Compare commits

...

5 Commits

Author SHA1 Message Date
Armando Ruocco
2a14ed371f
Merge 6a55a361a3 into 6f712151df 2026-09-03 17:56:40 +02:00
Krypton
6f712151df
docs: add Helm chart installation (#599)
Add Helm chart install steps next to kubectl, for the current docs and
the 0.13.0 and 0.14.0 versioned snapshots.

Pin the chart's image tag to the plugin version on older releases. The
chart ships after the plugin, so its own version numbers don't map to
ours, and we skip the pin on the latest release since the chart already
defaults to itself there.

On the current docs, make clear the Helm tab installs the latest
release, not a main-branch build. Only kubectl can test a main-branch
build.

Closes #351

Signed-off-by: Krypton <root@krypton.ninja>
Signed-off-by: danishedb <danish.khan@enterprisedb.com>
Signed-off-by: Marco Nenciarini <marco.nenciarini@enterprisedb.com>
Co-authored-by: danishedb <danish.khan@enterprisedb.com>
Co-authored-by: Marco Nenciarini <marco.nenciarini@enterprisedb.com>
2026-09-03 17:35:45 +02:00
Marco Nenciarini
f459a30472
build(deps): pin pip-compile to the sidecar's Python version via dagger (#1093)
The sidecar's lockfile (`containers/sidecar-requirements.txt`) was being
regenerated with whatever python3 happened to be on the contributor's
machine, drifting from the python3.13 venv the sidecar image actually
ships (this surfaced in #1090, where the lockfile ended up regenerated
with Python 3.12). Adds a `task pip-compile-sidecar` that runs
pip-compile inside a debian:trixie-slim dagger container, the same base
image family the sidecar build uses, so regeneration always targets the
right Python version regardless of the local machine.


Signed-off-by: Marco Nenciarini <marco.nenciarini@enterprisedb.com>
2026-09-03 15:25:33 +08:00
Marco Nenciarini
6a55a361a3 test: replace sleep-based test with deterministic channel verification
The cleanup routine test used time.Sleep() without actually verifying
the goroutine stopped. Added a done channel to provide deterministic
verification of goroutine termination.

Signed-off-by: Marco Nenciarini <marco.nenciarini@enterprisedb.com>
2025-12-23 17:06:00 +01:00
Armando Ruocco
62b579101f fix: prevent memory leak by periodically cleaning up expired cache entries
Signed-off-by: Armando Ruocco <armando.ruocco@enterprisedb.com>
2025-12-23 17:06:00 +01:00
12 changed files with 425 additions and 39 deletions

View File

@ -67,6 +67,26 @@ tasks:
GITHUB_REF= dagger -s call -m github.com/cloudnative-pg/daggerverse/commitlint@${DAGGER_COMMITLINT_SHA} GITHUB_REF= dagger -s call -m github.com/cloudnative-pg/daggerverse/commitlint@${DAGGER_COMMITLINT_SHA}
lint --source . --args "--from=origin/main" stdout lint --source . --args "--from=origin/main" stdout
pip-compile-sidecar:
desc: Regenerate containers/sidecar-requirements.txt with the same Python version as the sidecar image
cmds:
- >
GITHUB_REF= dagger call --no-mod
container from --address=debian:trixie-slim
with-env-variable --name=DEBIAN_FRONTEND --value=noninteractive
with-exec --args="apt-get,update,-qq"
with-exec --args="apt-get,install,-y,-qq,python3,python3-venv,python3-pip,gcc,libpq-dev"
with-exec --args="pip,install,--quiet,--break-system-packages,pip-tools,click<8.5.0"
with-directory --path=/work --source=containers
with-workdir --path=/work
with-exec --args="pip-compile,--allow-unsafe,--generate-hashes,--output-file=sidecar-requirements.txt,--strip-extras,sidecar-requirements.in"
file --path=/work/sidecar-requirements.txt
export --path=containers/sidecar-requirements.txt
sources:
- containers/sidecar-requirements.in
generates:
- containers/sidecar-requirements.txt
uncommitted: uncommitted:
desc: Check for uncommitted changes desc: Check for uncommitted changes
deps: deps:

View File

@ -36,6 +36,9 @@ import (
// DefaultTTLSeconds is the default TTL in seconds of cache entries // DefaultTTLSeconds is the default TTL in seconds of cache entries
const DefaultTTLSeconds = 10 const DefaultTTLSeconds = 10
// DefaultCleanupIntervalSeconds is the default interval in seconds for cache cleanup
const DefaultCleanupIntervalSeconds = 30
type cachedEntry struct { type cachedEntry struct {
entry client.Object entry client.Object
fetchUnixTime int64 fetchUnixTime int64
@ -49,18 +52,30 @@ func (e *cachedEntry) isExpired() bool {
// ExtendedClient is an extended client that is capable of caching multiple secrets without relying on informers // ExtendedClient is an extended client that is capable of caching multiple secrets without relying on informers
type ExtendedClient struct { type ExtendedClient struct {
client.Client client.Client
cachedObjects []cachedEntry cachedObjects []cachedEntry
mux *sync.Mutex mux *sync.Mutex
cleanupInterval time.Duration
cleanupDone chan struct{} // Signals when cleanup routine exits
} }
// NewExtendedClient returns an extended client capable of caching secrets on the 'Get' operation // NewExtendedClient returns an extended client capable of caching secrets on the 'Get' operation.
// It starts a background goroutine that periodically cleans up expired cache entries.
// The cleanup routine will stop when the provided context is cancelled.
func NewExtendedClient( func NewExtendedClient(
ctx context.Context,
baseClient client.Client, baseClient client.Client,
) client.Client { ) client.Client {
return &ExtendedClient{ ec := &ExtendedClient{
Client: baseClient, Client: baseClient,
mux: &sync.Mutex{}, mux: &sync.Mutex{},
cleanupInterval: DefaultCleanupIntervalSeconds * time.Second,
cleanupDone: make(chan struct{}),
} }
// Start the background cleanup routine
go ec.startCleanupRoutine(ctx)
return ec
} }
func (e *ExtendedClient) isObjectCached(obj client.Object) bool { func (e *ExtendedClient) isObjectCached(obj client.Object) bool {
@ -208,3 +223,55 @@ func (e *ExtendedClient) Patch(
return e.Client.Patch(ctx, obj, patch, opts...) return e.Client.Patch(ctx, obj, patch, opts...)
} }
// startCleanupRoutine periodically removes expired entries from the cache.
// It runs until the context is cancelled.
func (e *ExtendedClient) startCleanupRoutine(ctx context.Context) {
defer close(e.cleanupDone)
contextLogger := log.FromContext(ctx).WithName("extended_client_cleanup")
ticker := time.NewTicker(e.cleanupInterval)
defer ticker.Stop()
for {
select {
case <-ctx.Done():
contextLogger.Debug("stopping cache cleanup routine")
return
case <-ticker.C:
// Check context before cleanup to avoid unnecessary work during shutdown
if ctx.Err() != nil {
return
}
e.cleanupExpiredEntries(ctx)
}
}
}
// cleanupExpiredEntries removes all expired entries from the cache.
func (e *ExtendedClient) cleanupExpiredEntries(ctx context.Context) {
contextLogger := log.FromContext(ctx).WithName("extended_client_cleanup")
e.mux.Lock()
defer e.mux.Unlock()
initialCount := len(e.cachedObjects)
if initialCount == 0 {
return
}
// Create a new slice with only non-expired entries
validEntries := make([]cachedEntry, 0, initialCount)
for _, entry := range e.cachedObjects {
if !entry.isExpired() {
validEntries = append(validEntries, entry)
}
}
removedCount := initialCount - len(validEntries)
if removedCount > 0 {
e.cachedObjects = validEntries
contextLogger.Debug("cleaned up expired cache entries",
"removedCount", removedCount,
"remainingCount", len(validEntries))
}
}

View File

@ -20,6 +20,7 @@ SPDX-License-Identifier: Apache-2.0
package client package client
import ( import (
"context"
"time" "time"
corev1 "k8s.io/api/core/v1" corev1 "k8s.io/api/core/v1"
@ -59,6 +60,7 @@ var _ = Describe("ExtendedClient Get", func() {
extendedClient *ExtendedClient extendedClient *ExtendedClient
secretInClient *corev1.Secret secretInClient *corev1.Secret
objectStore *barmancloudv1.ObjectStore objectStore *barmancloudv1.ObjectStore
cancelCtx context.CancelFunc
) )
BeforeEach(func() { BeforeEach(func() {
@ -79,7 +81,14 @@ var _ = Describe("ExtendedClient Get", func() {
baseClient := fake.NewClientBuilder(). baseClient := fake.NewClientBuilder().
WithScheme(scheme). WithScheme(scheme).
WithObjects(secretInClient, objectStore).Build() WithObjects(secretInClient, objectStore).Build()
extendedClient = NewExtendedClient(baseClient).(*ExtendedClient) ctx, cancel := context.WithCancel(context.Background())
cancelCtx = cancel
extendedClient = NewExtendedClient(ctx, baseClient).(*ExtendedClient)
})
AfterEach(func() {
// Cancel the context to stop the cleanup routine
cancelCtx()
}) })
It("returns secret from cache if not expired", func(ctx SpecContext) { It("returns secret from cache if not expired", func(ctx SpecContext) {
@ -164,3 +173,141 @@ var _ = Describe("ExtendedClient Get", func() {
Expect(objectStore.GetResourceVersion()).To(Equal("from cache")) Expect(objectStore.GetResourceVersion()).To(Equal("from cache"))
}) })
}) })
var _ = Describe("ExtendedClient Cache Cleanup", func() {
var (
extendedClient *ExtendedClient
cancelCtx context.CancelFunc
)
BeforeEach(func() {
baseClient := fake.NewClientBuilder().
WithScheme(scheme).
Build()
ctx, cancel := context.WithCancel(context.Background())
cancelCtx = cancel
extendedClient = NewExtendedClient(ctx, baseClient).(*ExtendedClient)
})
AfterEach(func() {
cancelCtx()
})
It("cleans up expired entries", func(ctx SpecContext) {
// Add some expired entries
expiredSecret1 := &corev1.Secret{
ObjectMeta: metav1.ObjectMeta{
Namespace: "default",
Name: "expired-secret-1",
},
}
expiredSecret2 := &corev1.Secret{
ObjectMeta: metav1.ObjectMeta{
Namespace: "default",
Name: "expired-secret-2",
},
}
validSecret := &corev1.Secret{
ObjectMeta: metav1.ObjectMeta{
Namespace: "default",
Name: "valid-secret",
},
}
// Add expired entries (2 minutes ago)
addToCache(extendedClient, expiredSecret1, time.Now().Add(-2*time.Minute).Unix())
addToCache(extendedClient, expiredSecret2, time.Now().Add(-2*time.Minute).Unix())
// Add valid entry (just now)
addToCache(extendedClient, validSecret, time.Now().Unix())
Expect(extendedClient.cachedObjects).To(HaveLen(3))
// Trigger cleanup
extendedClient.cleanupExpiredEntries(ctx)
// Only the valid entry should remain
Expect(extendedClient.cachedObjects).To(HaveLen(1))
Expect(extendedClient.cachedObjects[0].entry.GetName()).To(Equal("valid-secret"))
})
It("does nothing when all entries are valid", func(ctx SpecContext) {
validSecret1 := &corev1.Secret{
ObjectMeta: metav1.ObjectMeta{
Namespace: "default",
Name: "valid-secret-1",
},
}
validSecret2 := &corev1.Secret{
ObjectMeta: metav1.ObjectMeta{
Namespace: "default",
Name: "valid-secret-2",
},
}
addToCache(extendedClient, validSecret1, time.Now().Unix())
addToCache(extendedClient, validSecret2, time.Now().Unix())
Expect(extendedClient.cachedObjects).To(HaveLen(2))
// Trigger cleanup
extendedClient.cleanupExpiredEntries(ctx)
// Both entries should remain
Expect(extendedClient.cachedObjects).To(HaveLen(2))
})
It("does nothing when cache is empty", func(ctx SpecContext) {
Expect(extendedClient.cachedObjects).To(BeEmpty())
// Trigger cleanup
extendedClient.cleanupExpiredEntries(ctx)
Expect(extendedClient.cachedObjects).To(BeEmpty())
})
It("removes all entries when all are expired", func(ctx SpecContext) {
expiredSecret1 := &corev1.Secret{
ObjectMeta: metav1.ObjectMeta{
Namespace: "default",
Name: "expired-secret-1",
},
}
expiredSecret2 := &corev1.Secret{
ObjectMeta: metav1.ObjectMeta{
Namespace: "default",
Name: "expired-secret-2",
},
}
addToCache(extendedClient, expiredSecret1, time.Now().Add(-2*time.Minute).Unix())
addToCache(extendedClient, expiredSecret2, time.Now().Add(-2*time.Minute).Unix())
Expect(extendedClient.cachedObjects).To(HaveLen(2))
// Trigger cleanup
extendedClient.cleanupExpiredEntries(ctx)
Expect(extendedClient.cachedObjects).To(BeEmpty())
})
It("stops cleanup routine when context is cancelled", func() {
// Create a new client with a short cleanup interval for testing
baseClient := fake.NewClientBuilder().
WithScheme(scheme).
Build()
ctx, cancel := context.WithCancel(context.Background())
ec := NewExtendedClient(ctx, baseClient).(*ExtendedClient)
ec.cleanupInterval = 10 * time.Millisecond
// Cancel the context immediately
cancel()
// Verify the cleanup routine actually stops by waiting for the done channel
select {
case <-ec.cleanupDone:
// Success: cleanup routine exited as expected
case <-time.After(1 * time.Second):
Fail("cleanup routine did not stop within timeout")
}
})
})

View File

@ -80,7 +80,7 @@ func Start(ctx context.Context) error {
return err return err
} }
customCacheClient := extendedclient.NewExtendedClient(mgr.GetClient()) customCacheClient := extendedclient.NewExtendedClient(ctx, mgr.GetClient())
if err := mgr.Add(&CNPGI{ if err := mgr.Add(&CNPGI{
Client: customCacheClient, Client: customCacheClient,

View File

@ -54,7 +54,47 @@ Both checks are required before proceeding with the installation.
## Installing the Barman Cloud Plugin ## Installing the Barman Cloud Plugin
import Tabs from '@theme/Tabs';
import TabItem from '@theme/TabItem';
import { InstallationSnippet, ManifestVersion } from '@site/src/components/Installation'; import { InstallationSnippet, ManifestVersion } from '@site/src/components/Installation';
import { HelmInstallationSnippet } from '@site/src/components/HelmInstallation';
<Tabs groupId="install-method" queryString>
<TabItem value="helm" label="Helm Chart" default>
The plugin can be installed using the provided [Helm chart](https://github.com/cloudnative-pg/charts/tree/main/charts/plugin-barman-cloud).
This installs the latest published chart release; to test an unreleased
development snapshot instead, switch to the [**Manifest (kubectl)**](./?install-method=kubectl#installing-the-barman-cloud-plugin) tab.
<HelmInstallationSnippet />
Example output:
```output
Release "plugin-barman-cloud" does not exist. Installing it now.
NAME: plugin-barman-cloud
LAST DEPLOYED: Wed Jul 1 09:05:16 2026
NAMESPACE: cnpg-system
STATUS: deployed
REVISION: 1
DESCRIPTION: Install complete
TEST SUITE: None
```
Finally, check that the deployment is up and running:
```sh
kubectl -n cnpg-system rollout status deploy/plugin-barman-cloud
```
Example output:
```output
deployment "plugin-barman-cloud" successfully rolled out
```
</TabItem>
<TabItem value="kubectl" label="Manifest (kubectl)">
Install the plugin using `kubectl` by applying the manifest for <ManifestVersion />: Install the plugin using `kubectl` by applying the manifest for <ManifestVersion />:
@ -85,8 +125,7 @@ issuer.cert-manager.io/selfsigned-issuer created
Finally, check that the deployment is up and running: Finally, check that the deployment is up and running:
```sh ```sh
kubectl rollout status deployment \ kubectl -n cnpg-system rollout status deploy/barman-cloud
-n cnpg-system barman-cloud
``` ```
Example output: Example output:
@ -95,6 +134,11 @@ Example output:
deployment "barman-cloud" successfully rolled out deployment "barman-cloud" successfully rolled out
``` ```
</TabItem>
</Tabs>
---
This confirms that the plugin is deployed and ready to use. This confirms that the plugin is deployed and ready to use.
## Testing the latest development snapshot ## Testing the latest development snapshot

View File

@ -485,14 +485,10 @@ If problems persist:
### Plugin Limitations ### Plugin Limitations
1. **Installation method**: Currently only supports manifest and Kustomize 1. **Sidecar resource sharing**: The plugin sidecar container shares pod
installation ([#351](https://github.com/cloudnative-pg/plugin-barman-cloud/issues/351) -
Helm chart requested)
2. **Sidecar resource sharing**: The plugin sidecar container shares pod
resources with PostgreSQL resources with PostgreSQL
3. **Plugin restart behavior**: Restarting the sidecar container requires 2. **Plugin restart behavior**: Restarting the sidecar container requires
restarting the entire PostgreSQL pod restarting the entire PostgreSQL pod
## Recap of General Debugging Steps ## Recap of General Debugging Steps
@ -588,4 +584,3 @@ kubectl get secret -n <namespace> <secret-name> -o jsonpath='{.data}' | jq 'keys
* **"NoSuchBucket"** — Verify the bucket exists and the endpoint URL is correct. * **"NoSuchBucket"** — Verify the bucket exists and the endpoint URL is correct.
* **"Connection timeout"** — Check network connectivity and firewall rules. * **"Connection timeout"** — Check network connectivity and firewall rules.
* **"SSL certificate problem"** — For self-signed certificates, verify the CA bundle configuration. * **"SSL certificate problem"** — For self-signed certificates, verify the CA bundle configuration.

View File

@ -0,0 +1,36 @@
import {ReactElement} from 'react';
import CodeBlock from '@theme/CodeBlock';
import {useActiveVersion, useLatestVersion} from '@docusaurus/plugin-content-docs/client';
// HelmInstallationSnippet is the Helm command to install the plugin.
//
// - Latest release: no override. The chart already defaults to
// itself.
// - Older release: pin image.tag and sidecarImage.tag to that
// version. We check this again on every build using
// useLatestVersion, so an old page updates itself once a newer
// version ships.
// - Dev docs: also no override, but this does NOT install a dev
// build. Setting the tag alone would not be enough, since the
// chart's own templates (CRDs, RBAC...) can be older than what
// main needs. Use the kubectl method to test a dev build.
export function HelmInstallationSnippet(): ReactElement<null> {
const activeVersion = useActiveVersion('default');
const latestVersion = useLatestVersion('default');
const isOlderRelease = activeVersion
&& activeVersion.name !== 'current'
&& activeVersion.name !== latestVersion.name;
const setArgs = isOlderRelease
? ` \\
--set image.tag=v${activeVersion.name} \\
--set sidecarImage.tag=v${activeVersion.name}`
: '';
return (
<CodeBlock language="sh">
{`helm repo add cnpg https://cloudnative-pg.github.io/charts --force-update
helm upgrade --install plugin-barman-cloud \\
--namespace cnpg-system${setArgs} \\
cnpg/plugin-barman-cloud`}
</CodeBlock>
);
}

View File

@ -1,5 +1,7 @@
import {ReactElement} from 'react'; import {ReactElement} from 'react';
import CodeBlock from '@theme/CodeBlock'; import CodeBlock from '@theme/CodeBlock';
import Link from '@docusaurus/Link';
import {useLocation} from '@docusaurus/router';
import {useActiveVersion} from '@docusaurus/plugin-content-docs/client'; import {useActiveVersion} from '@docusaurus/plugin-content-docs/client';
// DEV_MANIFEST_URL is the URL of the manifest.yaml on the main branch of the plugin repo. // DEV_MANIFEST_URL is the URL of the manifest.yaml on the main branch of the plugin repo.
@ -31,14 +33,17 @@ export function ManifestVersion(): ReactElement<null> {
: <>the latest development snapshot from the <code>main</code> branch</>; : <>the latest development snapshot from the <code>main</code> branch</>;
} }
// DevSnapshotSection offers the main-branch manifest as an alternative; // DevSnapshotSection shows how to test the main-branch manifest. On
// on the Dev docs the main install already is that manifest, so hide it. // the Dev docs, the kubectl install above already does that, so we
// hide this section there. (The Helm tab there installs the latest
// release, not a dev build.)
export function DevSnapshotSection(): ReactElement { export function DevSnapshotSection(): ReactElement {
const activeVersion = useActiveVersion('default'); const activeVersion = useActiveVersion('default');
const {pathname} = useLocation();
if (!activeVersion || activeVersion.name === 'current') { if (!activeVersion || activeVersion.name === 'current') {
return ( return (
<p>The <a href="#installing-the-barman-cloud-plugin">install <p>The <Link to={`${pathname}?install-method=kubectl#installing-the-barman-cloud-plugin`}>kubectl
command above</a> already applies the latest development install command above</Link> already applies the latest development
snapshot from the <code>main</code> branch.</p> snapshot from the <code>main</code> branch.</p>
); );
} }

View File

@ -54,7 +54,45 @@ Both checks are required before proceeding with the installation.
## Installing the Barman Cloud Plugin ## Installing the Barman Cloud Plugin
import Tabs from '@theme/Tabs';
import TabItem from '@theme/TabItem';
import { InstallationSnippet, ManifestVersion } from '@site/src/components/Installation'; import { InstallationSnippet, ManifestVersion } from '@site/src/components/Installation';
import { HelmInstallationSnippet } from '@site/src/components/HelmInstallation';
<Tabs groupId="install-method">
<TabItem value="helm" label="Helm Chart" default>
The plugin can be installed using the provided [Helm chart](https://github.com/cloudnative-pg/charts/tree/main/charts/plugin-barman-cloud):
<HelmInstallationSnippet />
Example output:
```output
Release "plugin-barman-cloud" does not exist. Installing it now.
NAME: plugin-barman-cloud
LAST DEPLOYED: Wed Jul 1 09:05:16 2026
NAMESPACE: cnpg-system
STATUS: deployed
REVISION: 1
DESCRIPTION: Install complete
TEST SUITE: None
```
Finally, check that the deployment is up and running:
```sh
kubectl -n cnpg-system rollout status deploy/plugin-barman-cloud
```
Example output:
```output
deployment "plugin-barman-cloud" successfully rolled out
```
</TabItem>
<TabItem value="kubectl" label="Manifest (kubectl)">
Install the plugin using `kubectl` by applying the manifest for <ManifestVersion />: Install the plugin using `kubectl` by applying the manifest for <ManifestVersion />:
@ -85,8 +123,7 @@ issuer.cert-manager.io/selfsigned-issuer created
Finally, check that the deployment is up and running: Finally, check that the deployment is up and running:
```sh ```sh
kubectl rollout status deployment \ kubectl -n cnpg-system rollout status deploy/barman-cloud
-n cnpg-system barman-cloud
``` ```
Example output: Example output:
@ -95,6 +132,11 @@ Example output:
deployment "barman-cloud" successfully rolled out deployment "barman-cloud" successfully rolled out
``` ```
</TabItem>
</Tabs>
---
This confirms that the plugin is deployed and ready to use. This confirms that the plugin is deployed and ready to use.
## Testing the latest development snapshot ## Testing the latest development snapshot

View File

@ -485,14 +485,10 @@ If problems persist:
### Plugin Limitations ### Plugin Limitations
1. **Installation method**: Currently only supports manifest and Kustomize 1. **Sidecar resource sharing**: The plugin sidecar container shares pod
installation ([#351](https://github.com/cloudnative-pg/plugin-barman-cloud/issues/351) -
Helm chart requested)
2. **Sidecar resource sharing**: The plugin sidecar container shares pod
resources with PostgreSQL resources with PostgreSQL
3. **Plugin restart behavior**: Restarting the sidecar container requires 2. **Plugin restart behavior**: Restarting the sidecar container requires
restarting the entire PostgreSQL pod restarting the entire PostgreSQL pod
## Recap of General Debugging Steps ## Recap of General Debugging Steps
@ -588,4 +584,3 @@ kubectl get secret -n <namespace> <secret-name> -o jsonpath='{.data}' | jq 'keys
* **"NoSuchBucket"** — Verify the bucket exists and the endpoint URL is correct. * **"NoSuchBucket"** — Verify the bucket exists and the endpoint URL is correct.
* **"Connection timeout"** — Check network connectivity and firewall rules. * **"Connection timeout"** — Check network connectivity and firewall rules.
* **"SSL certificate problem"** — For self-signed certificates, verify the CA bundle configuration. * **"SSL certificate problem"** — For self-signed certificates, verify the CA bundle configuration.

