Configure external PostgreSQL with Kustomize
Remove bundled PostgreSQL and patch secrets, TLS mounts, policy, and migration for an external database.
Prerequisites
Provision supported TLS PostgreSQL with backup/restore, capacity, allowlists, and migration privileges. Read Kubernetes database.
Prepare the overlay
Delete both bundled PostgreSQL StatefulSet and Service with targeted delete patches. Make the external secret controller supply direct URLs. Mount any private CA into migration and every runtime role and use verify-full/sslrootcert.
Patch all applicable NetworkPolicies to the actual database destination: Web, migration, workers, scheduler, projector, and PgBouncer as selected. The checked-in example is not automatically complete for every environment.
Deploy the external path
Render and verify no bundled database resource, correct Secret/CA references, and restricted egress. Run the direct one-shot migration Job, require completion, then apply workloads.
Verify the database
At the provider, verify TLS identity, source, connections, and migration completion. Run readiness plus a create/restart/read/update incident workflow and an isolated restore test with matching stable secrets.
Operate it in production
Monitor availability/failover, replication, storage, connections, slow queries, certificates, backup, and maintenance. Assign explicit alert ownership.
Troubleshooting
Bundled database still renders: fix delete patch resource names/namespace.
Only some roles connect: patch CA, Secret, and NetworkPolicy for every role, not only Web.
Migration blocked: correct direct DNS/TLS/auth/privileges before applying workloads.
Change or undo external database use
Use a controlled data cutover and retained rollback source; never let bundled and external databases receive divergent writes.
Next steps
Last updated for v2.0.0
Edit this page on GitHub