Data placement and storage
Independent bundled or external placement for PostgreSQL, Kafka, ClickHouse, and Redis, including bundled-store limits.
Short glossary
- Helm release: an installed and independently managed resource set from one chart.
- Secret object: a Kubernetes resource referenced for sensitive values; the delivery charts do not own the values themselves.
- PersistentVolumeClaim (PVC): a storage request used by a bundled data component.
- NetworkPolicy: rules governing permitted network connections for application Pods.
- Container Storage Interface (CSI) and Container Network Interface (CNI) capabilities are provided by the customer cluster.
Data-store placement
Select bundled or external placement independently for PostgreSQL, Kafka, ClickHouse, and Redis. All 16 combinations of the four independent settings are supported; there is no aggregate installation mode.
| Store mode | Boundary |
|---|---|
| bundled | The package installs the selected single-node store in massaccess-data with an RWO PVC. |
| external | The package does not create this store and connects MassAccess to the company infrastructure endpoint and Secret. |
Confirmed limits
- Bundled data is single-node and non-HA; multi-node topology, drain, replication, failover, and PDB claims are not supported
- The charts do not provision or harden Kubernetes, DNS, CNI, CSI, StorageClass, Ingress/Gateway controllers, TLS automation, monitoring, or backup infrastructure
- Docker Desktop hostpath and local reference-CNI evidence does not prove customer CSI/CNI, HA, capacity, performance, disaster recovery, or production SLA
- The release contract does not claim cryptographic signing or absence of vulnerabilities; use the documented checksum, SBOM, SLSA provenance, and policy verification boundary