image:
|
tag: 10.7.7-debian-11-r30
|
|
podAnnotations:
|
vault.security.banzaicloud.io/vault-addr: "http://censored-for-compliance-reasons.com"
|
vault.security.banzaicloud.io/vault-skip-verify: "true"
|
vault.security.banzaicloud.io/vault-role: "cluster-nonprod"
|
vault.security.banzaicloud.io/vault-path: "cluster-nonprod"
|
|
serviceAccount:
|
create: true
|
automountServiceAccountToken: true
|
|
fullnameOverride: dev-mariadb
|
|
rbac:
|
create: true
|
|
podManagementPolicy: Parallel
|
|
replicaCount: 3
|
|
db:
|
user: technical
|
name: ""
|
|
persistence:
|
size: 20Gi
|
|
usePasswordFiles: true
|
customPasswordFiles:
|
root: "/vault-secrets/rootpassword"
|
user: "/vault-secrets/userpassword"
|
mariabackup: "/vault-secrets/mariabackuppassword"
|
|
extraVolumes:
|
- name: vault-secrets-volume
|
emptyDir: {}
|
|
extraVolumeMounts:
|
- mountPath: /vault-secrets
|
name: vault-secrets-volume
|
|
initContainers:
|
- command:
|
- bash
|
- -c
|
- |
|
echo -n "$PASSWORD" > /vault-secrets/userpassword
|
echo -n "$ROOTPASSWORD" > /vault-secrets/rootpassword
|
echo -n "$MARIABACKUPPASSWORD" > /vault-secrets/mariabackuppassword
|
image: ubuntu:jammy
|
name: init-container
|
volumeMounts:
|
- mountPath: /vault-secrets
|
name: vault-secrets-volume
|
env:
|
- name: PASSWORD
|
value: vault:cluster-nonprod/data/dev/common/mariadb-galera/credentials#mariadb-password
|
- name: ROOTPASSWORD
|
value: vault:cluster-nonprod/data/dev/common/mariadb-galera/credentials#mariadb-root-password
|
- name: MARIABACKUPPASSWORD
|
value: vault:cluster-nonprod/data/dev/common/mariadb-galera/credentials#mariadb-galera-mariabackup-password
|
|
resources:
|
requests:
|
cpu: 0.5
|
memory: 4096Mi
|
limits:
|
cpu: 2
|
memory: 4096Mi
|
|
initdbScripts:
|
init_dbs.sql: |
|
CREATE DATABASE IF NOT EXISTS vault;
|
CREATE DATABASE IF NOT EXISTS vault_lock;
|
CREATE DATABASE IF NOT EXISTS keycloak;
|
|
mariadbConfiguration: |-
|
[client]
|
port=3306
|
socket=/opt/bitnami/mariadb/tmp/mysql.sock
|
plugin_dir=/opt/bitnami/mariadb/plugin
|
|
[mysqld]
|
default_storage_engine=InnoDB
|
basedir=/opt/bitnami/mariadb
|
datadir=/bitnami/mariadb/data
|
plugin_dir=/opt/bitnami/mariadb/plugin
|
tmpdir=/opt/bitnami/mariadb/tmp
|
socket=/opt/bitnami/mariadb/tmp/mysql.sock
|
pid_file=/opt/bitnami/mariadb/tmp/mysqld.pid
|
bind_address=0.0.0.0
|
|
## Character set
|
##
|
collation_server=utf8_unicode_ci
|
init_connect='SET NAMES utf8'
|
character_set_server=utf8
|
|
## MyISAM
|
##
|
key_buffer_size=32M
|
myisam_recover_options=FORCE,BACKUP
|
|
## Safety
|
##
|
skip_host_cache
|
skip_name_resolve
|
max_allowed_packet=16M
|
max_connect_errors=1000000
|
sql_mode=IGNORE_SPACE,ONLY_FULL_GROUP_BY,STRICT_TRANS_TABLES,NO_ZERO_IN_DATE,NO_ZERO_DATE,ERROR_FOR_DIVISION_BY_ZERO,NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION
|
sysdate_is_now=1
|
|
## Binary Logging
|
##
|
log_bin=mysql-bin
|
expire_logs_days=14
|
# Disabling for performance per http://severalnines.com/blog/9-tips-going-production-galera-cluster-mysql
|
sync_binlog=0
|
# Required for Galera
|
binlog_format=row
|
|
## Caches and Limits
|
##
|
tmp_table_size=32M
|
max_heap_table_size=32M
|
# Re-enabling as now works with Maria 10.1.2
|
query_cache_type=1
|
query_cache_limit=4M
|
query_cache_size=256M
|
max_connections=500
|
thread_cache_size=50
|
open_files_limit=65535
|
table_definition_cache=4096
|
table_open_cache=4096
|
|
## InnoDB
|
##
|
innodb=FORCE
|
innodb_strict_mode=1
|
# Mandatory per https://github.com/codership/documentation/issues/25
|
innodb_autoinc_lock_mode=2
|
# Per https://www.percona.com/blog/2006/08/04/innodb-double-write/
|
innodb_doublewrite=1
|
innodb_flush_method=O_DIRECT
|
innodb_log_files_in_group=2
|
innodb_log_file_size=128M
|
innodb_flush_log_at_trx_commit=1
|
innodb_file_per_table=1
|
# 80% Memory is default reco.
|
# Need to re-evaluate when DB size grows
|
innodb_buffer_pool_size=2G
|
innodb_file_format=Barracuda
|
|
## Logging
|
##
|
log_error=/opt/bitnami/mariadb/logs/mysqld.log
|
slow_query_log_file=/opt/bitnami/mariadb/logs/mysqld.log
|
log_queries_not_using_indexes=1
|
slow_query_log=1
|
|
[galera]
|
wsrep_on=ON
|
wsrep_provider=/opt/bitnami/mariadb/lib/libgalera_smm.so
|
wsrep_sst_method=mariabackup
|
wsrep_slave_threads=4
|
wsrep_cluster_address=gcomm://
|
wsrep_cluster_name=galera
|
wsrep_sst_auth="root:"
|
# Enabled for performance per https://mariadb.com/kb/en/innodb-system-variables/#innodb_flush_log_at_trx_commit
|
innodb_flush_log_at_trx_commit=2
|
# MYISAM REPLICATION SUPPORT #
|
wsrep_mode=REPLICATE_MYISAM
|
|
[mariadb]
|
plugin_load_add=auth_pam
|
|
|
diagnosticMode:
|
enabled: false
|