Skip to content

fix(charts): run Postgres client init steps on the CloudNativePG minimal image - #1379

Open
aivong-openhands wants to merge 1 commit into
mainfrom
fix/postgres-client-image
Open

aivong-openhands wants to merge 1 commit into
mainfrom
fix/postgres-client-image

Conversation

@aivong-openhands

Copy link
Copy Markdown
Contributor

Why

Every "wait for the database" and "create the databases" step in the chart runs on bitnamilegacy/postgresql:latest, a frozen Bitnami image that Trivy reports at 19 critical / 146 high, 16 / 84 of them with fixes available. These steps only run the Postgres client tools (pg_isready and psql) against the configured server, so they need a maintained client image, not Bitnami's server image. This moves all of them to ghcr.io/cloudnative-pg/postgresql:17.11-202610050823-minimal-trixie, CloudNativePG's minimal image: 0 / 0 fixable, the same client major version as today (psql 17.5 → 17.11), runs as a non-root user, and is the image family #986 uses for the server. The dated tag is immutable, so installs stay reproducible.

The change covers the init containers in the openhands, runtime-api and plugin-directory charts, the wait-for-postgres containers in automation and integrations-hub, Keycloak's waitForDb image, and its Replicated proxy override. The bundled Postgres server (postgresql.image) is unchanged, so no data moves.

Validation

  • Trivy — bitnamilegacy/postgresql:latest reports 19 / 146 (16 / 84 fixable); the new image reports 1 / 61 with 0 / 0 fixable on both linux/amd64 and linux/arm64.
  • Init scripts against the bundled server — the rendered wait-for-db and create-db scripts, run in the new image against bitnamilegacy/postgresql:16.4.0-debian-12-r14, waited while the server started, created openhands, litellm and keycloak, and a second run left them in place without errors. The automation-style psql -c '\q' wait connects too.
  • Render and tests — with all subcharts enabled no bitnamilegacy/postgresql:latest reference remains; helm lint, the runtime-api, automation and integrations-hub unit tests (54) and scripts/ tests (325) pass.

Helm Chart Checklist

  • I have tested the chart upgrade path from the previous version — only init-container images change; they hold no state.
  • I have verified backwards compatibility with existing values.yaml configurations — keycloak.waitForDb.image keeps the same key; the other images were hard-coded before and still are.
  • I have updated the chart's README.md if there are any breaking changes or new required values — no new required values.

This PR was drafted by an AI agent on behalf of the user.

@github-actions github-actions Bot added the type: fix A bug fix label Oct 9, 2026
@aivong-openhands

Copy link
Copy Markdown
Contributor Author

Ran an embedded cluster install and a conversation worked end to end

@aivong-openhands
aivong-openhands marked this pull request as ready for review October 9, 2026 17:04

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: fix A bug fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant