PageSourceSearch

https://flanksource.com/assets/js/30338366.4dc861fb.js

js flanksource.com collected 2026-09-25 15:25:52 UTC 6,263 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkmission_control=globalThis.webpackChunkmission_control||[]).push([[2871],{45137(e,t,s){s.r(t),s.d(t,{assets:()=>l,contentTitle:()=>r,default:()=>h,frontMatter:()=>i,metadata:()=>n,toc:()=>c});const n=JSON.parse('{"id":"installation/self-hosted/database","title":"Database","description":"Alternative methods for connecting to the db used for persistence","source":"@site/docs/installation/self-hosted/database.md","sourceDirName":"installation/self-hosted","slug":"/installation/self-hosted/database","permalink":"/docs/installation/self-hosted/database","draft":false,"unlisted":false,"editUrl":"https://github.com/flanksource/docs/tree/main/docs/installation/self-hosted/database.md","tags":[],"version":"current","frontMatter":{"title":"Database","description":"Alternative methods for connecting to the db used for persistence","sidebar_custom_props":{"icon":"postgres"}},"sidebar":"overview","previous":{"title":"Getting Started","permalink":"/docs/installation/self-hosted"},"next":{"title":"SSO (OIDC)","permalink":"/docs/installation/self-hosted/sso"}}');var o=s(74848),a=s(28453);const i={title:"Database",description:"Alternative methods for connecting to the db used for persistence",sidebar_custom_props:{icon:"postgres"}},r=void 0,l={},c=[{value:"Configuring the default Statefulset",id:"configuring-the-default-statefulset",level:2},{value:"Updating postgres.conf settings",id:"updating-postgresconf-settings",level:3},{value:"Using an External Database",id:"using-an-external-database",level:2}];function d(e){const t={admonition:"admonition",code:"code",h2:"h2",h3:"h3",li:"li",p:"p",pre:"pre",ul:"ul",...(0,a.R)(),...e.components};return(0,o.jsxs)(o.Fragment,{children:[(0,o.jsx)(t.p,{children:"Mission Control stores all state in a Postgres Database, by default a Postgres StatefulSet is created."}),"\n",(0,o.jsx)(t.h2,{id:"configuring-the-default-statefulset",children:"Configuring the default Statefulset"}),"\n",(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-yaml",metastring:'title="values.yaml"',children:"db:\n  create: true\n  conf: # override postgres.conf settings\n  secretKeyRef: # auto-generated if it doesn't exist\n    name: incident-commander-postgres\n    key: DB_URL\n  storageClass: # optional storage class for PVC volume\n  storage: 20Gi\n  shmVolume: 256Mi # size of shm memory file to be mounted\n  resources: # resources to assign to the postgres /docs/guide/canary-checker/reference/database pod\n    requests:\n      memory: 4Gi\n"})}),"\n",(0,o.jsx)(t.p,{children:"The /docs/guide/canary-checker/reference/database password can then be retrieved using"}),"\n",(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-shell",children:"kubectl get secret incident-commander-postgres -o json | jq -r '.data.POSTGRES_PASSWORD' | base64 -d\n"})}),"\n",(0,o.jsxs)(t.admonition,{title:"Connecting",type:"info",children:[(0,o.jsx)(t.p,{children:"If you ever need to connect to the /docs/guide/canary-checker/reference/database, you can do so by forwarding the port:"}),(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-shell",children:"kubectl port-forward svc/postgres 5432:5432\npsql -U postgres localhost -p 5432 mission_control\n"})})]}),"\n",(0,o.jsx)(t.h3,{id:"updating-postgresconf-settings",children:"Updating postgres.conf settings"}),"\n",(0,o.jsx)(t.h2,{id:"using-an-external-database",children:"Using an External Database"}),"\n",(0,o.jsx)(t.p,{children:"Use a dedicated, empty database owned by the Mission Control login. Before installing or upgrading Mission Control, configure it as your database administrator:"}),"\n",(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-sql",children:'ALTER ROLE "mission-control" CREATEROLE;\nCREATE DATABASE mission_control OWNER "mission-control";\n'})}),"\n",(0,o.jsxs)(t.p,{children:["Replace the role and database names with your values. The ",(0,o.jsx)(t.code,{children:"CREATEROLE"})," attribute lets migrations create the ",(0,o.jsx)(t.code,{children:"postgrest_api"})," and ",(0,o.jsx)(t.code,{children:"postgrest_anon"})," roles. On PostgreSQL 16 and later, duty grants the Mission Control login ",(0,o.jsx)(t.code,{children:"SET TRUE, INHERIT FALSE"})," membership in those roles. This lets PostgREST assume them without automatically exposing their privileges to the login. No manual role grants or ",(0,o.jsx)(t.code,{children:"createrole_self_grant"})," setting are required."]}),"\n",(0,o.jsxs)(t.p,{children:["Database ownership provides the privileges needed to install trusted extensions and create schema objects, so no additional grants are required with the default ",(0,o.jsx)(t.code,{children:"public"})," schema configuration."]}),"\n",(0,o.jsx)(t.p,{children:"If the database already contains Mission Control objects, ensure that the Mission Control role owns them before running migrations."}),"\n",(0,o.jsx)(t.p,{children:"Create a secret with the following key:"}),"\n",(0,o.jsxs)(t.ul,{children:["\n",(0,o.jsx)(t.li,{children:(0,o.jsx)(t.code,{children:"DB_URL"})}),"\n"]}),"\n",(0,o.jsx)(t.p,{children:"The following keys are required for kratos:"}),"\n",(0,o.jsxs)(t.ul,{children:["\n",(0,o.jsx)(t.li,{children:(0,o.jsx)(t.code,{children:"DB_HOST"})}),"\n",(0,o.jsx)(t.li,{children:(0,o.jsx)(t.code,{children:"DB_NAME"})}),"\n",(0,o.jsx)(t.li,{children:(0,o.jsx)(t.code,{children:"DB_USERNAME"})}),"\n",(0,o.jsx)(t.li,{children:(0,o.jsx)(t.code,{children:"DB_PASSWORD"})}),"\n"]}),"\n",(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-yaml",metastring:'title="values.yaml"',children:"db:\n  create: false\n  secretKeyRef: # auto-generated if it doesn't exist\n    name: mission-control-postgres\n    key: DB_URL\n"})})]})}function h(e={}){const{wrapper:t}={...(0,a.R)(),...e.components};return t?(0,o.jsx)(t,{...e,children:(0,o.jsx)(d,{...e})}):d(e)}},28453(e,t,s){s.d(t,{R:()=>i,x:()=>r});var n=s(96540);const o={},a=n.createContext(o);function i(e){const t=n.useContext(a);return n.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function r(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(o):e.components||o:i(e.components),n.createElement(a.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.