From 29624e845dab5473c6b1646d33de9384238f80d2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B8rgen=20Stensrud?= Date: Tue, 25 Aug 2026 09:44:02 +0000 Subject: [PATCH] fix(forte-drop-pg-backup): set MC_CONFIG_DIR so backups can upload (#23) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The nightly Postgres backup CronJob has been **failing every run** — no backups exist in `s3://drops/_pgbackups/`. **Cause:** the upload container runs as uid 65532 (`runAsNonRoot`). `mc` defaults its config to `$HOME/.mc` = `/.mc` and dies with `mkdir /.mc: permission denied` on the non-writable root fs — before any upload. **Fix:** set `MC_CONFIG_DIR=/work/.mc` (the shared emptyDir, writable via `fsGroup: 65532`). The `pg_dump` initContainer already succeeds; this lets the upload step actually run. Validated: `kubectl kustomize` renders clean; env present on the upload container. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Danijel Simeunovic Co-authored-by: Sten Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/23 Reviewed-by: Danijel Simeunovic Co-authored-by: Jørgen Stensrud Co-committed-by: Jørgen Stensrud --- .../forte-drop-postgresql/resources/pg-backup-cronjob.yaml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/apps/overlays/upc-dev/forte-drop-postgresql/resources/pg-backup-cronjob.yaml b/apps/overlays/upc-dev/forte-drop-postgresql/resources/pg-backup-cronjob.yaml index 4304424..3ba3fef 100644 --- a/apps/overlays/upc-dev/forte-drop-postgresql/resources/pg-backup-cronjob.yaml +++ b/apps/overlays/upc-dev/forte-drop-postgresql/resources/pg-backup-cronjob.yaml @@ -77,6 +77,12 @@ spec: mc rm --recursive --force --older-than 30d "obj/${S3_BUCKET}/_pgbackups/" || true echo "backup retention pass complete" env: + # mc writes its config under $MC_CONFIG_DIR; point it at the shared + # emptyDir (writable by uid 65532 via fsGroup). Without this it tries + # to mkdir /.mc on the read-only-to-nonroot root fs -> "mkdir /.mc: + # permission denied" and every run fails before uploading. + - name: MC_CONFIG_DIR + value: "/work/.mc" - name: S3_ENDPOINT valueFrom: secretKeyRef: { name: forte-drop-secrets, key: S3_ENDPOINT }