mirror of
https://github.com/zalando/postgres-operator.git
synced 2026-09-30 19:31:23 +02:00
StatefulSet fsGroup config option to allow non-root spilo (#531)
* StatefulSet fsGroup config option to allow non-root spilo * Allow Postgres CRD to overide SpiloFSGroup of the Operator. * Document FSGroup of a Pod cannot be changed after creation.
This commit is contained in:
committed by
Sergey Dudoladov
parent
5a0e95ac45
commit
ec5b1d4d58
@@ -58,6 +58,13 @@ These parameters are grouped directly under the `spec` key in the manifest.
|
||||
custom docker image that overrides the **docker_image** operator parameter.
|
||||
It should be a [Spilo](https://github.com/zalando/spilo) image. Optional.
|
||||
|
||||
* **spiloFSGroup**
|
||||
the Persistent Volumes for the spilo pods in the StatefulSet will be owned
|
||||
and writable by the group ID specified. This will override the **spilo_fsgroup**
|
||||
operator parameter. This is required to run Spilo as a non-root process, but
|
||||
requires a custom spilo image. Note the FSGroup of a Pod cannot be changed
|
||||
without recreating a new Pod.
|
||||
|
||||
* **enableMasterLoadBalancer**
|
||||
boolean flag to override the operator defaults (set by the
|
||||
`enable_master_load_balancer` parameter) to define whether to enable the load
|
||||
|
||||
@@ -228,6 +228,11 @@ configuration they are grouped under the `kubernetes` key.
|
||||
that should be assigned to the Postgres pods. The priority class itself must
|
||||
be defined in advance. Default is empty (use the default priority class).
|
||||
|
||||
* **spilo_fsgroup**
|
||||
the Persistent Volumes for the spilo pods in the StatefulSet will be owned and writable by the group ID specified.
|
||||
This is required to run Spilo as a non-root process, but requires a custom spilo image. Note the FSGroup of a Pod
|
||||
cannot be changed without recreating a new Pod.
|
||||
|
||||
* **spilo_privileged**
|
||||
whether the Spilo container should run in privileged mode. Privileged mode is
|
||||
used for AWS volume resizing and not required if you don't need that
|
||||
|
||||
Reference in New Issue
Block a user