Skip to content

Commit 8e28375

Browse files
committed
fix(helm): make the clickhouse chown init idempotent so it doesn't re-walk on every restart
Because the adopted-volume condition stays true for the life of the release, the ownership init container runs on every pod restart, and an unconditional recursive chown re-walks the whole database each time - minutes of delay on large or network-backed data. Skip the chown when the volume root is already owned by the run-as user (mirroring fsGroupChangePolicy: OnRootMismatch), so only the first mount after adoption pays the cost.
1 parent 68ffbf8 commit 8e28375

1 file changed

Lines changed: 6 additions & 1 deletion

File tree

‎hosting/k8s/helm/templates/clickhouse.yaml‎

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,7 +78,12 @@ spec:
7878
- name: volume-permissions
7979
image: "{{ .Values.global.imageRegistry | default .Values.clickhouse.volumePermissions.image.registry }}/{{ .Values.clickhouse.volumePermissions.image.repository }}:{{ .Values.clickhouse.volumePermissions.image.tag }}"
8080
imagePullPolicy: {{ .Values.clickhouse.volumePermissions.image.pullPolicy }}
81-
command: ["sh", "-c", "chown -R {{ .Values.clickhouse.securityContext.runAsUser | default 101 }}:{{ .Values.clickhouse.securityContext.runAsGroup | default 101 }} /var/lib/clickhouse"]
81+
{{- $chownUser := .Values.clickhouse.securityContext.runAsUser | default 101 }}
82+
{{- $chownGroup := .Values.clickhouse.securityContext.runAsGroup | default 101 }}
83+
{{- /* Idempotent: skip the recursive chown when the volume root is already
84+
owned by the run-as user, so it doesn't re-walk the whole database on
85+
every restart (only the first mount after adoption pays the cost). */}}
86+
command: ["sh", "-c", "test \"$(stat -c %u /var/lib/clickhouse)\" = \"{{ $chownUser }}\" || chown -R {{ $chownUser }}:{{ $chownGroup }} /var/lib/clickhouse"]
8287
securityContext:
8388
runAsUser: 0
8489
runAsNonRoot: false

0 commit comments

Comments
 (0)