Skip to content

NimTechnology

Trình bày các công nghệ CLOUD một cách dễ hiểu.

  • Kubernetes & Container
    • Docker
    • Kubernetes
      • Gateway API
      • Ingress
      • Pod
    • Helm Chart
    • OAuth2 Proxy
    • Isito-EnvoyFilter
    • Apache Kafka
      • Kafka
      • Kafka Connect
      • Lenses
    • Vault
    • Longhorn – Storage
    • VictoriaMetrics
    • MetalLB
    • Kong Gateway
  • CI/CD
    • ArgoCD
    • ArgoWorkflows
    • Argo Events
    • Spinnaker
    • Jenkins
    • Harbor
    • TeamCity
    • Git
      • Bitbucket
  • Coding
    • DevSecOps
    • Terraform
      • GCP – Google Cloud
      • AWS – Amazon Web Service
      • Azure Cloud
    • Golang
    • Laravel
    • Python
    • Jquery & JavaScript
    • Selenium
  • Log, Monitor & Tracing
    • DataDog
    • Prometheus
    • Grafana
    • ELK
      • Kibana
      • Logstash
  • BareMetal
    • NextCloud
  • Toggle search form

[Crunchy] Install PostgreSQL on the k8s cluster via Crunchy Postgres.

Posted on July 27, 2026July 27, 2026 By nim No Comments on [Crunchy] Install PostgreSQL on the k8s cluster via Crunchy Postgres.

Đại loại thì Crunchy Postgres cung cấp cho chúng ta 1 operator
Từ đó bạn apply 1 Custom Resource: PostgresCluster

Thì Postgres Operator của Crunchy sẽ tạo cho bạn 1 cluster postgresql tương ứng.

Đầu tiên bạn cần cài đặt Crunchy Postgres Operator

Bạn sẽ thấy file Kustomization.

https://github.com/CrunchyData/postgres-operator/blob/main/config/default/kustomization.yaml

Sau khi cài được Postgres Operator rồi

apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization

namespace: postgres-operator

resources:
  - github.com/CrunchyData/postgres-operator/config/default?ref=v6.0.2

Giờ bạn tạo 1 PostgresCluster và tiến anh apply

apiVersion: postgres-operator.crunchydata.com/v1beta1
kind: PostgresCluster
metadata:
  name: postgres
  namespace: postgres-operator
spec:
  # Test deployment explicitly requested by operator.
  # Immutable build tag: preserves Crunchy postgres UID (26) required by PGO init.
  image: antiantiops/crunchy-postgres-documentdb:pg16-documentdb-d2781e5
  postgresVersion: 16
  instances:
    - name: instance1
      replicas: 1
      dataVolumeClaimSpec:
        accessModes:
          - ReadWriteOnce
        storageClassName: longhorn
        resources:
          requests:
            storage: 5Gi
      resources:
        limits:
          cpu: 500m
          memory: 512Mi
        requests:
          cpu: 100m
          memory: 256Mi
  users:
    - name: postgres
      databases:
        - postgres
    - name: ferretdb
      databases:
        - ferretdb
      password:
        type: AlphaNumeric
  patroni:
    dynamicConfiguration:
      postgresql:
        parameters:
          # DocumentDB core is a postmaster module; pg_cron is a DocumentDB dependency.
          shared_preload_libraries: pg_documentdb_core,pg_documentdb,pg_cron
          cron.database_name: ferretdb
          # DocumentDB index workers reconnect locally as this role.
          # Required when PostgreSQL md5/SCRAM authentication is enabled.
          documentdb.localhost_connection_string: "host=localhost user=ferretdb dbname=ferretdb password=oC7bCxxxxxxlN7DTOJ"
        pg_hba:
          - "host all all 0.0.0.0/0 md5"
          - "host all all ::0/0 md5"
  backups:
    pgbackrest:
      repos:
        - name: repo1
          volume:
            volumeClaimSpec:
              accessModes:
                - ReadWriteOnce
              storageClassName: longhorn
              resources:
                requests:
                  storage: 5Gi

Giờ đi vào giải thích từng block:

spec:
  image: antiantiops/crunchy-postgres-documentdb:pg16-documentdb-d2781e5
  postgresVersion: 16
  • postgresVersion: 16 yêu cầu PostgreSQL major version 16.
  • image thay image PostgreSQL mặc định của PGO bằng image tùy biến có DocumentDB.
  • Tag pg16-documentdb-d2781e5 là tag cố định, tốt hơn latest vì lần triển khai sau sẽ dùng đúng cùng một image.

Dòng comment nói image phải giữ PostgreSQL UID 26. Đây là điểm quan trọng: PGO init container và quyền trên volume có thể phụ thuộc vào UID/GID trong image. Nếu image tự build đổi user/UID, Pod có thể gặp lỗi quyền khi khởi tạo hoặc mount dữ liệu.

