Skip to content

DC-DR: client-deployable provisioner/ops-manager charts (values-gated enablement + RBAC) - #2396

Merged
souravbiswassanto merged 6 commits into
masterfrom
dc-dr-review
Oct 7, 2026
Merged

souravbiswassanto merged 6 commits into
masterfrom
dc-dr-review

Conversation

@tamalsaha

@tamalsaha tamalsaha commented Jul 18, 2026 •

Copy link
Copy Markdown
Member

Part of the KubeDB Postgres cross data center disaster recovery (DC-DR) effort. Makes the DC-DR-enabled operators client-deployable from the charts.

What this adds

  • kubedb-provisioner: values-gated DC-DR enablement (values.yaml dcDR.*), the DC-DR orchestrator flags/env on the provisioner StatefulSet (templates/statefulset.yaml), and the extra RBAC the hub orchestrator needs (templates/cluster-role.yaml).
  • kubedb-ops-manager: allow patch on placementpolicies (templates/cluster-role.yaml) for the per-DC horizontal-scaling path.

Follow-ups found during live testing (documented in the prompt-library journal; not yet in this branch)

  • The provisioner AND the ops-manager StatefulSets both need imagePullSecrets set, or a rollout to a private-registry image wedges on the spokes (401 anonymous pull). Currently only some of the workloads carry it.
  • Each DC-DR Postgres's serviceaccount needs a marker-reader RBAC (Role + RoleBinding in each spoke's dc-failover namespace granting get configmaps on primary-dc), or the coordinator fences read-only ("marker unreadable") and no DC becomes writable. Add a per-DB (or shared) marker-reader binding as part of provisioning a DC-DR Postgres.

One PR per repo; nothing bundled across repos. Companion review branches: postgres #916, pg-coordinator #261, apimachinery #1787, dr-controlplane #1, petset #49 (merged), webhook-server #232.

Summary by CodeRabbit

  • New Features
    • Added optional distributed disaster-recovery failover support for PostgreSQL, including per-data-center configuration and coordination settings.
    • Support can use a coordination-plane credential Secret when configured; otherwise, coordination uses the local cluster.
    • Updated access permissions to support failover coordination and placement-policy management.

… scaling

The DC-DR per-DC horizontal scale renumbers the base PlacementPolicy's
distributionRules after resizing the data centers (postgres pkg/ops
applyDCDRPlacement, CreateOrPatch). The chart already grants get/list/watch;
without patch the scale fails at the renumber step with
'cannot patch resource placementpolicies ... at the cluster scope'.

Signed-off-by: Tamal Saha <tamal@appscode.com>
(cherry picked from commit 3fef6138d912735bd91f1d012ef99d5a686bd6f8)
…able install

Make a fresh install DC-DR-ready with no hand-applied YAML. New dcDR values block
(enabled/localDC/coordKubeconfigSecret, default disabled). When dcDR.enabled:
- the provisioner StatefulSet gets --dc-dr-enabled / --dc-dr-local-dc=<localDC> /
  --dc-dr-coord-kubeconfig=/etc/dr/coord/kubeconfig, plus a read-only mount of the
  coordination-control-plane kubeconfig Secret at /etc/dr/coord (required guards fail
  the render if localDC or coordKubeconfigSecret is unset).
- the provisioner ClusterRole gains placementpolicies get/list/watch/create/patch/delete
  (it expands per-DC PlacementPolicies and GCs the cluster-scoped ones on delete).
When disabled the chart is byte-for-byte unchanged (helm template shows 0 dc-dr lines),
so plain installs are unaffected. Verified with helm template (on and off).

Stacks on the rebased A15 ops-manager placementpolicies patch. dr-controlplane's /.ocm
PVC + agent marker RBAC live in the dr-controlplane chart (its repo, master #4), deployed
alongside; documented in the runbook.

Signed-off-by: Tamal Saha <tamal@appscode.com>
kodiak-appscode[bot]
kodiak-appscode Bot previously approved these changes Jul 18, 2026
The postgres operator (pkg/cmds/server/operator.go) now accepts --dc-dr-coord-qps and
--dc-dr-coord-burst for the coordination control plane client, defaulting to 50/100 in
code. Add optional dcDR.coordQPS/dcDR.coordBurst values that render the flags only when
set, so existing installs are unaffected and larger multi-DB deployments can override the
defaults without a values-schema-breaking change.

Signed-off-by: Tamal Saha <tamal@appscode.com>
@souravbiswassanto
souravbiswassanto marked this pull request as draft August 11, 2026 10:11
@anisurrahman75
anisurrahman75 marked this pull request as ready for review August 18, 2026 11:16
Signed-off-by: souravbiswassanto <saurov@appscode.com>
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 37 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 13d942a6-b01f-4fbd-a2ae-b5e62db27572
📥 Commits

Reviewing files that changed from the base of the PR and between 4dce2fb and 6f98f41.

📒 Files selected for processing (4)
  • charts/kubedb-ops-manager/templates/cluster-role.yaml
  • charts/kubedb-provisioner/templates/cluster-role.yaml
  • charts/kubedb-provisioner/templates/statefulset.yaml
  • charts/kubedb-provisioner/values.yaml

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: ea4d3cf2-45bf-4bba-877f-4ec129921e55
📥 Commits

Reviewing files that changed from the base of the PR and between 146cff0 and 4dce2fb.

📒 Files selected for processing (4)
  • charts/kubedb-ops-manager/templates/cluster-role.yaml
  • charts/kubedb-provisioner/templates/cluster-role.yaml
  • charts/kubedb-provisioner/templates/statefulset.yaml
  • charts/kubedb-provisioner/values.yaml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The provisioner chart adds DC-DR configuration, operator arguments, an optional coordination kubeconfig mount, and conditional RBAC permissions. The ops-manager chart adds patch access to PlacementPolicies.

Changes

DC-DR chart support

Layer / File(s) Summary
Configure DC-DR provisioner
charts/kubedb-provisioner/values.yaml, charts/kubedb-provisioner/templates/cluster-role.yaml, charts/kubedb-provisioner/templates/statefulset.yaml
The chart adds DC-DR values and conditional permissions for ManagedClusters, PostgresOpsRequests, and Leases. When enabled, the operator receives DC-DR arguments. If a coordination kubeconfig Secret is configured, the pod mounts it read-only at /etc/dr/coord.
Grant ops-manager PlacementPolicy patch access
charts/kubedb-ops-manager/templates/cluster-role.yaml
The ClusterRole adds patch to its PlacementPolicy permissions.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Suggested reviewers: sheikh-arman

Merge Risk: ⚪ Minimal · up to 4dce2

No identified issue blocks merging this chart change after normal checks.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the DC-DR chart support and the values-gated enablement and RBAC changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
⚔️ Resolve merge conflicts 💡
  • Resolve merge conflict in branch dc-dr-review
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ArnobKumarSaha
ArnobKumarSaha marked this pull request as draft October 7, 2026 10:07
Signed-off-by: souravbiswassanto <saurov@appscode.com>
@souravbiswassanto
souravbiswassanto marked this pull request as ready for review October 7, 2026 10:20
@souravbiswassanto
souravbiswassanto merged commit 284c4bd into master Oct 7, 2026
4 of 6 checks passed
@souravbiswassanto
souravbiswassanto deleted the dc-dr-review branch October 7, 2026 10:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants