Spilo: High Availability PostgreSQL cluster using Docker
github.com
github.com
But, above all, I would warmly recommed anyone to first do their best to use cockroachDB (or yugadb if you like more) instead. The benefits of distributed/horiz scaled DB usually overcome the effort of moving to it (which should not be big as it's using same pg client/protocol). And it's free if you don't need enterprise features like partitions, etc.
I was running my own Spilo builds for a while, which was hit-and-miss. For my new (Kubernetes bare metal) cluster deployment I’ve moved over to Stackgres. I also evaluated CNPG (promising, but still early-ish days), as well as one other IIRC.
I found Stackgres to work most reliably. And it solves the biggest pain with Spilo, which is building an image with the required PG extensions. Stakgres instead has its own repository of extensions that it can install from, which is a huge help.
A false positive CVE list is an issue elsewhere as well, and it's important to understand that there's not much a Docker Postgres maintainer can do if the problem lies in the Debian or Ubuntu package and isn't getting fixed for some reason.
https://github.com/docker-library/faq#why-does-my-security-s...
It's also advisable not to use the default settings:
https://pythonspeed.com/articles/docker-security-scanner/ "trivy --ignore-unfixed <image>"
Of course, it is advisable for the image maintainer to rebuild the Docker image weekly or bi-weekly to ensure all recent patches are included.
However, for those who prioritize security, it is best to build the image themselves to guarantee up-to-date packages.
CVE-2005-2541 is documented & required behavior for the tar archive: https://marc.info/?l=bugtraq&m=112360016019030&w=2 . Infuriating that the CVE was seen as valid enough to get a number.
MySQL has PXC and Galera... Why nothing for PostgreSQL ?