Dump PostgreSQL pods whatever image they run

The dump assumed the official image's environment and the postgres
superuser. Bitnami keeps its passwords in files, and on this cluster the
superuser password no longer matches the database, so the Gitea database
backup would have failed. The collector now resolves the credentials from
either layout, probes them before dumping so a failed login cannot
truncate the archive, and falls back to a single-database dump when only
the application user works. Verified against both databases on the server.

Also adds the Nextcloud manifest that installs it on the cluster.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-03 21:32:43 +02:00
parent 8f5bc1755e
commit 1339ae864e
3 changed files with 284 additions and 4 deletions

217
deploy/nextcloud.yaml Normal file
View File

@ -0,0 +1,217 @@
# Nextcloud on microk8s, published on the host's public port 4444.
# The labels follow the Kubernetes recommended set, so the monitoring app groups the
# deployment and its database into one application on the backup page.
apiVersion: v1
kind: Namespace
metadata:
name: nextcloud
---
apiVersion: v1
kind: Secret
metadata:
name: nextcloud
namespace: nextcloud
type: Opaque
stringData:
POSTGRES_PASSWORD: "__DB_PASSWORD__"
NEXTCLOUD_ADMIN_PASSWORD: "__ADMIN_PASSWORD__"
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: nextcloud-postgresql
namespace: nextcloud
labels:
app.kubernetes.io/instance: nextcloud
app.kubernetes.io/name: postgresql
spec:
serviceName: nextcloud-postgresql
replicas: 1
selector:
matchLabels:
app.kubernetes.io/instance: nextcloud
app.kubernetes.io/name: postgresql
template:
metadata:
labels:
app.kubernetes.io/instance: nextcloud
app.kubernetes.io/name: postgresql
spec:
containers:
- name: postgresql
image: postgres:17-alpine
env:
- name: POSTGRES_DB
value: nextcloud
- name: POSTGRES_USER
value: nextcloud
- name: POSTGRES_PASSWORD
valueFrom:
secretKeyRef:
name: nextcloud
key: POSTGRES_PASSWORD
- name: PGDATA
value: /var/lib/postgresql/data/pgdata
ports:
- containerPort: 5432
name: postgresql
readinessProbe:
exec:
command: ["pg_isready", "-U", "nextcloud", "-d", "nextcloud"]
initialDelaySeconds: 10
periodSeconds: 10
resources:
requests:
cpu: 50m
memory: 128Mi
limits:
memory: 512Mi
volumeMounts:
- name: data
mountPath: /var/lib/postgresql/data
volumeClaimTemplates:
- metadata:
name: data
spec:
accessModes: [ReadWriteOnce]
storageClassName: microk8s-hostpath
resources:
requests:
storage: 8Gi
---
apiVersion: v1
kind: Service
metadata:
name: nextcloud-postgresql
namespace: nextcloud
labels:
app.kubernetes.io/instance: nextcloud
app.kubernetes.io/name: postgresql
spec:
selector:
app.kubernetes.io/instance: nextcloud
app.kubernetes.io/name: postgresql
ports:
- port: 5432
targetPort: postgresql
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: nextcloud-data
namespace: nextcloud
labels:
app.kubernetes.io/instance: nextcloud
app.kubernetes.io/name: nextcloud
spec:
accessModes: [ReadWriteOnce]
storageClassName: microk8s-hostpath
resources:
requests:
storage: 20Gi
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: nextcloud
namespace: nextcloud
labels:
app.kubernetes.io/instance: nextcloud
app.kubernetes.io/name: nextcloud
spec:
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/instance: nextcloud
app.kubernetes.io/name: nextcloud
template:
metadata:
labels:
app.kubernetes.io/instance: nextcloud
app.kubernetes.io/name: nextcloud
spec:
containers:
- name: nextcloud
image: nextcloud:31-apache
ports:
# published on the host's public interface by the CNI portmap plugin
- containerPort: 80
hostPort: 4444
name: http
env:
- name: POSTGRES_HOST
value: nextcloud-postgresql
- name: POSTGRES_DB
value: nextcloud
- name: POSTGRES_USER
value: nextcloud
- name: POSTGRES_PASSWORD
valueFrom:
secretKeyRef:
name: nextcloud
key: POSTGRES_PASSWORD
- name: NEXTCLOUD_ADMIN_USER
value: admin
- name: NEXTCLOUD_ADMIN_PASSWORD
valueFrom:
secretKeyRef:
name: nextcloud
key: NEXTCLOUD_ADMIN_PASSWORD
- name: NEXTCLOUD_TRUSTED_DOMAINS
value: "46.232.248.171:4444 46.232.248.171 localhost"
- name: PHP_MEMORY_LIMIT
value: 512M
- name: PHP_UPLOAD_LIMIT
value: 2G
readinessProbe:
httpGet:
path: /status.php
port: http
httpHeaders:
- name: Host
value: localhost
initialDelaySeconds: 30
periodSeconds: 15
failureThreshold: 20
livenessProbe:
httpGet:
path: /status.php
port: http
httpHeaders:
- name: Host
value: localhost
initialDelaySeconds: 180
periodSeconds: 30
failureThreshold: 6
resources:
requests:
cpu: 100m
memory: 512Mi
limits:
memory: 2Gi
volumeMounts:
- name: data
mountPath: /var/www/html
volumes:
- name: data
persistentVolumeClaim:
claimName: nextcloud-data
---
apiVersion: v1
kind: Service
metadata:
name: nextcloud
namespace: nextcloud
labels:
app.kubernetes.io/instance: nextcloud
app.kubernetes.io/name: nextcloud
spec:
selector:
app.kubernetes.io/instance: nextcloud
app.kubernetes.io/name: nextcloud
ports:
- port: 80
targetPort: http
name: http