High-availability PostgreSQL 18 with repmgr 5.5.0 for Kubernetes StatefulSet auto-failover
10.0K
High-availability PostgreSQL image with automatic failover for Kubernetes StatefulSet deployments. Built on Debian Trixie with repmgr 5.5.0 for streaming replication and automated failover management.
debian:trixie-slimThis image serves four distinct roles within a single Kubernetes StatefulSet pod, selected via the entrypoint argument:
entrypoint.sh <mode>
| Mode | Container Type | Purpose |
|---|---|---|
postgres | Main container | PostgreSQL server with initdb and replication setup |
init | Init container | Generate repmgr.conf, clone standby data from primary |
repmgrd | Sidecar | Register node and run repmgr failover daemon |
service-updater | Sidecar | Patch Kubernetes Service selector on primary failover |
| Variable | Description |
|---|---|
REPMGR_PASSWORD | Password for the repmgr replication user |
| Variable | Required | Default | Description |
|---|---|---|---|
POSTGRES_USER | Yes | - | Application database user |
POSTGRES_PASSWORD | Yes | - | Application database password |
POSTGRES_DB | Yes | - | Application database name |
PGDATA | No | /var/lib/postgresql/data/pgdata | Data directory path |
REPMGR_USER | No | repmgr | Repmgr database user |
REPMGR_DB | No | repmgr | Repmgr metadata database |
| Variable | Required | Default | Description |
|---|---|---|---|
HEADLESS_SERVICE | Yes | - | Headless service FQDN for node discovery |
REPMGR_USER | No | repmgr | Repmgr database user |
REPMGR_DB | No | repmgr | Repmgr metadata database |
PGDATA | No | /var/lib/postgresql/data/pgdata | Data directory path |
| Variable | Required | Default | Description |
|---|---|---|---|
NAMESPACE | Yes | - | Kubernetes namespace |
MASTER_SERVICE | Yes | - | Service name to patch on failover |
HEADLESS_SERVICE | Yes | - | Headless service FQDN for node discovery |
REPMGR_USER | No | repmgr | Repmgr database user |
REPMGR_DB | No | repmgr | Repmgr metadata database |
MONITORING_INTERVAL | No | 30 | Polling interval in seconds |
Reads /etc/repmgr/repmgr.conf generated by the init container. No additional environment variables required beyond PGDATA.
| Path | Type | Purpose |
|---|---|---|
/var/lib/postgresql/data | PVC | PostgreSQL data directory |
/etc/repmgr | emptyDir | repmgr.conf shared between init and sidecar containers |
repmgr.conf per pod. Ordinal 0 initializes as primary; ordinal N clones from the primary via pg_basebackup.initdb, configures WAL replication (wal_level=replica, max_wal_senders=10, wal_keep_size=1GB), and creates application and repmgr databases.pg_is_in_recovery(), then starts the repmgrd daemon.statefulset.kubernetes.io/pod-name selector to point to the current primary.When the primary pod becomes unavailable:
When a failed primary pod restarts:
repmgr.nodes (harmless)initContainers:
- name: init-repmgr
image: cagriekin/repmgr:trixie-5.5.0
command: ["/usr/local/bin/entrypoint.sh", "init"]
env:
- name: HEADLESS_SERVICE
value: "pg-headless.default.svc.cluster.local"
- name: REPMGR_PASSWORD
valueFrom:
secretKeyRef:
name: pg-secrets
key: repmgr-password
volumeMounts:
- name: data
mountPath: /var/lib/postgresql/data
- name: repmgr-config
mountPath: /etc/repmgr
containers:
- name: postgres
image: cagriekin/repmgr:trixie-5.5.0
command: ["/usr/local/bin/entrypoint.sh", "postgres"]
ports:
- containerPort: 5432
env:
- name: POSTGRES_USER
value: "app"
- name: POSTGRES_PASSWORD
valueFrom:
secretKeyRef:
name: pg-secrets
key: postgres-password
- name: POSTGRES_DB
value: "appdb"
- name: REPMGR_PASSWORD
valueFrom:
secretKeyRef:
name: pg-secrets
key: repmgr-password
volumeMounts:
- name: data
mountPath: /var/lib/postgresql/data
- name: repmgr-config
mountPath: /etc/repmgr
- name: repmgrd
image: cagriekin/repmgr:trixie-5.5.0
command: ["/usr/local/bin/entrypoint.sh", "repmgrd"]
volumeMounts:
- name: data
mountPath: /var/lib/postgresql/data
- name: repmgr-config
mountPath: /etc/repmgr
- name: service-updater
image: cagriekin/repmgr:trixie-5.5.0
command: ["/usr/local/bin/entrypoint.sh", "service-updater"]
env:
- name: NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- name: MASTER_SERVICE
value: "pg-primary"
- name: HEADLESS_SERVICE
value: "pg-headless.default.svc.cluster.local"
- name: REPMGR_PASSWORD
valueFrom:
secretKeyRef:
name: pg-secrets
key: repmgr-password
Content type
Image
Digest
sha256:c1bba0363…
Size
248 Bytes
Last updated
about 1 month ago
docker pull cagriekin/repmgr:sha256-b67d66cf89a3487ef8bd29709e166a92075a46650a907a337af04ef3a1d2f49d.sig