From 0e3ff4c3e64b915f75e5a338c836ad40bb29b23b Mon Sep 17 00:00:00 2001 From: Lorenzo Corallo Date: Thu, 17 Sep 2026 22:35:18 +0200 Subject: [PATCH] fix: retain application volumes and protect database rollouts --- bot-ts/src/deployment.yaml | 3 +++ influxdb/src/deployment.yaml | 4 ++++ monitoring/src/deployment-grafana.yaml | 2 ++ monitoring/src/deployment-prometheus.yaml | 2 ++ postgres/src/deployment.yaml | 11 +++++++++++ redis/src/deployment.yaml | 2 ++ tests/workload-manifests.test.rb | 15 +++++++++++++++ uptime-kuma/src/deployment.yaml | 2 ++ 8 files changed, 41 insertions(+) diff --git a/bot-ts/src/deployment.yaml b/bot-ts/src/deployment.yaml index 0601578..bef0f94 100644 --- a/bot-ts/src/deployment.yaml +++ b/bot-ts/src/deployment.yaml @@ -125,6 +125,8 @@ spec: apiVersion: v1 kind: PersistentVolumeClaim metadata: + annotations: + argocd.argoproj.io/sync-options: Prune=false,Delete=false name: redis-pvc spec: accessModes: @@ -150,6 +152,7 @@ spec: labels: app: bot-ts spec: + terminationGracePeriodSeconds: 90 containers: - name: bot-ts image: ghcr.io/polinetworkorg/telegram@sha256:aa7203181e578cbc48e9fe1c8a011dc89f49f7a21137be6124051f727bb814fb diff --git a/influxdb/src/deployment.yaml b/influxdb/src/deployment.yaml index e485e4d..b2399c5 100644 --- a/influxdb/src/deployment.yaml +++ b/influxdb/src/deployment.yaml @@ -1,6 +1,8 @@ apiVersion: v1 kind: PersistentVolumeClaim metadata: + annotations: + argocd.argoproj.io/sync-options: Prune=false,Delete=false name: influxdb-config-pvc spec: accessModes: @@ -13,6 +15,8 @@ spec: apiVersion: v1 kind: PersistentVolumeClaim metadata: + annotations: + argocd.argoproj.io/sync-options: Prune=false,Delete=false name: influxdb-data-pvc spec: accessModes: diff --git a/monitoring/src/deployment-grafana.yaml b/monitoring/src/deployment-grafana.yaml index 224ebcf..7490f9b 100644 --- a/monitoring/src/deployment-grafana.yaml +++ b/monitoring/src/deployment-grafana.yaml @@ -2,6 +2,8 @@ apiVersion: v1 kind: PersistentVolumeClaim metadata: + annotations: + argocd.argoproj.io/sync-options: Prune=false,Delete=false name: grafana-pvc spec: storageClassName: longhorn diff --git a/monitoring/src/deployment-prometheus.yaml b/monitoring/src/deployment-prometheus.yaml index f548d5c..3eb74db 100644 --- a/monitoring/src/deployment-prometheus.yaml +++ b/monitoring/src/deployment-prometheus.yaml @@ -2,6 +2,8 @@ apiVersion: v1 kind: PersistentVolumeClaim metadata: + annotations: + argocd.argoproj.io/sync-options: Prune=false,Delete=false name: prometheus-pvc spec: storageClassName: longhorn diff --git a/postgres/src/deployment.yaml b/postgres/src/deployment.yaml index 5d27398..0b53eb5 100644 --- a/postgres/src/deployment.yaml +++ b/postgres/src/deployment.yaml @@ -49,6 +49,8 @@ metadata: name: postgres spec: replicas: 1 + strategy: + type: Recreate selector: matchLabels: app: postgres @@ -77,6 +79,15 @@ spec: name: azure-kv key: db-pass optional: false + readinessProbe: + exec: + command: + - sh + - -c + - pg_isready -h 127.0.0.1 -U "$POSTGRES_USER" -d "$POSTGRES_DB" + periodSeconds: 10 + timeoutSeconds: 5 + failureThreshold: 3 volumeMounts: - mountPath: /var/lib/postgresql/data name: postgresdata diff --git a/redis/src/deployment.yaml b/redis/src/deployment.yaml index 15e18ce..f704009 100644 --- a/redis/src/deployment.yaml +++ b/redis/src/deployment.yaml @@ -1,6 +1,8 @@ apiVersion: v1 kind: PersistentVolumeClaim metadata: + annotations: + argocd.argoproj.io/sync-options: Prune=false,Delete=false name: redis-pvc spec: accessModes: diff --git a/tests/workload-manifests.test.rb b/tests/workload-manifests.test.rb index 3dc59ea..8967fea 100644 --- a/tests/workload-manifests.test.rb +++ b/tests/workload-manifests.test.rb @@ -58,4 +58,19 @@ def init_container(resource, name) raise "Grafana memory request must cover its observed working set" unless grafana.dig("resources", "requests", "memory") == "768Mi" raise "Grafana must use Recreate with its single-writer PVC" unless grafana_deployment.dig("spec", "strategy", "type") == "Recreate" +postgres_deployment = deployment("postgres/src/deployment.yaml", "postgres") +postgres = container(postgres_deployment, "postgres") +raise "PostgreSQL must keep a single writer during rollout" unless postgres_deployment.dig("spec", "strategy", "type") == "Recreate" +raise "PostgreSQL must report database readiness" unless postgres.dig("readinessProbe", "exec", "command").last.include?("pg_isready") +raise "Do not restart PostgreSQL automatically on probe failures" if postgres["livenessProbe"] + +claims = Dir.glob(File.join(ROOT, "**/src/*.yaml")).flat_map do |path| + YAML.load_stream(File.read(path)).compact.select { |doc| doc["kind"] == "PersistentVolumeClaim" } +end +claims.each do |claim| + next unless claim.dig("spec", "storageClassName") == "longhorn" + options = claim.dig("metadata", "annotations", "argocd.argoproj.io/sync-options").to_s.split(",") + raise "Argo must retain #{claim.dig("metadata", "name")}" unless ["Prune=false", "Delete=false"].all? { |option| options.include?(option) } +end + puts "workload manifest checks passed" diff --git a/uptime-kuma/src/deployment.yaml b/uptime-kuma/src/deployment.yaml index 79680bd..19c2585 100644 --- a/uptime-kuma/src/deployment.yaml +++ b/uptime-kuma/src/deployment.yaml @@ -1,6 +1,8 @@ apiVersion: v1 kind: PersistentVolumeClaim metadata: + annotations: + argocd.argoproj.io/sync-options: Prune=false,Delete=false name: uptime-pvc spec: accessModes: