Clone
1
Operations
Gitea edited this page 2026-08-12 09:46:27 +00:00

Operations

Growing storage (Helm)

Changing persistence.size/persistence.storageClass on an already-installed StatefulSet makes helm upgrade fail with "updates to statefulset spec for fields other than replicas, template, and updateStrategy are forbidden" — Kubernetes forbids changing volumeClaimTemplates after the fact.

So, from the start, for production: set persistence.existingClaim: <name>. Then no volumeClaimTemplate exists at all, and resizing is a plain PVC edit (kubectl patch pvc ... -p '{"spec":{"resources":{"requests":{"storage":"100Gi"}}}}', as long as the StorageClass has allowVolumeExpansion: true).

If you're stuck with a chart-generated PVC anyway:

kubectl delete statefulset <release>-aptly --cascade=orphan   # PVC survives
# adjust persistence.size in values.yaml
helm upgrade <release> oci://git.morlana.online/f.weber/aptly ...

The PVC itself always survives helm uninstall regardless (StatefulSet PVCs are never Helm-managed) — helm.sh/resource-policy: keep is neither needed nor applicable here.

Backup & restore (Compose)

docker compose --profile backup run --rm backup
# writes /backup/aptly-<timestamp>.tar.zst (without .gnupg)

Restore: stop the container, restore the tar into the aptly_data volume, provide the GPG key again via config/gpg/ (the private key is deliberately NOT included in the backup — it only ever lives in GNUPGHOME/Secrets, never on the data volume).

GPG key rotation

GNUPGHOME lives on an in-memory volume in both Compose and the Helm chart (tmpfs/emptyDir: {medium: Memory}), which is repopulated from the configured Secret on every start. Rotation is therefore simple:

  • Compose: drop new key files under compose/config/gpg/, then docker compose restart aptly-init aptly (or up -d again).
  • Helm: update the referenced Secret, then kubectl rollout restart statefulset/<release>-aptly.

A key removed from the configuration actually disappears — nothing is left behind on a PersistentVolume.