Repository navigation
DC-DR: client-deployable provisioner/ops-manager charts (values-gated enablement + RBAC) - #2396
Conversation
… scaling The DC-DR per-DC horizontal scale renumbers the base PlacementPolicy's distributionRules after resizing the data centers (postgres pkg/ops applyDCDRPlacement, CreateOrPatch). The chart already grants get/list/watch; without patch the scale fails at the renumber step with 'cannot patch resource placementpolicies ... at the cluster scope'. Signed-off-by: Tamal Saha <tamal@appscode.com> (cherry picked from commit 3fef6138d912735bd91f1d012ef99d5a686bd6f8)
…able install Make a fresh install DC-DR-ready with no hand-applied YAML. New dcDR values block (enabled/localDC/coordKubeconfigSecret, default disabled). When dcDR.enabled: - the provisioner StatefulSet gets --dc-dr-enabled / --dc-dr-local-dc=<localDC> / --dc-dr-coord-kubeconfig=/etc/dr/coord/kubeconfig, plus a read-only mount of the coordination-control-plane kubeconfig Secret at /etc/dr/coord (required guards fail the render if localDC or coordKubeconfigSecret is unset). - the provisioner ClusterRole gains placementpolicies get/list/watch/create/patch/delete (it expands per-DC PlacementPolicies and GCs the cluster-scoped ones on delete). When disabled the chart is byte-for-byte unchanged (helm template shows 0 dc-dr lines), so plain installs are unaffected. Verified with helm template (on and off). Stacks on the rebased A15 ops-manager placementpolicies patch. dr-controlplane's /.ocm PVC + agent marker RBAC live in the dr-controlplane chart (its repo, master #4), deployed alongside; documented in the runbook. Signed-off-by: Tamal Saha <tamal@appscode.com>
The postgres operator (pkg/cmds/server/operator.go) now accepts --dc-dr-coord-qps and --dc-dr-coord-burst for the coordination control plane client, defaulting to 50/100 in code. Add optional dcDR.coordQPS/dcDR.coordBurst values that render the flags only when set, so existing installs are unaffected and larger multi-DB deployments can override the defaults without a values-schema-breaking change. Signed-off-by: Tamal Saha <tamal@appscode.com>
Signed-off-by: souravbiswassanto <saurov@appscode.com>
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 37 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (4)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe provisioner chart adds DC-DR configuration, operator arguments, an optional coordination kubeconfig mount, and conditional RBAC permissions. The ops-manager chart adds ChangesDC-DR chart support
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Feature Suggested reviewers: Merge Risk: ⚪ Minimal · up to No identified issue blocks merging this chart change after normal checks. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1⚔️ Resolve merge conflicts 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Signed-off-by: souravbiswassanto <saurov@appscode.com>
Part of the KubeDB Postgres cross data center disaster recovery (DC-DR) effort. Makes the DC-DR-enabled operators client-deployable from the charts.
What this adds
values.yamldcDR.*), the DC-DR orchestrator flags/env on the provisioner StatefulSet (templates/statefulset.yaml), and the extra RBAC the hub orchestrator needs (templates/cluster-role.yaml).patchonplacementpolicies(templates/cluster-role.yaml) for the per-DC horizontal-scaling path.Follow-ups found during live testing (documented in the prompt-library journal; not yet in this branch)
imagePullSecretsset, or a rollout to a private-registry image wedges on the spokes (401 anonymous pull). Currently only some of the workloads carry it.dc-failovernamespace grantingget configmapsonprimary-dc), or the coordinator fences read-only ("marker unreadable") and no DC becomes writable. Add a per-DB (or shared) marker-reader binding as part of provisioning a DC-DR Postgres.One PR per repo; nothing bundled across repos. Companion review branches: postgres #916, pg-coordinator #261, apimachinery #1787, dr-controlplane #1, petset #49 (merged), webhook-server #232.
Summary by CodeRabbit