Instance PostgreSQL

instances:
  - name: instance1
    replicas: 1

Tạo một nhóm instance tên instance1.

replicas: 1 nghĩa là chỉ có một Pod PostgreSQL.

Đây là cấu hình phù hợp cho môi trường test/dev, nhưng không có high availability: nếu node hoặc Pod gặp sự cố, database tạm thời không phục vụ được cho tới khi Pod được khôi phục.

dataVolumeClaimSpec:
  accessModes:
    - ReadWriteOnce
  storageClassName: longhorn
  resources:
    requests:
      storage: 5Gi

Đây là PVC chứa dữ liệu database chính:

  • ReadWriteOnce (RWO): volume được gắn đọc-ghi bởi một node tại một thời điểm; đây là kiểu phổ biến cho PostgreSQL.
  • storageClassName: longhorn: yêu cầu Kubernetes cấp volume qua Longhorn.
  • storage: 5Gi: dung lượng yêu cầu ban đầu là 5 GiB.

Lưu ý: 5 GiB thường khá nhỏ nếu dùng DocumentDB, vì dữ liệu, index, WAL và tăng trưởng database đều cần không gian. Cũng cần xác nhận StorageClass Longhorn của bạn có cho phép mở rộng volume hay không trước khi production.

Contents

Toggle
  • CPU và RAM
  • Luồng hoạt động

CPU và RAM

resources:
  limits:
    cpu: 500m
    memory: 512Mi
  requests:
    cpu: 100m
    memory: 256Mi

Người dùng và database

users:
  - name: postgres
    databases:
      - postgres

Tạo role postgres.

Role này được cấp quyền trên database postgres.

Đây thường là tài khoản quản trị/khởi đầu, nhưng không nên dùng trực tiếp cho ứng dụng.

  - name: ferretdb
    databases:
      - ferretdb
    password:
      type: AlphaNumeric
  • Tạo role ứng dụng ferretdb.
  • Tạo hoặc gán role này với database ferretdb.
  • password.type: AlphaNumeric yêu cầu operator sinh password gồm ký tự chữ và số, rồi lưu nó trong Kubernetes Secret do PGO quản lý.access.crunchydata

Tên ferretdb gợi ý database này dành cho FerretDB, một lớp tương thích MongoDB chạy trên PostgreSQL/DocumentDB.

Patroni và cấu hình động

patroni:
  dynamicConfiguration:

PGO dùng Patroni để quản lý lifecycle PostgreSQL, như bootstrap, failover và áp cấu hình runtime. dynamicConfiguration là nơi thêm cấu hình PostgreSQL được Patroni quản lý.

postgresql:
  parameters:
    shared_preload_libraries: pg_documentdb_core,pg_documentdb,pg_cron

shared_preload_libraries là tham số rất quan trọng:

  • pg_documentdb_core: nạp phần lõi DocumentDB.
  • pg_documentdb: nạp extension/chức năng DocumentDB.
  • pg_cron: scheduler chạy tác vụ SQL định kỳ.

Các thư viện ở đây phải được preload ngay lúc PostgreSQL khởi động, nên khi thay đổi giá trị này, PostgreSQL cần restart để có hiệu lực. PostgreSQL dùng cơ chế shared_preload_libraries cho các module cần khởi tạo sớm trong server process.

cron.database_name: ferretdb

Chỉ định database mà pg_cron sử dụng để lưu metadata và chạy job.

Do đó, extension và cấu hình pg_cron được định hướng về database ferretdb, thay vì database mặc định postgres.

documentdb.localhost_connection_string: "host=localhost user=ferretdb dbname=ferretdb password=oC7bCxxxxxxlN7DTOJ"

Đây là connection string nội bộ để worker của DocumentDB kết nối ngược lại PostgreSQL qua localhost.

Worker dùng role ferretdb và kết nối vào database ferretdb.

Comment cho biết điều này cần thiết khi PostgreSQL đang dùng xác thực password như MD5 hoặc SCRAM.

Quy tắc đăng nhập

pg_hba:
  - "host all all 0.0.0.0/0 md5"
  - "host all all ::0/0 md5"

pg_hba.conf quy định ai có thể kết nối vào PostgreSQL và dùng cách xác thực nào:

DòngÝ nghĩa
host all all 0.0.0.0/0 md5Cho phép mọi user vào mọi database từ mọi địa chỉ IPv4, dùng xác thực password MD5
host all all ::0/0 md5Tương tự cho mọi địa chỉ IPv6

Cấu hình này rất rộng: bất cứ client nào có đường mạng đến PostgreSQL Service/Pod đều có thể thử đăng nhập bằng bất kỳ role nào. Hãy chỉ giới hạn CIDR mạng của cluster/application, ví dụ 10.42.0.0/16, và ưu tiên SCRAM thay vì MD5 khi toàn bộ client đã hỗ trợ.

