Repository navigation
fix(charts): run Postgres client init steps on the CloudNativePG minimal image - #1379
Open
aivong-openhands wants to merge 1 commit into
Open
aivong-openhands wants to merge 1 commit into
aivong-openhands wants to merge 1 commit into
Conversation
Contributor
Author
|
Ran an embedded cluster install and a conversation worked end to end |
aivong-openhands
marked this pull request as ready for review
October 9, 2026 17:04
aivong-openhands
requested review from
dylan-openhands,
jlav and
mamoodi
as code owners
October 9, 2026 17:04
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Every "wait for the database" and "create the databases" step in the chart runs on
bitnamilegacy/postgresql:latest, a frozen Bitnami image that Trivy reports at 19 critical / 146 high, 16 / 84 of them with fixes available. These steps only run the Postgres client tools (pg_isreadyandpsql) against the configured server, so they need a maintained client image, not Bitnami's server image. This moves all of them toghcr.io/cloudnative-pg/postgresql:17.11-202610050823-minimal-trixie, CloudNativePG's minimal image: 0 / 0 fixable, the same client major version as today (psql 17.5 → 17.11), runs as a non-root user, and is the image family #986 uses for the server. The dated tag is immutable, so installs stay reproducible.The change covers the init containers in the openhands, runtime-api and plugin-directory charts, the
wait-for-postgrescontainers in automation and integrations-hub, Keycloak'swaitForDbimage, and its Replicated proxy override. The bundled Postgres server (postgresql.image) is unchanged, so no data moves.Validation
bitnamilegacy/postgresql:latestreports 19 / 146 (16 / 84 fixable); the new image reports 1 / 61 with 0 / 0 fixable on both linux/amd64 and linux/arm64.wait-for-dbandcreate-dbscripts, run in the new image againstbitnamilegacy/postgresql:16.4.0-debian-12-r14, waited while the server started, createdopenhands,litellmandkeycloak, and a second run left them in place without errors. The automation-stylepsql -c '\q'wait connects too.bitnamilegacy/postgresql:latestreference remains;helm lint, the runtime-api, automation and integrations-hub unit tests (54) andscripts/tests (325) pass.Helm Chart Checklist
keycloak.waitForDb.imagekeeps the same key; the other images were hard-coded before and still are.This PR was drafted by an AI agent on behalf of the user.