Update PDB docs for critical-op maxUnavailable semantics

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Juhani Pelli 2026-07-24 18:58:31 +03:00
parent 61e506dea0
commit 187e88e5cd
1 changed files with 7 additions and 4 deletions

View File

@ -639,9 +639,11 @@ masters in single-node clusters and/or the last remaining running instance in a
cluster. cluster.
## PDB for critical operations ## PDB for critical operations
The `MinAvailable` parameter of this PDB is equal to the `numberOfInstances` set in the The `MaxUnavailable` parameter of this PDB is set to `0`, while label selector includes
cluster manifest, while label selector includes `critical-operation=true` condition. This `critical-operation=true` condition. This blocks voluntary disruptions for all pods of a
allows to protect all pods of a cluster, given they are labeled accordingly. cluster that are labeled accordingly, without leaving an unsatisfiable budget behind when
no pods carry the label (which previously kept monitoring alerts like
`KubePdbNotEnoughHealthyPods` firing permanently).
For example, Operator labels all Spilo pods with `critical-operation=true` during the major For example, Operator labels all Spilo pods with `critical-operation=true` during the major
version upgrade run. You may want to protect cluster pods during other critical operations version upgrade run. You may want to protect cluster pods during other critical operations
by assigning the label to pods yourself or using other means of automation. by assigning the label to pods yourself or using other means of automation.
@ -651,7 +653,8 @@ The PDB is only relaxed in two scenarios:
* If a cluster is scaled down to `0` instances (e.g. for draining nodes) * If a cluster is scaled down to `0` instances (e.g. for draining nodes)
* If the PDB is disabled in the configuration (`enable_pod_disruption_budget`) * If the PDB is disabled in the configuration (`enable_pod_disruption_budget`)
The PDBs are still in place having `MinAvailable` set to `0`. Disabling PDBs The PDBs are still in place: the primary PDB with `MinAvailable` set to `0` and the
critical operations PDB with `MaxUnavailable` set to `100%`. Disabling PDBs
helps avoiding blocking Kubernetes upgrades in managed K8s environments at the helps avoiding blocking Kubernetes upgrades in managed K8s environments at the
cost of prolonged DB downtime. See PR [#384](https://github.com/zalando/postgres-operator/pull/384) cost of prolonged DB downtime. See PR [#384](https://github.com/zalando/postgres-operator/pull/384)
for the use case. for the use case.