View File

@ -54,7 +54,45 @@ Both checks are required before proceeding with the installation.
## Installing the Barman Cloud Plugin ## Installing the Barman Cloud Plugin
import Tabs from '@theme/Tabs';
import TabItem from '@theme/TabItem';
import { InstallationSnippet, ManifestVersion } from '@site/src/components/Installation'; import { InstallationSnippet, ManifestVersion } from '@site/src/components/Installation';
import { HelmInstallationSnippet } from '@site/src/components/HelmInstallation';
<Tabs groupId="install-method">
<TabItem value="helm" label="Helm Chart" default>
The plugin can be installed using the provided [Helm chart](https://github.com/cloudnative-pg/charts/tree/main/charts/plugin-barman-cloud):
<HelmInstallationSnippet />
Example output:
```output
Release "plugin-barman-cloud" does not exist. Installing it now.
NAME: plugin-barman-cloud
LAST DEPLOYED: Wed Jul 1 09:05:16 2026
NAMESPACE: cnpg-system
STATUS: deployed
REVISION: 1
DESCRIPTION: Install complete
TEST SUITE: None
```
Finally, check that the deployment is up and running:
```sh
kubectl -n cnpg-system rollout status deploy/plugin-barman-cloud
```
Example output:
```output
deployment "plugin-barman-cloud" successfully rolled out
```
</TabItem>
<TabItem value="kubectl" label="Manifest (kubectl)">
Install the plugin using `kubectl` by applying the manifest for <ManifestVersion />: Install the plugin using `kubectl` by applying the manifest for <ManifestVersion />:
@ -85,8 +123,7 @@ issuer.cert-manager.io/selfsigned-issuer created
Finally, check that the deployment is up and running: Finally, check that the deployment is up and running:
```sh ```sh
kubectl rollout status deployment \ kubectl -n cnpg-system rollout status deploy/barman-cloud
-n cnpg-system barman-cloud
``` ```
Example output: Example output:
@ -95,6 +132,9 @@ Example output:
deployment "barman-cloud" successfully rolled out deployment "barman-cloud" successfully rolled out
``` ```
</TabItem>
</Tabs>
This confirms that the plugin is deployed and ready to use. This confirms that the plugin is deployed and ready to use.
## Testing the latest development snapshot ## Testing the latest development snapshot

View File

@ -485,14 +485,10 @@ If problems persist:
### Plugin Limitations ### Plugin Limitations
1. **Installation method**: Currently only supports manifest and Kustomize 1. **Sidecar resource sharing**: The plugin sidecar container shares pod
installation ([#351](https://github.com/cloudnative-pg/plugin-barman-cloud/issues/351) -
Helm chart requested)
2. **Sidecar resource sharing**: The plugin sidecar container shares pod
resources with PostgreSQL resources with PostgreSQL
3. **Plugin restart behavior**: Restarting the sidecar container requires 2. **Plugin restart behavior**: Restarting the sidecar container requires
restarting the entire PostgreSQL pod restarting the entire PostgreSQL pod
## Recap of General Debugging Steps ## Recap of General Debugging Steps
@ -588,4 +584,3 @@ kubectl get secret -n <namespace> <secret-name> -o jsonpath='{.data}' | jq 'keys
* **"NoSuchBucket"** — Verify the bucket exists and the endpoint URL is correct. * **"NoSuchBucket"** — Verify the bucket exists and the endpoint URL is correct.
* **"Connection timeout"** — Check network connectivity and firewall rules. * **"Connection timeout"** — Check network connectivity and firewall rules.
* **"SSL certificate problem"** — For self-signed certificates, verify the CA bundle configuration. * **"SSL certificate problem"** — For self-signed certificates, verify the CA bundle configuration.