infra/secrets
Viktor Barzin a1ba218cd2 [ci skip] Phase 1: PostgreSQL migrated to CNPG on local disk
Major milestone - shared PostgreSQL moved from NFS to CloudNativePG:
- CNPG cluster (pg-cluster) running in dbaas namespace on local-path storage
- PostGIS image (ghcr.io/cloudnative-pg/postgis:16) for dawarich compatibility
- All 20 databases and 19 roles restored from pg_dumpall backup
- postgresql.dbaas Service patched to point at CNPG primary
- Old PG deployment scaled to 0 (NFS data intact for rollback)
- All 12+ dependent services verified running:
  authentik, n8n, dawarich, tandoor, linkwarden, netbox, woodpecker,
  rybbit, affine, health, resume, trading-bot, atuin
- Authentik PgBouncer working through the switched endpoint

TODO: codify CNPG cluster in Terraform, add 2nd replica, update backup CronJob
2026-02-28 19:08:06 +00:00
..
certificate.pfx update tls certs; add technitium doh open without recursion for now; add dashy web 2023-10-21 12:14:31 +00:00
deploy_key Add drone ci deploy keys 2021-02-14 18:18:03 +00:00
deploy_key.pub Add drone ci deploy keys 2021-02-14 18:18:03 +00:00
fullchain.pem Drone CI Update TLS Certificates Commit 2026-02-15 00:05:36 +00:00
nfs_directories.txt [ci skip] Phase 1: PostgreSQL migrated to CNPG on local disk 2026-02-28 19:08:06 +00:00
nfs_exports.sh add the nfs dirs 2026-02-08 02:29:48 +00:00
privkey.pem Drone CI Update TLS Certificates Commit 2026-02-15 00:05:36 +00:00