fix(forte-drop-pg-backup): set MC_CONFIG_DIR so backups can upload (#23)
/ test (push) Successful in 10s

The nightly Postgres backup CronJob has been **failing every run** — no backups exist in `s3://drops/_pgbackups/`.

**Cause:** the upload container runs as uid 65532 (`runAsNonRoot`). `mc` defaults its config to `$HOME/.mc` = `/.mc` and dies with `mkdir /.mc: permission denied` on the non-writable root fs — before any upload.

**Fix:** set `MC_CONFIG_DIR=/work/.mc` (the shared emptyDir, writable via `fsGroup: 65532`). The `pg_dump` initContainer already succeeds; this lets the upload step actually run.

Validated: `kubectl kustomize` renders clean; env present on the upload container.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: Sten <sten@Sten-sin-MacBook-Pro.local>
Reviewed-on: #23
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: Jørgen Stensrud <jorgen.stensrud@fortedigital.com>
Co-committed-by: Jørgen Stensrud <jorgen.stensrud@fortedigital.com>
This commit was merged in pull request #23.
This commit is contained in:
2026-08-25 09:44:02 +00:00
committed by danijel.simeunovic
co-authored by danijel.simeunovic Sten
parent 4712eb4804
commit 29624e845d
@@ -77,6 +77,12 @@ spec:
mc rm --recursive --force --older-than 30d "obj/${S3_BUCKET}/_pgbackups/" || true mc rm --recursive --force --older-than 30d "obj/${S3_BUCKET}/_pgbackups/" || true
echo "backup retention pass complete" echo "backup retention pass complete"
env: env:
# mc writes its config under $MC_CONFIG_DIR; point it at the shared
# emptyDir (writable by uid 65532 via fsGroup). Without this it tries
# to mkdir /.mc on the read-only-to-nonroot root fs -> "mkdir /.mc:
# permission denied" and every run fails before uploading.
- name: MC_CONFIG_DIR
value: "/work/.mc"
- name: S3_ENDPOINT - name: S3_ENDPOINT
valueFrom: valueFrom:
secretKeyRef: { name: forte-drop-secrets, key: S3_ENDPOINT } secretKeyRef: { name: forte-drop-secrets, key: S3_ENDPOINT }