Data stores inventory β the ktayl-solution IS
:::note Verified, live Produced by querying the running cluster (CNPG clusters + StatefulSets + Deployments + NATS + the control-plane store), not from memory. Snapshot date: 2026-10-06. Reproduce with the commands in Operate / verify below. This is the companion to Canonical data model (the logical model) β this page is the physical "what engine runs where." :::
The data layer is PostgreSQL-standard with vendor-forced exceptions, plus purpose-built stores for vectors, analytics, cache, events, secrets, objects and observability.
Relationalβ
PostgreSQL β the house standard (~20 instances, 3 deployment styles)β
| Style | Image | Where (ns / service) |
|---|---|---|
| CNPG operator (preferred) | cloudnative-pg/postgresql:17.4 | authentik (2) Β· claims (dev 1 / prod 1) Β· underwriting (dev 1 / prod 2) Β· nextcloud Β· data-platform (dp-postgres) Β· langfuse (langfuse-postgres) Β· synapse/Matrix (synapse-postgres, C collation) β both migrated 2026-10-06, see CNPG standardisation |
Custom base postgresql:18.4.0-noavx512 | Harbor | postgresql-ai (shared: openwebui/litellm/ragdb/vaultwarden/flowise/mlflow) Β· postgresql-synapsepostgresql-ai is the last consumer blocking removal of the image+repo. |
| Plain / vendor StatefulSet | postgres:16/15-alpine, bitnami | ktayl-iam (dev+prod) Β· ktayl policy-service (dev+prod) Β· retrieva (dev+dev) Β· backstage (bitnami 15.4) Β· plane (15.7) Β· temporal (15) Β· harbor-database (goharbor) |
External (points elsewhere via DATABASE_URL) | β | (none β langfuse's metadata DB moved to its own in-ns CNPG cluster on 2026-10-06) |
β οΈ Consolidation debt: Postgres is universal but deployed three inconsistent ways (CNPG vs raw StatefulSet vs vendor-bundled). CNPG is the intended standard (backup/HA/PITR) β the raw/vendor ones are candidates to migrate. See Database backup and the custom base image note below.
MariaDB β the vendor-forced exception (3 β the old "one deviation" note is stale)β
mariadb:10.6.27 ERPNext Β· mariadb:11.4 BookStack Β· mariadb:11.4 GLPI. All three because
the adopted app (Frappe/ERPNext, BookStack, GLPI) is MariaDB-native β adopt-vs-build drives the
engine, not a platform preference.
MySQL / Oracle β legacy simulation onlyβ
globalcore-legacy ships docker-compose.yml (MySQL) + docker-compose.oracle.yml (Oracle) β the
Java/SOAP legacy the Claims ACL strangles. Local-dev / ACL target, not on-cluster.
SQLite β the cluster's own stateβ
k3s control-plane datastore = kine β SQLite (on the control-plane node; backed up by the kine-backup CronJob + a controller systemd timer). Nextcloud was on SQLite historically β migrated to CNPG.
Vector / searchβ
- Qdrant
v1.11.0(ai) β the RAG vector DB (retrieva Β· open-webui Β· rag-ingest). - pgvector β vector search inside Postgres (the
-noavx512base; ai + synapse). β two coexisting vector approaches (Qdrant vs pgvector) β a deliberate split (ADR-worthy).
Analytics (OLAP) & BIβ
- ClickHouse
25.2.1+ Zookeeper (langfuse) β columnar store for LLM traces. - Metabase
v0.50.26(data-platform) β BI; queries thedp-postgresmedallion.
Cache / KV / brokerβ
- Redis / Valkey (~9): litellm-cache Β· langfuse-redis Β· nextcloud-redis Β· plane-redis Β· harbor-redis Β· argocd-redis Β· matrix-synapse-redis Β· erpnext-valkey (cache + queue) Β· retrieva-redis.
- RabbitMQ
3.13.6(plane) β AMQP broker.
Specialised storesβ
| Store | Engine | Role |
|---|---|---|
| Vault | Raft (integrated storage) | secrets KV (AWS-KMS auto-unseal) |
| NATS JetStream | file-backed streams | event store: JOBS Β· POLICY_EVENTS Β· UNDERWRITING_EVENTS Β· HR_LIFECYCLE Β· CLAIMS_CDC(_PROD) |
| MinIO | S3 object | plane-ce-minio (in-cluster) + controller MinIO (Docker, backup target) + Cloudflare R2 (off-site CNPG barman) |
| Prometheus / Loki / Tempo | TSDB / logs / traces | observability datastores |
| Stalwart | RocksDB (embedded) | mail store (Longhorn PVC) |
Headline observationsβ
- Postgres = standard; MariaDB = vendor-forced (ERPNext/GLPI/BookStack). The "one MySQL deviation" claim is outdated β it's 3, all adopted-app-driven.
- Postgres deployment is inconsistent (CNPG / raw STS / vendor) β the biggest cleanup target; migrate load-bearing ones onto CNPG for backup/PITR parity.
- Two vector approaches (Qdrant + pgvector) coexist deliberately.
- The custom
postgresql-noavx512base is a single point of fragility β it lives only in Harbor and was once GC'd out; protected by an always-retain rule. See the registry retention runbook.
Operate / verifyβ
# CNPG Postgres clusters
ssh controller "kubectl --context minicloud get cluster.postgresql.cnpg.io -A"
# every stateful datastore (image per workload)
ssh controller "kubectl --context minicloud get sts -A -o custom-columns=NS:.metadata.namespace,NAME:.metadata.name,IMAGE:.spec.template.spec.containers[0].image"
# DBs that run as Deployments (metabase, redis/valkeyβ¦)
ssh controller "kubectl --context minicloud get deploy -A -o wide | grep -iE 'postgres|maria|redis|valkey|clickhouse|qdrant|metabase|rabbit|minio'"
# NATS JetStream streams
ssh controller "kubectl exec -n messaging <nats-box> -- nats -s nats://nats:4222 stream ls"
See alsoβ
- Logical model β Canonical data model Β· System of record β System of record
- Backup/DR β DR runbook Β· Custom base image + the SIGILL story β the Docker course
(
ktayl-docker-course, Module 0 + the registry retention troubleshooting).