Ví dụ hướng chặt hơn:

pg_hba:
  - "host ferretdb ferretdb 10.42.0.0/16 scram-sha-256"
  - "host all all 127.0.0.1/32 scram-sha-256"

Tuy nhiên, trước khi đổi sang SCRAM, bạn phải bảo đảm password đã được tạo/lưu theo SCRAM và DocumentDB/FerretDB client tương thích.

Backup pgBackRest

backups:
  pgbackrest:
    repos:
      - name: repo1
  • Bật pgBackRest, công cụ backup/restore PostgreSQL mà PGO tích hợp.
  • repo1 là repository backup đầu tiên. PGO hỗ trợ cấu hình repository kiểu volume hoặc object storage tùy triển khai.access.crunchydata
volume:
  volumeClaimSpec:
    accessModes:
      - ReadWriteOnce
    storageClassName: longhorn
    resources:
      requests:
        storage: 5Gi

Backup được lưu trên một PVC Longhorn khác, dung lượng 5 GiB.

Volume backup tách với data volume là đúng, vì xóa hoặc hỏng PVC dữ liệu không đồng nghĩa mất ngay backup.

Luồng hoạt động

Khi apply manifest này, luồng khái quát là:

  1. PGO thấy resource PostgresCluster/postgres.
  2. Operator tạo PVC dữ liệu Longhorn 5 GiB và Pod PostgreSQL 16 từ custom image.
  3. Operator tạo role/database postgres và ferretdb, đồng thời quản lý Secret mật khẩu.
  4. Patroni áp PostgreSQL parameters, preload DocumentDB và pg_cron, rồi khởi động PostgreSQL.
  5. PGO tạo một repository pgBackRest trên PVC Longhorn riêng cho backup.

Làm sao để lấy thông tin database để kết nối

Bạn vào phân secret và lấy ra các config liên đến database của bạn.

Kubernetes & Container

Post navigation

Previous Post: [podman] Run a Docker container without using Docker
Next Post: Komodo manages many Docker containers on many servers

More Related Articles

[Kubernetes] How to delete Persistent Volume is Terminating and very stubborn Kubernetes
[git-sync] an auto simple that pulls a git repository into a container on Kubernetes Git
[Goldilocks] Help you identify a starting point for resource requests and limits. Kubernetes & Container
Komodo manages many Docker containers on many servers Kubernetes & Container
[Longhorn] Store label with longhorn in order to create many storage classes and have many storage styles “SSD, HDD, fast, slow” Kubernetes & Container
[Harbor] Install harbor(private docker hub) On k8s through helm and repo goharbor Harbor

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Tham Gia Group DevOps nhé!
Để Nim có nhiều động lực ra nhiều bài viết.
Để nhận được những thông báo mới nhất.

Recent Posts

  • Komodo manages many Docker containers on many servers July 27, 2026
  • [Crunchy] Install PostgreSQL on the k8s cluster via Crunchy Postgres. July 27, 2026
  • [podman] Run a Docker container without using Docker July 15, 2026
  • Transform a Google Drive to S3 AWS June 12, 2026
  • [Rancher/EKS] Rancher from v2.12.x can not work on eks cluster. April 15, 2026

Archives

  • July 2026
  • June 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021

Categories

  • AI
    • OpenClaw
  • BareMetal
    • NextCloud
  • CI/CD
    • Argo Events
    • ArgoCD
    • ArgoWorkflows
    • Git
      • Bitbucket
    • Harbor
    • Jenkins
    • Spinnaker
    • TeamCity
  • Coding
    • DevSecOps
    • Golang
    • Jquery & JavaScript
    • Laravel
    • NextJS 14 & ReactJS & Type Script
    • Python
    • Selenium
    • Terraform
      • AWS – Amazon Web Service
      • Azure Cloud
      • GCP – Google Cloud
  • Kubernetes & Container
    • Apache Kafka
      • Kafka
      • Kafka Connect
      • Lenses
    • Docker
    • Helm Chart
    • Isito-EnvoyFilter
    • Kong Gateway
    • Kubernetes
      • Gateway API
      • Ingress
      • Pod
    • Longhorn – Storage
    • MetalLB
    • OAuth2 Proxy
    • Vault
    • VictoriaMetrics
  • Log, Monitor & Tracing
    • DataDog
    • ELK
      • Kibana
      • Logstash
    • Fluent
    • Grafana
    • Prometheus
  • Uncategorized
  • Admin

Copyright © 2026 NimTechnology.