadmin
|
||||||
POSTGRES_PASSWORD_FILE: /run/secrets/postgresql_password
|
POSTGRES_PASSWORD_FILE: /run/secrets/postgresql_password
|
||||||
|
|||||||
Reference in New Issue
Block a user