The dump assumed the official image's environment and the postgres superuser. Bitnami keeps its passwords in files, and on this cluster the superuser password no longer matches the database, so the Gitea database backup would have failed. The collector now resolves the credentials from either layout, probes them before dumping so a failed login cannot truncate the archive, and falls back to a single-database dump when only the application user works. Verified against both databases on the server. Also adds the Nextcloud manifest that installs it on the cluster. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
218 lines
5.6 KiB
YAML
218 lines
5.6 KiB
YAML
# Nextcloud on microk8s, published on the host's public port 4444.
|
|
# The labels follow the Kubernetes recommended set, so the monitoring app groups the
|
|
# deployment and its database into one application on the backup page.
|
|
apiVersion: v1
|
|
kind: Namespace
|
|
metadata:
|
|
name: nextcloud
|
|
---
|
|
apiVersion: v1
|
|
kind: Secret
|
|
metadata:
|
|
name: nextcloud
|
|
namespace: nextcloud
|
|
type: Opaque
|
|
stringData:
|
|
POSTGRES_PASSWORD: "__DB_PASSWORD__"
|
|
NEXTCLOUD_ADMIN_PASSWORD: "__ADMIN_PASSWORD__"
|
|
---
|
|
apiVersion: apps/v1
|
|
kind: StatefulSet
|
|
metadata:
|
|
name: nextcloud-postgresql
|
|
namespace: nextcloud
|
|
labels:
|
|
app.kubernetes.io/instance: nextcloud
|
|
app.kubernetes.io/name: postgresql
|
|
spec:
|
|
serviceName: nextcloud-postgresql
|
|
replicas: 1
|
|
selector:
|
|
matchLabels:
|
|
app.kubernetes.io/instance: nextcloud
|
|
app.kubernetes.io/name: postgresql
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/instance: nextcloud
|
|
app.kubernetes.io/name: postgresql
|
|
spec:
|
|
containers:
|
|
- name: postgresql
|
|
image: postgres:17-alpine
|
|
env:
|
|
- name: POSTGRES_DB
|
|
value: nextcloud
|
|
- name: POSTGRES_USER
|
|
value: nextcloud
|
|
- name: POSTGRES_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: nextcloud
|
|
key: POSTGRES_PASSWORD
|
|
- name: PGDATA
|
|
value: /var/lib/postgresql/data/pgdata
|
|
ports:
|
|
- containerPort: 5432
|
|
name: postgresql
|
|
readinessProbe:
|
|
exec:
|
|
command: ["pg_isready", "-U", "nextcloud", "-d", "nextcloud"]
|
|
initialDelaySeconds: 10
|
|
periodSeconds: 10
|
|
resources:
|
|
requests:
|
|
cpu: 50m
|
|
memory: 128Mi
|
|
limits:
|
|
memory: 512Mi
|
|
volumeMounts:
|
|
- name: data
|
|
mountPath: /var/lib/postgresql/data
|
|
volumeClaimTemplates:
|
|
- metadata:
|
|
name: data
|
|
spec:
|
|
accessModes: [ReadWriteOnce]
|
|
storageClassName: microk8s-hostpath
|
|
resources:
|
|
requests:
|
|
storage: 8Gi
|
|
---
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: nextcloud-postgresql
|
|
namespace: nextcloud
|
|
labels:
|
|
app.kubernetes.io/instance: nextcloud
|
|
app.kubernetes.io/name: postgresql
|
|
spec:
|
|
selector:
|
|
app.kubernetes.io/instance: nextcloud
|
|
app.kubernetes.io/name: postgresql
|
|
ports:
|
|
- port: 5432
|
|
targetPort: postgresql
|
|
---
|
|
apiVersion: v1
|
|
kind: PersistentVolumeClaim
|
|
metadata:
|
|
name: nextcloud-data
|
|
namespace: nextcloud
|
|
labels:
|
|
app.kubernetes.io/instance: nextcloud
|
|
app.kubernetes.io/name: nextcloud
|
|
spec:
|
|
accessModes: [ReadWriteOnce]
|
|
storageClassName: microk8s-hostpath
|
|
resources:
|
|
requests:
|
|
storage: 20Gi
|
|
---
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: nextcloud
|
|
namespace: nextcloud
|
|
labels:
|
|
app.kubernetes.io/instance: nextcloud
|
|
app.kubernetes.io/name: nextcloud
|
|
spec:
|
|
replicas: 1
|
|
strategy:
|
|
type: Recreate
|
|
selector:
|
|
matchLabels:
|
|
app.kubernetes.io/instance: nextcloud
|
|
app.kubernetes.io/name: nextcloud
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/instance: nextcloud
|
|
app.kubernetes.io/name: nextcloud
|
|
spec:
|
|
containers:
|
|
- name: nextcloud
|
|
image: nextcloud:31-apache
|
|
ports:
|
|
# published on the host's public interface by the CNI portmap plugin
|
|
- containerPort: 80
|
|
hostPort: 4444
|
|
name: http
|
|
env:
|
|
- name: POSTGRES_HOST
|
|
value: nextcloud-postgresql
|
|
- name: POSTGRES_DB
|
|
value: nextcloud
|
|
- name: POSTGRES_USER
|
|
value: nextcloud
|
|
- name: POSTGRES_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: nextcloud
|
|
key: POSTGRES_PASSWORD
|
|
- name: NEXTCLOUD_ADMIN_USER
|
|
value: admin
|
|
- name: NEXTCLOUD_ADMIN_PASSWORD
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: nextcloud
|
|
key: NEXTCLOUD_ADMIN_PASSWORD
|
|
- name: NEXTCLOUD_TRUSTED_DOMAINS
|
|
value: "46.232.248.171:4444 46.232.248.171 localhost"
|
|
- name: PHP_MEMORY_LIMIT
|
|
value: 512M
|
|
- name: PHP_UPLOAD_LIMIT
|
|
value: 2G
|
|
readinessProbe:
|
|
httpGet:
|
|
path: /status.php
|
|
port: http
|
|
httpHeaders:
|
|
- name: Host
|
|
value: localhost
|
|
initialDelaySeconds: 30
|
|
periodSeconds: 15
|
|
failureThreshold: 20
|
|
livenessProbe:
|
|
httpGet:
|
|
path: /status.php
|
|
port: http
|
|
httpHeaders:
|
|
- name: Host
|
|
value: localhost
|
|
initialDelaySeconds: 180
|
|
periodSeconds: 30
|
|
failureThreshold: 6
|
|
resources:
|
|
requests:
|
|
cpu: 100m
|
|
memory: 512Mi
|
|
limits:
|
|
memory: 2Gi
|
|
volumeMounts:
|
|
- name: data
|
|
mountPath: /var/www/html
|
|
volumes:
|
|
- name: data
|
|
persistentVolumeClaim:
|
|
claimName: nextcloud-data
|
|
---
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: nextcloud
|
|
namespace: nextcloud
|
|
labels:
|
|
app.kubernetes.io/instance: nextcloud
|
|
app.kubernetes.io/name: nextcloud
|
|
spec:
|
|
selector:
|
|
app.kubernetes.io/instance: nextcloud
|
|
app.kubernetes.io/name: nextcloud
|
|
ports:
|
|
- port: 80
|
|
targetPort: http
|
|
name: http
|