pg_isready with the 1s default times out under I/O stall and kubelet kills a healthy postgres mid-recovery; each kill restarts a multi-minute fsync from zero and loops forever. readiness/liveness timeout 5s, liveness threshold 5, startup budget 15min.
Shared PostgreSQL
This directory contains the shared PostgreSQL 17 deployment for Authentik, Gitea, NetBox, Netronome, and Statuspage. It creates one database and one login role per service. Per-service standalone databases were removed after the migration (Sep 2026); Penpot stays on its own compose PostgreSQL (archived, not part of the shared instance).
Compatibility baseline
| Service | Current application | Shared PostgreSQL 17 |
|---|---|---|
| Authentik | 2025.10.x | Supported (Authentik requires 14+) |
| Gitea | 1.27.3 | Supported (Gitea requires 12+) |
| NetBox | 4.7.x | Supported (NetBox 4.x requires 13+) |
| Netronome | 0.14.0 | Supported (upstream's example uses 17) |
| Statuspage | custom | Supported |
A major-version change must use a logical dump/restore; changing only the image tag while keeping a data directory is not supported.
For Compose, copy .env.example to .env, set all passwords, and start it with
docker compose -f shared-compose.yaml up -d. This file is intentionally not
named compose.yaml, so the repository deploy workflow does not start a second
database accidentally.
Applications that use this database must also join that external network and use
homelab-postgres:5432.
For Kubernetes, create k8s/secrets.yaml from the example before applying the
manifests. The k8s/active marker makes the normal deploy workflow include the
namespace, StatefulSet, ConfigMap, and NetworkPolicy. Applications use
postgres.database.svc.cluster.local:5432.
Migrate each existing database with a tested logical dump/restore before
switching an application. Do not reuse a PostgreSQL 14 or 17 data directory
with PostgreSQL 15.