a2f3410e42
Add per-site and per-box inventories, consolidate shared network design, and relocate the switch and access-point references under the home site.
1.7 KiB
1.7 KiB
colony-psql
The shared PostgreSQL instance for colony services. Rather than each service running its own
database, the containers (and the git VM) connect here over the ctrs network.
- Source:
shill/containers/colony-psql.nix - Host: NixOS container on
shill - nixpkgs:
mine
Role
- PostgreSQL 14 with TCP/IP enabled, reachable from the whole colony address space using
md5authentication. The firewall allows5432. - Local
peerauth mapspostgres,root,netdataanddevto thepostgressuperuser via the ident map. - netdata with the Python PostgreSQL collector.
- Consumers wait for the database to accept connections with the
lib.my.systemdAwaitPostgreshelper (e.g.sharry,atticd,mastodon-init-db, andmiddleman's nginx as a DNS bootstrap hack).
Network assignments
See the consolidated network assignments table (this box: colony-psql).
The assignment also has the alt name colony-psql (no -ctr suffix), which is what consumers
use as the database hostname.
Consumers
- object —
sharryandhedgedoc(andatticdwhen enabled) overcolony-psql:5432 - toot — Mastodon's database (Mastodon currently disabled)
- chatterbox — the mautrix bridges (WhatsApp, Messenger, Instagram) via Postgres URIs in their secret env files
gitVM — Gitea
Notable config files
nixos/boxes/colony/vms/shill/containers/colony-psql.nix— container definition and PostgreSQL configuration